Leadership1 publisher3 min readPublished
A five-question test moves the sovereignty argument onto the permissions layer
A Forbes Tech Council column argues that an institution's control over what its agents may do decides sovereignty, and the European rules it cites were written for cloud vendors.
The Board Room · Leadership desk

What happened
- A NIST concept paper from February, the column's starting point, described enterprises moving AI from producing text and graphics to taking actions in production systems, including deploying code.
- Kashyap adds a fourth column to the model, data and compute trio: execution sovereignty, the authority an institution keeps over what its agents may do and when that authority can be withdrawn.
- Europe's proposed Cloud and AI Development Act would introduce a single EU-wide framework for assessing cloud and AI sovereignty.
- The European supervisory authorities published their first list of critical ICT third-party providers last November.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint Authorization is out of scope for the interoperability standards, so no protocol upgrade will settle what an institution's agents may do; the decision sits in identity issuance and policy evaluation, which institutions usually buy.
- exposure An institution can pass a data-residency audit and still have its payment agents stopped by an outside provider tightening a default. The dashboard the supervisor reads does not show that dependency.
- decision The five questions turn a sovereignty posture into a procurement choice this quarter: whether to accept managed identity and policy services, or to pay to keep issuance, audit and the halt switch in house.
- contradiction The column argues regulation is catching up, but the instruments it cites govern vendor contracts and switching. No rule in force covers agent permissions, so the claim that they are being formalized is an inference.
Two agent specifications in the column show why permission does not travel with capability. The Model Context Protocol's authorization specification binds an access token to the server it was issued for, and requires servers to reject tokens that were not issued for them [5]. Agent2Agent handles identity at the protocol layer, expects credentials to be obtained out of band and leaves the authorization decision to the receiving agent [6]. Neither standard decides what anyone inside an institution may do. The deciding happens in the identity provider, the policy engine, the log and the revocation path, which Dr. Aditya Vikram Kashyap, an AI governance leader writing for the Forbes Tech Council, says institutions rarely negotiate hardest over [7][16].
His worked example is a domestic bank running agents across treasury operations and supplier payments. Data stays in country and workloads run in country, and the supervisor is satisfied [8]. The machine identities are issued by an external provider, the policy engine that decides which actions clear is a managed service, and the model behind the agents updates on a schedule the bank does not set [8]. If that provider changes a default, tightens a limit or suspends the service, Kashyap writes, the payments stop [8].
The test he offers has five questions about any deployment: who can widen its permissions without your sign-off, who can narrow them, who can see what it did, who can halt it mid-action and who can move it elsewhere when the relationship sours [12]. The failure threshold is two answers out of five, or 40 percent of the listed control rights [17]. Kashyap wrote that if the answer to more than one of them is not the institution itself, the system is hosted domestically and governed abroad [13].
The European instruments he reaches for were written for vendors. DORA obliges banks to maintain documented exit strategies for critical technology services [9], and the Data Act requires cloud providers to remove the obstacles that stop customers from switching away [15]. Kashyap calls the financial-supervision pair "control-rights instruments wearing resilience clothing" [11]. Taken together, the instruments described in the column cover exit planning, provider designation, switching and a sovereignty assessment framework, and stop short of which actions an agent may execute [19].
I can see the objection: this is a taxonomy, and procurement has handled it for years through revocation clauses, audit rights and exit plans. The column's answer is that the same contract terms now decide something they were not drafted for. A foreign-built agent running under your identity infrastructure, your authorization policy and your audit trail, with the technical and contractual ability to revoke and replace it, may have strong execution sovereignty, Kashyap writes. The reverse also holds: a domestically hosted model whose agents authenticate through a foreign identity service and obey a foreign policy engine has weak execution sovereignty [18]. "Location is a fact about infrastructure. Sovereignty is a fact about control rights," he wrote [14].
The documents that answer the five questions exist already: the identity-issuance contract, the policy engine's service terms, the audit export, the notice period on a suspension. For banks, DORA's exit-strategy duty makes one of the five a supervised question [9]. The other four are a buyer's to ask, and the framework is one author's, not a regulator's [4].
What to watch
- Whether the proposed Cloud and AI Development Act's assessment framework scores control rights such as revocation and audit access, or only where systems sit.
- Whether the next European supervisory authorities list of critical ICT third-party providers extends to identity providers and policy engines.
- Whether any supervisor writes an exit-strategy requirement that covers machine identities and agent authorization.