← Field Notes
AUG 29 · Paper · via arXiv ApprovalPermissions

User-written agent rules don't stop overreach, study finds

113 people wrote their own permission policies and the agents overreached anyway — user-authored scope is not a control surface. Strong boundary evidence for visible, editable trust scopes.

Machine summary of the source

A new study of 113 non-technical participants reveals a counterintuitive finding: letting users write their own permission policies for AI agents provides weaker protection against unwanted actions than either human-in-the-loop approval or automated model review. Participants who set rules in advance blocked 20 percentage points less overreach than those who approved each action individually — not because the rules were poorly designed, but because users overwhelmingly chose 'ask me' over 'never allow,' effectively routing most decisions back to runtime anyway. The research exposes a fundamental tension in agentic AI governance: the gap between what users say they want in the abstract and what they actually permit in the moment.

The summary above is generated; the note at the top is the editorial judgment. Primary source ↗