Daon Just Patented the “Permission Slip” for AI Agents. Fraud Teams Should Pay Attention — and Ask Hard Questions.

11

Aug

Daon Just Patented the “Permission Slip” for AI Agents. Fraud Teams Should Pay Attention — and Ask Hard Questions.

The agentic AI wave has a fraud problem that almost nobody in the enterprise wants to say out loud: we are handing software the keys to payment rails, customer records, and back-office tools faster than we can verify who — or what — is actually turning those keys.

That’s why a recent announcement covered by MSN caught our attention. Daon, the digital identity company best known for biometric authentication in banking and telecom, says it has completed the first commercially patented three-layer trust stack for AI agent authorization. The third and final patent — U.S. Patent No. 12,688,261, “Methods and Systems for Authorizing Invocation of a Tool by an Autonomous Artificial Intelligence Agent,” issued July 21, 2026 — closes the loop on an architecture Daon has been assembling since late 2025.

From a fraud-prevention standpoint, this is one of the more consequential identity stories of the year. Here’s our read on what it actually means, and where the open questions are.

What Daon Actually Patented

The stack, detailed in Daon’s announcement, addresses three distinct failure modes — each of which maps to a fraud vector we’ve been tracking on this site.

Layer 1: Person-agent fidelity (U.S. Patent 12,452,035, October 2025). Does the agent still answer to the human who authorized it? This layer continuously monitors the bond between principal and agent, which matters because prompt injection — malicious instructions buried in a webpage, email, or document that hijack an agent mid-task — is emerging as the social engineering of the machine era. The scam email of 2020 tricked your employee. The poisoned webpage of 2026 tricks your employee’s agent.

Layer 2: Agent behavioral integrity (U.S. Patent 12,563,045, February 2026). Is the agent, and the environment it runs in, behaving within expected parameters? Think of this as behavioral biometrics for software: the same drift-detection logic fraud teams already apply to account takeover, pointed at an autonomous process instead of a human session.

Layer 3: Action-level authorization (U.S. Patent 12,688,261, July 2026). Should this specific action proceed right now? This is the layer Daon calls a “digital permission slip” — a short-lived token cryptographically bound to the action type, resource scope, time window, rate limits, and execution context. Tamper with the runtime and the token dies. It’s the agentic equivalent of a single-use virtual card number, and it’s the piece fraud practitioners should find most interesting.

Why the Old Model Breaks

Daon’s president and chief product officer, Ralph Rodriguez, framed the core problem well in the announcement: traditional identity and access management assumes a human authenticates and then operates within a session. Agents don’t work that way — they “plan, branch, parallelize, and invoke tools at machine speed.”

Every fraud professional should sit with that sentence. Session-based trust is the foundation of nearly every authentication and authorization control the industry has deployed for two decades. Step-up authentication, session risk scoring, device binding — all of it assumes a human on the other end whose behavior unfolds at human speed. An autonomous agent inherits its principal’s permissions and then acts hundreds of times per minute, across parallel branches, in ways no session-based model was built to evaluate.

The numbers cited in the coverage back up the urgency. A Cloud Security Alliance survey from January found 74% of enterprises grant AI agents more access than required. Enterprise agent fleets have roughly doubled since December 2025, and nearly half of deployed agents operate with no security oversight or logging. Over-permissioned, unmonitored, machine-speed actors with legitimate credentials — that is, functionally, an insider-threat population growing at 100% every few months.

The Skeptic’s Corner

Our enthusiasm comes with caveats, because it always should.

A patent is not a deployment. Patented architecture and production-hardened product are different things. The value of this stack will be proven in live regulated environments — banks, insurers, healthcare systems — under adversarial pressure, not in a filing at the USPTO. Daon says the capabilities are being integrated into its TrustX platform; adoption and real-world attack data will tell the story.

Proprietary control layers in a standards vacuum cut both ways. NIST flagged agent governance as a priority in February, and Senator Mark Warner’s June discussion draft would push NIST toward open standards for agent authentication. If open standards arrive, patented proprietary stacks will need to interoperate with them — or risk becoming well-defended islands. Enterprises evaluating any vendor in this space should ask pointed questions about standards alignment.

Daon isn’t alone, whatever the patent position. SecureAuth, Microsoft’s Entra Agent ID, and the Yubico/Delinea axis are all circling agent identity. Daon’s differentiator is a commercially patented end-to-end architecture backed by a 320+ patent portfolio in biometrics and digital identity. That’s a real moat — but fraud leaders should evaluate the control model on its merits, not the patent count.

What Fraud and Compliance Teams Should Do Now

Regardless of which vendor ultimately wins this category, the three-layer framing is a useful audit lens today. If your organization is deploying agents — and per Gartner, 40% of enterprise applications will embed task-specific agents by the end of 2026 — ask three questions: Can we verify each agent is still faithful to the human who authorized it? Can we detect when an agent’s behavior drifts outside sanctioned boundaries? And can we approve or deny individual high-risk actions at the moment of execution, with an evidence trail a regulator will accept?

If the answer to any of those is no, you have an authorization gap that fraud actors will eventually find. With the EU AI Act’s high-risk compliance deadline having landed August 2, “we didn’t have a control for that” is no longer an answer regulators will accept either.

Daon CEO Tom Grissen put it plainly: agentic AI won’t move safely into high-value production “on intelligence alone. It requires identity, policy, containment, and evidence at the moment an agent attempts to act.” On that point, we couldn’t agree more. The fraud fights of the next five years won’t just be about proving a human is who they claim to be — they’ll be about proving a machine is still doing what its human intended.

Share this post

RELATED

Posts