SHIRO & Co. / Threat Observatory
Capability Is Not Authority
The Authority Surface examines what happens when AI capability gains access to credentials, APIs, financial systems, infrastructure, industrial equipment and physical machines.
AI systems are increasingly moving beyond conversation into tools, transactions, infrastructure and physical environments. The critical question is no longer only what a model can do, but what authority the surrounding system has granted it.
OPERATIONAL CHAIN
Capability
Authority Surface
Supervisory Layer
Real-World Action
The Core Question
From Intelligence to Operational Authority
Most AI safety discussions focus on model capability: reasoning, autonomy, planning, tool use or intelligence. Authority Surface adds another layer: what external systems the model is actually allowed to reach.
Limited Capability Environment
AI model → generates text → no external access → limited real-world consequence
Expanded Authority Environment
AI model → credentials → APIs → payments → cloud systems → industrial systems → physical machines
What Is an Authority Surface?
Credentials
APIs
Communication systems
Financial systems
Cloud infrastructure
Enterprise software
Operational technology
Industrial equipment
Robotics
Physical machines
Six Dimensions
Access
What systems or resources can the AI reach?
Permission
What actions is it authorized to perform?
Persistence
Can access or effects continue over time?
Propagation
Can actions move into other systems, agents or environments?
Reversibility
Can the resulting action be stopped, rolled back or corrected?
Observability
Can humans or supervisory systems see what the AI is doing and why?
Supervision Layer
Authority Requires Supervision
SHIRO & Co.’s Supervisory Layer examines where human or institutional review should exist before AI inference becomes operational consequence.
The framework does not imply that a system autonomously makes final governance decisions. Human review remains part of the supervisory structure.
CAPABILITY
AUTHORITY SURFACE
SUPERVISORY LAYER
ALLOW
/ HOLD /
DENY
REAL-WORLD ACTION
ALLOW
Conditions are sufficiently established for action to proceed.
HOLD
Additional evidence, review or human judgment is required.
DENY
The action should not proceed under the current conditions.
Software to Physical Actor
Chatbot
Tool User
Agent
System Operator
Infrastructure Participant
Physical Actor
Text → Action
AI moves from generating output to executing operations.
System → Infrastructure
AI gains access to financial, cloud or operational systems.
Digital → Physical
AI becomes connected to machines, robots or physical environments.
Why This Matters Now
AI Agents
Models are increasingly allowed to take actions rather than only generate responses.
Enterprise Systems
AI is being connected to internal applications, credentials, workflows and payments.
Infrastructure
AI systems may operate cloud, operational and industrial resources.
Physical AI
Threat Observatory
Structural questions. Not incidents. Not alerts.
The Threat Observatory examines structural changes in technological risk before those changes become visible only as incidents.
Authority
Supervision
Human intervention
Uncertainty
Recruitment
Infrastructure
Physical control
Consequence
Research Connection
Threat Observatory
What can AI reach or control?
Algorithmic Allocation Observatory
When does inference gain authority over human consequence?
Decision Boundary
Where should action be allowed, held or denied?