
What happened
Keydris has released a system that issues AI agents signed authorization tokens (called kits) before they can call external tools or services. A lightweight component called the Kit Reader sits on each tool server, verifies the token with Keydris's central Gateway, and blocks any action that lacks valid authorization.
Why it matters
AI agents now act faster than humans can review and against systems that do not tolerate mistakes. Unlike software built for human users, agents need verifiable proof of what they are permitted to do at the moment of action. Keydris lets institutions answer critical questions—which actions were actually authorized, who authorized them, and what proof exists—before harm occurs rather than after.
What to watch
Keydris is designed to work across any AI model, vendor, or platform, positioning itself as neutral infrastructure between institutions. The system issues tokens with minimum privilege by default, syncs revocation instantly across boundaries, and produces signed audit records automatically as part of normal operation—not assembled after the fact for compliance review.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
AI agents present a novel liability that traditional software authorization frameworks do not address. While every previous category of software was built for humans clicking buttons and reviewing actions, agents act at machine speed—faster than any human can validate, against systems that do not forgive mistakes. The core problem Keydris addresses is that trust by assumption is no longer sufficient when an agent can cause damage in milliseconds.
Keydris positions itself as infrastructure that sits at the boundary between the agent and the tool it calls, creating a verifiable chain of proof around every action. Each authorization decision is cryptographically signed and immutable, with revocation built into the verification process itself rather than as a separate administrative function. This approach answers the questions that security and compliance leaders already ask: which actions were actually authorized and by whom, what happens when authority is revoked, and what record would be handed to an auditor. The system's output—signed records of every decision—is generated automatically as the system operates, not assembled after the fact for compliance review.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Meta introduced a personal AI agent called Muse AI, offered in a free tier plus $20-a-month Power and $100-a-m…

Between May 11 and 12, 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, shut down…

Companies are expected to spend over $2.5 trillion on AI in 2026, a 47% increase on 2025, but many now report…

Jacob Coxon resigned from Anthropic, warning it and OpenAI were "gambling with our lives" on superintelligence

Dartmouth's Ivory Yang and collaborators built NüshuRescue, which trained GPT-4 Turbo on 35 Chinese-Nüshu sent…

Researchers Ivory Yang, Weicheng Ma and Soroush Vosoughi unveiled NüshuRescue, an AI framework that trained GP…
