Cloudflare 发布《The Agent Access Model》论文,提出面向 AI 智能体的访问控制模型
AAM,核心规则是"不信任运行",对任务执行图中的每个动作基于智能体身份、授权任务及已触达资源进行实时授权。
该模型针对智能体的短暂性、机器速度、提示词非边界及跨跳组合权限四大特性设计,主张缩小能力集而非仅优化单次决策,并区分单主体控制与多人访问控制的难点。
Cloudflare published the paper "The Agent Access Model," proposing the access control model AAM for AI agents. Its core rule is 'distrust execution,' which...
Cloudflare published the paper "The Agent Access Model," proposing the access control model AAM for
AI agents. Its core rule is 'distrust execution,' which performs real-time authorization for each action in the task execution graph based on the agent's identity, the authorized tasks, and the resources already reached. The model is designed for four key characteristics of agents: transience, machine speed, non-boundary prompts, and cross-hop combined permissions. It advocates reducing the capability set rather than merely optimizing single decision-making, and it distinguishes between the challenges of single-subject control and multi-user access control.
Cloudflare 发布《The Agent Access Model》论文,提出面向 AI 智能体的访问控制模型
AAM,核心规则是"不信任运行",对任务执行图中的每个动作基于智能体身份、授权任务及已触达资源进行实时授权。
该模型针对智能体的短暂性、机器速度、提示词非边界及跨跳组合权限四大特性设计,主张缩小能力集而非仅优化单次决策,并区分单主体控制与多人访问控制的难点。
Cloudflare 发布《The Agent Access Model》论文,提出面向 AI 智能体的访问控制模型 AAM。其核心是“不信任运行”,在任务执行图中依据智能体身份、授权任务及已触达资源,对每个动作实施实时授权。
材料指出,AAM 针对智能体的短暂性、机器速度、提示词非边界及跨跳组合权限四项特性设计。论文还主张缩小智能体能力集,而非只优化单次访问决策,并区分单主体与多人访问控制问题。
Aioga 判断,AAM 的重点不只是判断某次请求是否允许,而是把授权放到任务执行过程的每个动作上。若该思路落地,权限边界可能从静态配置转向与身份、任务和已触达资源联动。
值得关注的是,智能体在连续任务中可能形成跨步骤的组合权限。材料提出缩小能力集,意味着权限治理或将更重视限制可执行范围,而不只是提升单次判断的准确性;但材料未说明具体实施效果。 后续可关注 Cloudflare 是否公布 AAM 的具体实现、评估方法或部署案例,以及模型如何处理多人协作访问。当前材料仅说明论文提出的规则与设计重点,尚不足以判断其实际性能或适用范围。
The readable text on this page was extracted from the public source and organized with attribution, publication time and the original link. Copyright remains with the original author and publisher.
Ingestion channel: Summary aggregation · Source domain: blog.cloudflare.com
Source: Cloudflare Blog
Original link: Open original source
Aioga archive: Open intelligence page
Content record: summary-fallback · Updated: 2026-08-05T13:00:41.000Z

统一接入主流 AI 模型 API,为开发、测试与生产环境提供稳定调用入口。
立即访问 api.w173.comAioga aggregates global AI updates and preserves source information for verification and citation.