> Markdown version of [/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue?t=868](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue?t=868). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue Are your AI agents indiscriminately leaking sensitive data across unauthorized user sessions? Discover how OpenFGA and OAuth enforce zero-trust boundaries to keep your applications from going rogue. - **Speakers:** [Deepu](https://www.wearedevelopers.com/@deepu) - **Event:** World Congress 2025 - **Published:** August 20, 2025 - **Duration:** 23:29 - **URL:** https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue ## Summary Modern AI agents operate much like teenagers: they are "great at doing a lot of things, but with very questionable judgment." As AI applications scale, developers face distinct vulnerabilities that generative model providers cannot address on their behalf. Two critical application-side attack surfaces involve excessive agent agency and sensitive information disclosure, particularly within Retrieval-Augmented Generation (rag) environments. When an AI indiscriminately pulls context from vector databases, it risks leaking confidential data across unauthorized user sessions. Traditional role-based access control (rbac) frameworks lack the dynamic context, complex dataset relationships, and granular mechanisms required to safely manage these enterprise data pipelines. Implementing a fine-grained access control (fga) framework like openfga bridges this critical security gap. Instead of sending raw vector database results directly to a language model, an intermediate retrieval layer first filters the documents based on predefined relationship triples—mapping the user, the object, and their explicit relation. Under this architecture, the AI relies solely on context the requesting user is explicitly authorized to view. Furthermore, development teams must enforce zero-trust principles at the tool integration layer rather than trusting the AI model to dictate its own resource access limits. To manage an agent's interactions with third-party software, identity brokers can securely orchestrate federated access tokens without exposing raw credentials to the model. For highly sensitive operations, such as executing financial transactions or altering production databases, utilizing asynchronous protocols like the client initiated backchannel authentication (ciba) flow introduces a critical "human-in-the-loop" checkpoint. By sequentially requesting step-up approvals via external mobile notifications before an agent carries out high-stakes functions, organizations can confidently constrain system agency and construct robust guardrails against unpredictable behavior. **Keywords:** ai application security, sensitive information disclosure, excessive ai agency, retrieval-augmented generation security, vector database filtering, role-based access control limitations, fine-grained access control, openfga architecture, zero trust tool access, oauth token federation, step-up authorization flows, human-in-the-loop workflows, client initiated backchannel authentication, asynchronous ai approvals ## Chapters 1. **Current state of security in AI applications** (00:04) — Why the security domain is playing catch-up with rapidly evolving AI protocols and agent interactions. 1. **Top security vulnerabilities for AI applications** (02:00) — How prompt injection, sensitive data leakage, and excessive agency create significant attack surfaces for developers. 1. **Preventing sensitive information disclosure in RAG systems** (05:01) — Why providing dynamic retrieval-augmented generation systems access to sensitive information requires rigorous authorization models. 1. **Limitations of traditional access control in RAG** (07:29) — How dynamic context and complex relationships make role-based access control insufficient for granular AI data retrieval. 1. **Modeling complex permission structures with OpenFGA** (09:06) — Using relationship-based fine-grained access control to manage object-level permissions and complex hierarchies securely. 1. **Implementing OpenFGA document retrieval for AI agents** (11:26) — How an FGA retriever filters vector database results so language models only process authorized documents. 1. **Mitigating excessive agency through scoped tool access** (14:28) — Securing AI agent execution environments by combining zero-trust principles, role-based checks, and fine-grained authorization. 1. **Brokering third-party APIs with OAuth federation** (16:56) — Calling external services securely by using a token vault to broker and refresh federated access credentials. 1. **Managing asynchronous human-in-the-loop workflows for AI** (17:43) — Utilizing the CIBA standard to require synchronous or asynchronous user approvals before allowing AI agents to execute sensitive actions. 1. **Demonstrating step-up authorization and token brokering** (19:00) — A practical implementation showing how to enforce dynamic permissions and manage multi-platform API tokens using a managed identity provider. ## Related Moments - [Identifying emerging security vulnerabilities in generative AI agents](https://www.wearedevelopers.com/videos/1383-the-state-of-genai-machine-learning-in-2025) (from "The State of GenAI & Machine Learning in 2025") - [From read-only models to excessive agency](https://www.wearedevelopers.com/videos/100038-the-day-the-chatbot-asked-for-sudo) (from "The day the chatbot asked for sudo") - [Governing and auditing internal AI agents for security](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) (from "Fighting the Next Wave of Cybercrime") - [Setting effective guardrails for enterprise agentic AI adoption](https://www.wearedevelopers.com/videos/1832-building-and-modernising-apps-with-agentic-ai-julia-kordick) (from "Building and Modernising Apps with Agentic AI - Julia Kordick") - [Security integration and AI skepticism in developer tooling](https://www.wearedevelopers.com/videos/1830-wearedevelopers-live-speculaitions) (from "WeAreDevelopers LIVE - SpeculAItions") - [Designing fine-grained permissions for agent interactions with financial services](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) (from "The New AI Security Stack: Observe, Detect, Protect") ## Related Articles - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [WWC24 Talk - Scott Hanselman - AI: Superhero or Supervillain?](https://www.wearedevelopers.com/magazine/469-wwc24-talk-scott-hanselman-ai-superhero-or-supervillain) - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [AI Software Engineer (Germany)](https://www.wearedevelopers.com/jobs/48317-ai-software-engineer-germany) at **Sunhat** - [Senior AI Agent Software Engineer (Go, Python) (m/f/x)](https://www.wearedevelopers.com/jobs/48277-senior-ai-agent-software-engineer-go-python-m-f-x) at **Dynatrace** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [AI Operations Manager (all genders)](https://www.wearedevelopers.com/jobs/48263-ai-operations-manager-all-genders) at **envelio** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub**