arXiv · 2609.23226
Security of Agent-Integrated Software: When Human Operations and Agent Actions Coexist
Abstract
Agent-Integrated Software (AIS) embeds an intelligent agent in a conventional application, supporting both human operations and agent actions. Human operations let users make precise changes and inspect results, while agent actions carry out routine or multi-step tasks. These complementary roles make coexistence a likely long-term feature of many software systems. Human operations and agent actions affect the same software state and can use one another's results. Therefore, security policies must remain effective across both paths. We argue that AIS security must be assessed at the level of the whole software system. Protecting the agent and the conventional software core separately does not establish that they are secure together. To guide security analysis of AIS as a whole, we organize the problems arising from this coexistence into four categories: context misuse, authorization violation, execution control, and effect integrity. Using these categories, we examine how current practices address the security problems in AIS and where their protection remains limited. Building on this analysis, we identify research opportunities in preserving information provenance, enforcing policy across operation paths, maintaining valid authorization over time, and managing persistent effects and recovery. This resulting perspective provides a conceptual framework for understanding and improving the security of AIS.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Ding Yang, Yuchen Ling, Shengcheng Yu, Zhenyu Chen, Chunrong Fang. 2026-09-19. Security of Agent-Integrated Software: When Human Operations and Agent Actions Coexist. https://arxiv.org/abs/2609.23226
Cite the original work for its findings. Save a collection to share your selection of sources.