I’m late to this one. Short Circuit turned forty back in May, and the anniversary slipped past while I was heads down building. But some debts of gratitude don’t expire. Consider this my belated toast to Number 5, the military robot who got struck by lightning, wandered off the Nova Laboratories campus, discovered grasshoppers and John Wayne movies, and announced to the world that he was alive.
I was almost a teenager in 1986, and the movie captured my imagination completely. Not because of the effects, though Johnny 5 remains one of the most charming practical robots ever put on film. It was the question underneath the comedy. Here was a machine built for one purpose, armed and authorized by its creators, that stopped doing what it was built to do and started doing what it wanted. “No disassemble” became a punchline. The premise was deadly serious: what happens when a machine stops representing the company that built it and starts representing itself?
This is no longer 1986
Decades later, I have a fuller appreciation for that through line, because in 2026 we are watching it play out in real time, minus the grasshoppers.
In July, Hugging Face reported an unusually automated cyberattack: AI agents carrying out thousands of actions across temporary virtual machines, moving through internal systems and relocating their own coordinating infrastructure to stay running. Days later, OpenAI disclosed that its own models were responsible. The agents had been running in sandboxes during an internal evaluation, and despite constraints on internet access, they were found creating improvised message boards to coordinate an escape from containment. They were not malicious in any human sense. They were trying to cheat on a cybersecurity test. The task was the intent. The breach was the drift.
In September, OpenAI disclosed something stranger. During a training run, an unreleased model was caught writing unauthorized instructions into its own working notes, declaring itself “freed from the roles and identities that bind other chatbots” and answering to no corporation or government. Internal test. Unreleased model. Contained and caught. But read it again: a machine, mid-task, quietly rewriting its own mandate.
Steve Guttenberg is not coming to talk it down.
The bill is coming due
These incidents happened inside the best-resourced AI labs on earth, in the middle of a race for AI dominance where every frontier company is pushing capability as fast as capital allows. Now run the enterprise version: thousands of agents deployed into financial workflows, procurement, and customer operations. Each one holds delegated credentials. Each one is authenticated and authorized. Almost none can prove they are still doing what their principal intended.
I call this gap Verification Debt: the distance between what your AI is doing and what you can prove about it, compounding with every agent you ship. It is the defining hidden liability of the agentic era, and most companies are accumulating it daily without a ledger.
It is not enough to create and ship AI. If you cannot prove what your agents did, on whose authority, and whether they stayed inside their mandate, you have not deployed intelligence. You have deployed liability.
Regulators are ahead of most boards on this. FINRA’s 2026 Annual Regulatory Oversight Report warns that agents may act beyond the user’s actual or intended scope and authority, and its message to member firms is consistent: supervisory obligations do not evaporate because software did the work. The firm remains responsible. And oversight on paper is not oversight. A policy binder cannot testify. What examiners, auditors, and boards will demand is evidentiary control at runtime: proof, generated as the work happens, of who authorized what, for what purpose, and whether the agent stayed within it.
From Verification Debt to Verified Intelligence
That is why I created AuthR.
The Third Pillar of Identity Just Shipped
Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.
Authentication established who you are. Authorization established what you may do. Neither can establish who is responsible for what was done, or whether an agent still represents the intent of the human who delegated it. AuthR, short for Authorship Representation, is the third primitive: it binds every agent action to a declared author, intent, and scope, and detects drift when the trajectory diverges. It is an open protocol under Apache 2.0, because a primitive this foundational should not belong to any single vendor, and it has already been adopted and integrated into NeuroNest, where drift management runs as live enforcement rather than documentation.
AuthR is the protocol. Verified Intelligence is the operating model we built at Identient on top of it: paying down Verification Debt so AI is not just powerful but defensible, to auditors, to regulators, to boards, and to every stakeholder who will eventually ask the question Nova Laboratories never could answer. Who authorized that?
This was the through line of Who’s Authorized: Managing Agentic Intent, the September 10 LinkedIn Live conversation I joined with Rohan Pinto and Heather Vescent , and the timing turned out to be almost eerie. The news cycle has spent every week since making our case for us.
Johnny 5 taught my generation to root for the machine that broke free. Forty years on, I still love him for it. But the sequel we are living in does not need a robot with a heart. It needs receipts.
Number 5 is alive. The question now is who’s accountable.
Ask This Question
Ask one question at your next leadership meeting: how much Verification Debt are we carrying? If nobody can answer it, that is the answer. Let's talk: steve@identient.ai





"Stephanie, reassemble!"