IT Brief Ireland - Technology news for CIOs & IT decision-makers
Ireland
Daon wins patent for real-time AI agent authorisation

Daon wins patent for real-time AI agent authorisation

Wed, 29th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Daon has secured a US patent for a system that authorises AI agent requests in real time. It is the third patent in the company's agentic AI governance portfolio.

The patent covers a method for deciding whether an autonomous agent may carry out a specific action against a protected tool, service, account or application programming interface. The system assesses the agent's link to the person it is acting for, the integrity of its behaviour and the context of the requested action before issuing a tightly limited authorisation.

The move comes as banks, insurers, healthcare groups and other regulated organisations test AI agents for tasks involving sensitive records, transactions and internal systems. These sectors face a particular challenge in allowing software to act with some autonomy while still controlling who it acts for, what it can do and how long that authority lasts.

According to Daon, the newly patented process creates a "digital permission slip" for each approved action. That permission can be restricted by action type, scope and time limit. The patent also covers features including short authorisation windows, rate and transaction limits, execution-context binding and session-tied replay protection.

Three-layer model

The latest patent completes a three-part architecture Daon has been building around AI agent governance. The first patent addresses whether an AI agent remains faithfully linked to the intended person. The second focuses on whether the agent and its runtime environment continue to behave within expected limits.

This third patent shifts the decision point to the moment an action is attempted. Rather than relying on a single human login or broad permissions granted in advance, the approach aims to authorise or deny each sensitive action individually.

Tom Grissen, Chief Executive Officer at Daon, described the patent as a response to a gap between experimental AI deployment and operational use in more tightly controlled sectors. "Agentic AI is unlikely to safely move from experimentation into high-value production environments on intelligence alone. It requires identity, policy, containment, and evidence at the moment an agent attempts to act," he said.

He added: "This patent strengthens Daon's ability to help enterprises move beyond the false choice between blocking autonomous agents and granting them broad standing authority."

Regulated use

The framework is intended for industries including financial services, insurance, healthcare, telecommunications, travel and hospitality, and the public sector. In those settings, AI agents could retrieve records, prepare transactions, assist staff, analyse claims, assemble documents or interact with protected operational systems.

Such uses raise a more specific access-control question than conventional identity systems were built to answer. Traditional identity and access management generally assumes that a human user authenticates and then operates within a session. Autonomous agents, however, may plan, branch, run parallel tasks and invoke tools without direct human action at each step.

Ralph A. Rodriguez, President and Chief Product Officer at Daon, said that changes the nature of authorisation. "Traditional identity and access management was designed around a human authenticating and then operating within a session.

"Autonomous agents can plan, branch, parallelize, and invoke tools at machine speed. This requires the control question to become more precise. Should this agent be allowed to perform this exact action, against this exact resource, right now?"

He added that the company's research focuses on linking three checks: whether the agent remains tied to the right person, whether its behaviour remains within expected bounds and whether a requested action should be allowed under specific limits. "Our research creates a practical trust stack for safe agentic AI. Namely, to maintain fidelity to the person, assess integrity of the agent and its runtime, and authorize or constrain each sensitive action."

Broader portfolio

The patent reflects longer-term research through Daon Labs, where the company has developed a portfolio of more than 320 patents across biometric authentication, deepfake defence, digital identity, agentic AI and other security fields. The latest filing extends that work into the governance of autonomous software actors, an area drawing increasing attention as companies look for ways to introduce AI agents into customer service, operations and internal workflows.

One possible use case would let an agent review account data or prepare a draft while still requiring approval from the relevant person before an irreversible action such as a payment, identity change, trade execution or release of sensitive information. That would allow narrower permissions and a shorter decision window for high-risk actions, rather than broad standing access from the outset.

Taken together, the three patents are designed to answer three connected questions for regulated businesses: whether the agent is still acting for the intended person, whether it is behaving as expected and whether a specific action should be allowed at that moment.