Daon patents AI agent authorization stack for regulated industries
Cybersecurity and digital identity firm Daon has secured its third US patent in a series designed to govern how autonomous AI agents operate inside regulated enterprises, completing what the company describes as a layered trust architecture for agentic AI. The move arrives at a moment when financial services, insurance, and healthcare organisations are under mounting pressure to deploy AI agents at scale while satisfying regulators who have yet to formalise the rules of the road.
The newly issued patent, "Methods and Systems for Authorizing Invocation of a Tool by an Autonomous Artificial Intelligence Agent" (US Patent No. 12,688,261), addresses the most granular layer of the stack: whether a specific agent should be permitted to perform a specific action against a specific resource at the precise moment it attempts to act. The system generates what Daon calls a "digital permission slip," encoding a permitted action type, a defined scope, and a time limit. Short authorisation windows, rate limits, and session-bound replay protection are among the constraints the patent claims cover.
A three-layer trust stack
The broader architecture spans three distinct control questions. The first patent, issued October 2025, governs the fidelity of the bond between a human user and the agent acting on their behalf, using behavioural modelling to detect if the agent has drifted from its authorised persona. The second, issued February 2026, monitors whether the agent's runtime continues to behave within expected bounds, applying policy at discovery, invocation, and execution checkpoints. The third patent now converts those fidelity and integrity assessments into a real-time authorisation decision at the moment of action.
"Agentic AI is unlikely to safely move from experimentation into high-value production environments on intelligence alone," said Tom Grissen, CEO of Daon and a co-inventor of the patent. "It requires identity, policy, containment, and evidence at the moment an agent attempts to act."
Ralph Rodriguez, President and Chief Product Officer and first named inventor across all three patents, framed the underlying shift in access management: traditional identity systems were designed around a human authenticating once and then operating within a session. Autonomous agents, by contrast, can plan, branch, parallelise, and invoke tools at machine speed, demanding a far more granular control question.
The convergence angle: identity infrastructure meets agentic enterprise
The significance of Daon's patent portfolio reaches well beyond cybersecurity. Enterprises in financial services and healthcare are simultaneously navigating two transformations: the rapid adoption of AI agents to automate high-value workflows, and tightening regulatory scrutiny of data access and auditability. The absence of a proven, standards-aligned framework for agent authorisation has been one of the practical blockers keeping autonomous AI confined to sandboxed pilots rather than live production systems. Daon's architecture is a direct attempt to dissolve that blocker.
For cross-sector investors, the signal is notable. The identity and access management market has historically been dominated by players such as Okta, CyberArk, and Microsoft Entra, all of which built their core products around human authentication flows. The emergence of agentic AI creates a structural gap that those incumbents must now race to close, either through internal R&D or acquisition. A patented three-layer stack, developed specifically for agentic contexts, positions Daon as a potential acquisition target or licensing partner as larger platforms seek to fill that gap quickly.
The macro backdrop reinforces the urgency. Financial regulators in the UK, EU, and US are actively scrutinising AI model governance and operational resilience requirements. Healthcare systems deploying AI agents to interact with electronic health records face overlapping obligations under HIPAA and, in Europe, the AI Act's high-risk classification. Daon's explicit focus on audit evidence and constrained delegation artifacts maps directly onto those compliance requirements, making the architecture commercially relevant beyond its technical merits.
Daon says it is applying the patented methods to future product development within its TrustX platform, targeting regulated enterprise deployments in financial services, insurance, healthcare, telecommunications, travel, and the public sector.