Social Sciences · Research topic

Open research questions in Access Control and Trust

62 unresolved questions extracted from the limitations and future-work sections of 253 Access Control and Trust papers in our library. Each links back to the study that raised it.

What the literature leaves open

  • The relevance-authorization gap, where retrieval systems rank documents by relevance rather than authorization. Tool-mediated disclosure, where agents invoke tools with agent credentials rather than end-user authorization. Context accumulation, where multi-turn conversations persist context without per-turn policy re-validation.

    Securing the Agent: Vendor-Neutral, Multitenant Enterprise Retrieval and Tool Use · 2026 · DOI
  • Security risks in LLM-assisted software development. Lack of access to current enterprise standards. Hallucinated APIs.

    RAG-SecCode: Retrieval-Augmented Secure Coding Guidance for Enterprise LLM Software Development · 2026 · DOI
  • Making every transition explicit and rejecting any transition whose warrant is absent. Separating proof and evidence from consent, standing, ethical permission, jurisdiction, and execution authority. Constructing a sixteen-field review ledger and preserving refusal and authority lineage.

    PECAN - Proof-Ethics Crossing And Authorization Nexus · 2026 · DOI
  • BOLA attacks can be launched by manipulating API parameters. The resource ID can be tampered with to access sensitive data. The lack of effective defense methods against BOLA attacks.

    Rethinking Broken Object Level Authorization Attacks Under Zero Trust Principle · 2026 · DOI
  • The infrastructure that makes AI agents capable has outrun the infrastructure that makes them safe. AI agents operate with the power of a networked software system and the trust model of a demo.

    SALUCA: Shield Around Local Unprotected Computerized Agents · 2026 · DOI
  • Further study of the implications of high-risk permission defaults for meaningful user consent. Examination of the effectiveness of automated permission review systems.

    Permission by Default: Privacy, Consent, and the Expanding Authority of OpenAI's Desktop AI Agents · 2026 · DOI
  • The gap between the author-observed interface and the published documentation. The lack of understanding of the implications of high-risk permission defaults for meaningful user consent.

    Permission by Default: Privacy, Consent, and the Expanding Authority of OpenAI's Desktop AI Agents · 2026 · DOI
  • The need for a formal verification architecture for certifying specified behavioral transitions in sovereign AI systems. The lack of a framework that separates cryptographic validity, formal validity, robustness under specified perturbations, and empirical behavioral observation.

    URVSO_Formal_Verification_Core_Sovereign_AI_Transition_Systems.pdf · 2026 · DOI
  • Lack of a principled basis for organizational authorization of autonomous AI agents. Existing frameworks do not provide end-to-end, testable governance mechanisms. Need for a governance-first architecture that reframes the authorization question.

    LATTICE: a governance-first architecture for authorized autonomous AI operations · 2026 · DOI
  • At the broader level, supply-chain integrity, provenance, accountability, and end-to-end observability remain largely open problems.

    Securing Agentic AI: From Per-Action Checks to Trajectory Assurance · 2026
  • Despite the security implications of these permission grants, the M365 ecosystem has not been systematically studied.

    Lost in Permissions: Exploring the Microsoft 365 App Ecosystem · 2026
  • These experiments use three mechanism-design variables--the evidence channel, collection policy, and release transformation--but MID is not limited to these choices and can accommodate other deployable mechanisms.

    Privacy-Preserving AI Verification via Minimal Information Disclosure · 2026
  • Provides broad network-level access, facilitating lateral movement for insider threats. Rule-based only; fails to adapt to evolving threats or understand user behavior. Time-consuming and inconsistent; lacks the scalability needed for dynamic environments. B. Problem Statement, Aim & Objectives The AI-driven Zero Trust Network Access (ZTNA) system is designed to overcome the limitations of traditional network security by integrating artificial intelligence with advanced access control mechanisms. The system ensures secure, real- time, and context-aware access to organizational resources by identity verification, contin- uous implementing strong authentication, and secure communication across cloud and hybrid environments. 1) Problem Statement: Traditional security models and Virtual Private Networks (VPNs) rely on perimeter-based protection and implicit trust once a user gains access. This approach makes systems vulnerable to insider threats, cre- dential misuse, and lateral movement attacks. Additionally, these solutions lack intelligent automation for continuous verification and real-time threat detection. The proposed sys- tem addresses these issues by developing an AI-powered ZTNA platform that provides context-aware access control, continuous monitoring, and real-time threat detection.

    ZTNA – Zero Trust Network Access · 2026 · DOI
  • This revised paper makes a narrower but substantially stronger claim than the original manuscript lineage. TrustDS contributes a policy-compiled governance layer for cross- cloud marketplace analytics: policies are turned into executable guards, PET choice and placement are planned jointly, and each release is paired with portable evidence. Under explicit assumptions, the formal model supports policy safety and passive-adversary confidentiality modulo explicit leakage; empirically, the prototype improves latency over two operational baselines while preserving dynamic-consent coverage and bounded release-path delay. The most important next steps are now clear. Future work should add machine-checked semantics, broader malicious-security backends, fault-injection campaigns under sustained WAN partitions, stronger utility analyses for DP releases, and public archival deposition of the full benchmark artifact with a persistent DOI. Those extensions would strengthen the framework further, but they are no longer prerequisites for interpreting the present claims correctly.

    TrustDS: policy-compiled governance and verifiable evidence for cross-cloud marketplace analytics under explicit security assumptions · 2026 · DOI
  • Emerging opportunities in automation, artificial intelligence, and adaptive security systems should be explored. The paper suggests that future research should focus on addressing the challenges and limitations of Zero Trust Architecture.

    Zero Trust Architecture in Enterprise Networks · 2026 · DOI
  • The traditional perimeter-based security models are increasingly ineffective. The assumption that internal networks are inherently secure no longer holds true. There is a need for a new security framework that can address modern cybersecurity threats.

    Zero Trust Architecture in Enterprise Networks · 2026 · DOI
  • Current AI governance approaches are inadequate. OS-layer governance is not yet standardized.

    The Hamecohming Framework: Enterprise_AI_Governance_AbsoluteSecretTag · 2026 · DOI
  • Developing effective access control mechanisms for institutional systems. Integrating security models into APIs. Addressing the gap in current access control systems.

    DISEÑO DE UN MODELO DE CONTROL DE ACCESO BASADO EN ROLES Y SEGURIDAD A NIVEL DE FILAS EN APIS ACADÉMICAS · 2026 · DOI
  • The study proposes validating the model in real systems as future work. The study suggests exploring the application of the proposed model in different domains and contexts.

    DISEÑO DE UN MODELO DE CONTROL DE ACCESO BASADO EN ROLES Y SEGURIDAD A NIVEL DE FILAS EN APIS ACADÉMICAS · 2026 · DOI
  • Classical Public Key Infrastructure provides static identity guarantees but cannot guarantee that a given transaction originates from that entity at that moment. This gap enables replay attacks, key reuse vulnerabilities, and long-term compromise cascades.

    EIDA: Ephemeral Identity Distribution Architecture · 2026 · DOI
  • Existing application security frameworks address the security vulnerabilities of large language model systems in legal technology platforms incompletely. There is a need for a formal operational model to protect against prompt injection and insecure output handling.

    Formal Operational Models for Protecting Web Interfaces of Legal LLM Systems from Prompt Injection and Insecure Output Handling · 2026 · DOI
  • The current audit infrastructure is insufficient for autonomous artificial intelligence. There is a need for a method to prove that each action conformed to the applicable rules at the time it was taken.

    Provably Compliant Autonomous Actions: A Consensus Enforced, Dual Authority Certification Gate with Freshness Bound Per Action Proofs · 2026 · DOI
  • Future secure coding assistants may function as enterprise knowledge interfaces. Retrieval augmentation can be applied to other knowledge-intensive tasks.

    RAG-SecCode: Retrieval-Augmented Secure Coding Guidance for Enterprise LLM Software Development · 2026 · DOI
  • The paper suggests that future research should focus on developing more effective and fair AI security taxonomies, based on harm-based classification and an extramural adversarial record. The paper suggests that future research should examine the implications of this approach on the security-law panel of the Meaning Feudalism series.

    Adversarial by Origin: How the Classification of External Influence on Machine Meaning Becomes Law Without Becoming Jurisprudence (EA-SEI-ADVERSARY-01 v1.0) · 2026 · DOI
  • The paper identifies a gap in the current approach to AI security taxonomies, which prioritizes origin-based classification over harm-based classification. The paper argues that this gap must be addressed in order to develop more effective and fair AI security taxonomies.

    Adversarial by Origin: How the Classification of External Influence on Machine Meaning Becomes Law Without Becoming Jurisprudence (EA-SEI-ADVERSARY-01 v1.0) · 2026 · DOI

Most-cited papers in Access Control and Trust

Most recent work

Find a gap in your own Access Control and Trust sub-topic

This page shows what the Access Control and Trust literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.

Open the Research Gap Finder →

Related topics in Social Sciences

62 open questions have been extracted from the limitations and future-work passages of 253 Access Control and Trust papers in our library. Each one below links back to the study that raised it, so you can read the original claim in context.

Tools for your next paper

Compare the categoryHonest roundups of the AI research tools, ours listed alongside the alternatives.

Command palette

Jump anywhere, run any action.