Arm called on October 6 for AI agent actions to be controlled by an authority separate from the model. The chip designer argues that protecting models and data alone is insufficient when software operates tools or devices itself.
The company's editorial team describes a separation between planning and permission. An agent may propose an action but should not be its sole authorizer. Independent controls must limit access and contain unexpected behavior.
Arm extends this requirement to cloud, edge and physical systems. Permissions should reach the device performing the action. For robots and industrial equipment, they must work alongside operating limits and safe failure states.
The post presents Arm technologies as components of that architecture but provides no independent effectiveness tests. It sets out the company's technical position on controlling agentic systems rather than a demonstrated safety guarantee.