iProov targets human approval gap as AI agents gain autonomy

September 22, 2026
12:58PM PHT

Insider Spotlight

  • iProov is targeting a governance gap in agentic AI: having permission to act does not necessarily prove that a human approved a specific action
  • Its proposed framework focuses human checks on sensitive or critical actions rather than every step an AI agent takes
  • The company is publishing the specification openly to encourage scrutiny, feedback and independent implementations



As AI agents gain the ability to act autonomously across digital services, organizations face a growing governance problem: an agent may have legitimate access credentials while still taking an action its human user never specifically intended or approved.

iProov is proposing a way for receiving systems to distinguish between those two conditions.

Independent implementations

The biometric identity verification company has published the Human Approval and Presence Specification, or HAPS, an experimental procedural specification designed to verify human approval before selected AI-agent actions proceed.

Published on GitHub under an Apache-2.0 license, HAPS includes rules, a partial Rust reference implementation and test vectors. iProov is inviting industry experts to scrutinize the approach, provide feedback and develop independent implementations.

 Andrew Bud, founder and CEO of iProov | Contributed photo

Misuse of credentials

The framework addresses situations where an AI agent remains within its granted permissions but takes unintended actions because of factors such as prompt injection, excessive goal-seeking or misuse of delegated credentials.

“AI agents are moving rapidly from answering questions to taking actions on our behalf. As their autonomy and capabilities grow, governance must keep pace,” iProov founder and CEO Andrew Bud said in a press statement.

“We need to distinguish between an agent having permission to act and a human actually approving the specific action it is about to take. HAPS is a specification that makes that human approval verifiable. We’re publishing it openly at this experimental stage because the industry needs to solve this challenge together. We’re inviting the community to scrutinize it, challenge it, and build on it so together we can establish strong, practical safeguards for an agentic AI world,” he added.

Evidence of human presence

Organizations determine which actions are sufficiently sensitive or critical to warrant additional approval. When triggered, HAPS calls for the action to pause, show the human what the agent intends to do, obtain evidence of human presence and approval, and verify that evidence before proceeding.

The approval is securely linked to the specific requested action, allowing the receiving organization to check whether the authorization matches what the agent is attempting to execute.

Agent-resistant proof

HAPS does not prescribe a particular method for proving human presence. iProov said it has developed an internal implementation using biometric liveness as one example of an agent-resistant proof, while keeping the specification itself proof-agnostic. —Vanessa Hidalgo | Ed: Corrie S. Narisma

Featured News
Explore the latest news from InsiderPH
Tuesday, 22 September 2026
Insight to the one percent
© 2024 InsiderPH, All Rights Reserved.