Definition
Approval laundering is a failure to preserve the binding between the action a person approves and the action or effects an agent harness executes. Approval appears to authorize the work, but scope, arguments, identity, timing, delegation, or downstream behavior changes what actually happens.
An approved commit command, for example, can trigger a repository hook that modifies an additional file. Checking the command string alone does not establish approval for that additional effect.
Origin and evidence
Yang Wang's September 30, 2026 preprint uses the label for six classes: scope, argument, temporal, tool, delegation, and semantic laundering. Its controlled study instruments one coding-agent harness and tests a prototype approval token bound to recorded invocation fields.
The prototype addresses some seeded cases but does not solve effects that occur below those fields. Wang's paper documents this taxonomy and use of the label; it does not establish the first use of the phrase in every domain.
Scope and evidence limits
The taxonomy is working terminology from a controlled study. Its measured failure rates should not be generalized to every harness or production workload.
A separate October 2026 preprint on intent-execution correspondence studies tool calls altered along their execution path. Such alteration can be accidental. It is related to approval integrity, but a changed tool call alone does not establish that a human approval was laundered.
Operational significance
An approval needs a stated scope: which principal, agent, session, tool, arguments, resources, duration, and effects it permits. Enforcement then needs to preserve that scope through dispatch, delegation, hooks, scripts, and other reachable behavior.
Signing invocation fields can detect changes to those fields. It cannot establish that a called program's hidden effects fit the approved scope. Combine invocation integrity with resource controls, review of executable extensions, and evidence of the effects that actually occurred.
Inspect the enforcement point and its coverage. A visible approval prompt records the user's response; additional controls have to preserve its scope through execution.
Distinguish it from nearby terms
- Prompt injection supplies instructions through an untrusted channel. Approval laundering describes the approval-to-execution gap and need not assume an attacker.
- Excessive agency grants too much authority. Approval laundering can arise even when the intended grant is narrow.
- Approval fatigue concerns human scrutiny of repeated requests. Laundering concerns whether execution preserves a grant.
- An execution trace records activity. It proves approval integrity only if it captures the relevant authorization and effects.
Check your understanding
A person approves adding one file to a commit. A pre-commit hook stages another file while the recorded command and arguments stay unchanged. Which boundary failed, and why would signing only those arguments miss it?