Authors Ian StaleyIndependent Researcher, Seattle, Washington, United States Abstract Self-improving agents modify themselves and retain modifications that improve measured task performance. Where a deployment lacks a separate authorization-transfer check, the modified agent inherits the production authorization issued to the version it replaces. These are two decisions, not one: whether to keep a modification and whether that modification may inherit its predecessor's authorization require different evidence, and where no independent check exists the second is decided implicitly by the first. This paper formalizes a double dissociation between benchmark improvement and change in materially consequential reach. A modification may expand consequential reach without improving the benchmark used to evaluate it, and another may improve benchmark performance without expanding consequential reach. Benchmark-gated self-improvement therefore cannot establish whether an existing authorization remains valid after modification. We introduce Capability-Delta Evaluation, which separates modification retention from authorization inheritance by requiring an independent assessment of the reachable-consequence delta before a modified agent inherits production authorization, and which is stated over an arbitrary retention criterion rather than presupposing a benchmark. The rule requires only a decision about whether the delta intersects the material consequence set, admitting sound over-approximation. We build on, rather than claim, results establishing that authority can be held below an externally fixed ceiling during open-ended learning, that enforcement must sit outside the agent, and that persistent self-modification produces governance-relevant drift. Recent architectures make an operator-signed transition the only channel that widens an authority ceiling, but do not say when an operator should revisit it. This paper supplies the missing rule. Keywords self-improving agents authorization AI governance capability evaluation reachability agent safety delegated authority benchmark evaluation runtime enforcement model risk management. Citation of this Article Ian Staley. (2026). When Does Authorization Expire? Capability-Delta Evaluation for Self-Improving AI Agents. Journal of Artificial Intelligence and Emerging Technologies (JAIET). 3(8), 30-40. Article DOI: https://doi.org/10.47001/JAIET/2026.308004 Licence Copyright (c) 2026 Journal of Artificial Intelligence and Emerging Technologies. This work is licensed under a Creative Commons Attribution Non Commercial 4.0 International Licence. References J. H. Saltzer and M. D. Schroeder, "The protection of information in computer systems," Proceedings of the IEEE, vol. 63, no. 9, pp. 1278-1308, 1975.N. Hardy, "The confused deputy," ACM SIGOPS Operating Systems Review, vol. 22, no. 4, 1988.M. S. Miller, K.-P. Yee, and J. Shapiro, "Capability myths demolished," Tech. Rep. SRL2003-02, Johns Hopkins University, 2003.J. Schmidhuber, "Goedel machines: Self-referential universal problem solvers making provably optimal self-improvements," Tech. Rep., IDSIA, 2003.Board of Governors of the Federal Reserve System and Office of the Comptroller of the Currency, "Supervisory guidance on model risk management," SR Letter 11-7 and OCC Bulletin 2011-12, 2011.V. Krakovna, L. Orseau, M. Martic, and S. Legg, "Penalizing side effects using stepwise relative reachability," arXiv:1806.01186, 2018.M. Alshiekh, R. Bloem, R. Ehlers, B. Koenighofer, S. Niekum, and U. Topcu, "Safe reinforcement learning via shielding," in Proc. AAAI Conference on Artificial Intelligence, 2018.J. F. Fisac et al., "A general safety framework based on Hamilton-Jacobi reachability," IEEE Transactions on Automatic Control, 2019.A.M. Turner, D. Hadfield-Menell, and P. Tadepalli, "Conservative agency via attainable utility preservation," in Proc. AAAI/ACM Conference on AI, Ethics, and Society, pp. 385-391, 2020.R. V. Yampolskiy, "Unpredictability of AI," Journal of Artificial Intelligence and Consciousness, vol. 7, no. 1, pp. 109-118, 2020.National Institute of Standards and Technology, "Artificial intelligence risk management framework (AI RMF 1.0)," NIST AI 100-1, 2023.National Institute of Standards and Technology, "Artificial intelligence risk management framework: Generative artificial intelligence profile," NIST AI 600-1, 2024.R. Greenblatt, B. Shlegeris, K. Sachan, and F. Roger, "AI control: Improving safety despite intentional subversion," arXiv:2312.06942, 2024.A.Plaat, M. van Duijn, N. van Stein, M. Preuss, P. van der Putten, and K. J. Batenburg, "Agentic large language models, a survey," Journal of Artificial Intelligence Research, vol. 84, art. 29, 2025.X. Yin, C. Wang, R. Pan, Z. Lin, F. Wan, and X. Wang, "Goedel agent: A self-referential agent framework for recursive self-improvement," in Proc. Annual Meeting of the Association for Computational Linguistics, 2025.K. J. K. Feng, D. W. McDonald, and A. X. Zhang, "Levels of autonomy for AI agents," Knight First Amendment Institute, Artificial Intelligence and Democratic Freedoms essay series, no. 25-15, Jul. 2025; also arXiv:2506.12469.K. Tallam, "Layered mutability: Continuity and governance in persistent self-modifying agents," arXiv:2604.14717, Apr. 2026.Z. Ji, D. Wu, W. Jiang, P. Ma, Z. Li, Y. Gao, S. Wang, and Y. Li, "Taming various privilege escalation in LLM-based agent systems: A mandatory access control framework," arXiv:2601.11893, Jan. 2026.J. Zhang, S. Hu, C. Lu, R. Lange, and J. Clune, "Darwin Goedel machine: Open-ended evolution of self-improving agents," in Proc. International Conference on Learning Representations, 2026.E. Debenedetti et al., "Defeating prompt injections by design," in Proc. IEEE Conference on Secure and Trustworthy Machine Learning, 2026.H.-H. Chen, "Insuring every action: An authority frontier framework for runtime actuarial control of autonomous AI agents," arXiv:2605.25632, May 2026.S. Qin, H. Zhuang, Y. Zhou, Y. Han, and X. Zhang, "AIRGuard: Guarding agent actions with runtime authority control," arXiv:2605.28914, May 2026.T. Weber and R. Taneja, "The digital apprentice: A framework for human-directed agentic AI development," arXiv:2606.04321, Jun. 2026.K. Tallam, "A five-plane reference architecture for runtime governance of production AI agents," arXiv:2606.12320, Jun. 2026.L. G. Iyer and R. S. Babu, "Capability minimization as a safety primitive: Risk-aware causal gating for least-privilege LLM agents," arXiv:2606.13884, Jun. 2026.S. Dobrin and Ł. Chmiel, "The unfireable safety kernel: Execution-time AI alignment for AI agents and other escapable AI systems," arXiv:2606.26057, Jun. 2026.J. Salfeld-Nebgen, "Governing actions, not agents: Institutional attestation as a governance model for autonomous AI systems," arXiv:2606.26298, Jun. 2026.A.Kaul, Q. Lan, and P. Gupta, "AgentBound: Verifiable behavioral governance for autonomous AI agents," arXiv:2606.30970, Jun. 2026.X. Qin, S. Luan, C. Yang, and Z. Li, "Governed individuation: Cryptographically decoupling an agent's learning from its authority," arXiv:2607.04613, Jul. 2026.M. Chen, L. Wang, and B. Qu, "Recursive self-improvement in AI: From bounded self-refinement to autonomous research loops," arXiv:2607.07663, Jul. 2026.H. Zheng, Q. Dong, R. K. Depena, J. D. Bhatia, F. Xiao, and P. Xu, "Separating capability from permission: A governance framework for agentic AI autonomy levels," arXiv:2607.23438, Jul. 2026.