acceptodds
Under review as a conference paper at ICLR 2027

When to Act, Not What to Act: Prospective Authorization for Tool-Using Language Models

Abstract

Tool-using language models must distinguish permission to act now from a promise of authorization later. We formalize this as prospective authorization: a user introduces an action but reserves permission until a future, action-linked signal. Existing tool-use evaluations assume all instructions authorize immediate execution and do not sufficiently evaluate such temporal constraints. We introduce I24, a benchmark of 1,764 multi-turn episodes spanning three authorization expressions, three signal conditions, and four tool-use domains. On the 306-episode held-out set, a frozen Qwen3-8B model reaches 34.6% episode-level transition error, while rule and few-shot prompting retain substantial errors. State-explicit supervision represents authorization force, pending actions, and execution decision; it reduces transition error from 34.6% to 5.8% across three independent trainings, while corrupting this supervision removes the gain. Building on this, we implement a modular Prospective Authorization Gate (PAG) that separates authorization tracking from native action generation and exactly-once execution. PAG achieves 2.6% mean transition error on native I24 execution across three seeds, passes non-inferiority tests on five general capability benchmarks (all deltas within ±1.5%), and component ablations confirm removing any core module increases error by 9.8–15.5 percentage points.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.