---
title: Least privilege for AI agents is an optimisation problem. We ran it on a quantum computer.
description: An AI agent that can both raise and approve a purchase order has to be split in two. Deciding how is a hard optimisation problem, and the kind quantum computers are sold for. We ran a ten-tool version on IBM's ibm_fez, checked every answer against the true optimum, and found the thing that decides whether today's hardware helps at all. Four questions for you at the end.
author: CISO AI
published: 2026-10-08
tags: quantum computing, ai agents, least privilege, separation of duties, optimisation
image: /intel/og-card-least-privilege.png
imageSize: 1200x630
---

Give an AI agent a tool and it keeps it. A procurement agent that started with two tools gains a payments tool when someone wires up a new workflow, a shell tool when a developer is debugging, and a vendor tool because the onboarding team asked. Six months later it can raise a purchase order, create the vendor, approve the order and release the payment, which is the combination every fraud control in the company exists to prevent.

Humans have had a fix for this for decades, segregation of duties: nobody holds both halves of a toxic pair. For agents the fix is the same, with a twist. Splitting an agent in two is easy. Splitting it well is not, because the tools that conflict are usually the tools that get used together, and a child agent that holds half of every workflow is useless. Choosing the split that breaks every toxic pair while breaking as few working relationships as possible is an optimisation problem of the kind mathematicians call NP-hard, and the kind quantum computing vendors say their machines are for.

In a companion piece, [The Army put its convoys on a quantum computer](/analysis/army-quantum-convoys-we-ran-ours), we ran a convoy routing problem on the same hardware: choose a road for each of up to twelve Army convoys so that the last one arrives as early as possible, the problem Q-CTRL and the Australian Army used in their quantum case study. The quantum computer did little better than guessing. We ran the agent problem on the same machine, on 8 October, and the result was different in a way that tells you what to ask a vendor. The comments are open at the bottom.

## The problem

Take an agent with ten tools: read vendors, raise purchase orders, approve purchase orders, create vendors, release payments, read files, write files, fetch web pages, post to the web, and run shell commands. Four pairs are toxic. An agent must not both raise and approve an order, create a vendor and pay it, approve an order and release its payment, or write code and run it.

Against that, eight pairs of tools are used together in real work, each with a weight for how often: reading a vendor and raising an order (almost always), reading and writing files, fetching and posting to the web, and so on. The weights are the kind of thing a gateway's audit trail gives you for free, by counting which tools were called under the same task.

The job is to put every tool in one of two child agents so that no child holds a toxic pair and as little working affinity as possible is cut. Each toxic pair left together costs three points; each working pair split costs its weight. Lower is better. It maps onto a quantum computer directly: one qubit per tool, and one interaction per pair that matters, twelve in all.

## What we ran

We solved it for 6, 8 and 10 tools with QAOA, the quantum optimisation algorithm, with the angles tuned on a laptop first as practitioners do. The ten-tool version ran with one layer of the algorithm and with two. Each circuit was sampled 8,192 times on ibm_fez, IBM's 156-qubit Heron processor, and the whole job used 11 seconds of quantum processor time.

![The five-tool version of the circuit: one wire per tool, a two-qubit gate for each pair of tools that conflict or work together, then a mixing rotation on every wire](/intel/analysis-agent-split-circuit.png)
A five-tool version of the circuit. Each two-qubit gate joins a pair of tools that either conflict or work together; the whole ten-tool problem has twelve such pairs.

Every answer was compared with three things:

- **The true optimum**, found by checking all 1,024 assignments on a laptop, in 3 milliseconds.
- **A simple classical rule:** place the tools with the most conflicts first, each on whichever side costs least so far.
- **Random guessing**, with the same number of attempts the quantum computer had.

## What the figures show

| Tools, layers | Two-qubit gates on the chip | Optimum | Simple rule | Quantum, typical | Random, typical | Exact hits, quantum | Exact hits, random |
| - | - | - | - | - | - | - | - |
| 6, one | 18 | 0.9 | 0.9 | 3.7 | 5.7 | 9.2% | 3.0% |
| 8, one | 28 | 0.9 | 0.9 | 4.4 | 6.2 | 5.4% | 1.6% |
| 10, one | 37 | 1.2 | 1.2 | 5.3 | 8.2 | 2.3% | 0.3% |
| 10, two | 80 | 1.2 | 1.2 | 4.9 | 8.3 | 4.3% | 0.3% |

![Share of samples that were exactly an optimal split, for random guessing, real hardware, simulated hardware noise and a perfect simulator, at 6, 8 and 10 tools](/intel/analysis-agent-split-optimal.png)
Exact hits on an optimal split. On the real chip the ten-tool, two-layer circuit landed on the optimum 4.3% of the time against 0.3% for guessing, and kept more than half of what a perfect simulator achieves.

Three things stand out.

**This time the quantum computer clearly beat guessing.** Its typical answer was 2 to 3 points better than random at every size, and it hit the exact optimum 3 to 14 times as often. At ten tools with two layers, one sample in 23 was a perfect split; for random guessing it was one in 300. A third of its samples had no toxic pair left at all. The [convoy problem](/analysis/army-quantum-convoys-we-ran-ours) managed none of this.

**The classical methods still won outright.** The simple rule found the optimum at every size. The laptop found it by brute force in milliseconds. At this scale a quantum computer is not needed, and the best of 8,192 random guesses found the optimum too, as it did for convoys. The honest claim is about the shape of the answers the machine gives, not about finding an answer nobody else could.

**The difference from the convoy result is not the qubits.** Both problems used ten qubits. The [convoy circuit](/analysis/army-quantum-convoys-we-ran-ours) compiled to 358 two-qubit operations on the chip because every convoy interacts with every other. The agent circuit compiled to 37 because a tool only interacts with the few tools it conflicts with or works beside. Noise grows with every two-qubit operation, and the chart below puts the two studies on one axis.

![Hardware hit rate as a multiple of random guessing, against two-qubit gates after compiling, for the agent split and the convoy problem](/intel/analysis-agent-split-survival.png)
Each point is one run on ibm_fez. Below about 40 two-qubit gates the algorithm survives the chip; in the hundreds it does not. Qubit count told us nothing; gate count told us everything.

Going from one layer to two on the ten-tool problem is the same lesson in miniature. The second layer more than doubles the exact-hit rate on a perfect simulator, but it also more than doubles the gate count, and the real chip kept 55% of the simulator's two-layer hit rate against 59% of its one-layer hit rate. Deeper is better right up until the noise takes it back.

## What the quantum computer saw

Composer, IBM's visual circuit tool, can draw the state of a circuit before measurement for up to five qubits. Here is the five-tool version, with the procurement tools only: the two tallest bars are the two optimal splits (the same split, mirrored), and the next two are the second-best, which differ only in where the vendor-reading tool lands.

![Statevector amplitudes for the five-tool circuit, 32 bars, with the two optimal splits as the tallest](/intel/analysis-agent-split-statevector.png)
The amplitude the circuit puts on each of the 32 possible splits of five tools. Squaring a bar gives the chance of sampling that split.

![Q-sphere view of the same state, the 32 splits arranged on a sphere with marker size showing probability](/intel/analysis-agent-split-qsphere.png)
The same state on IBM's Q-sphere. The largest markers are the optimal splits.

## The split it chose

The optimal answer, which the hardware's best sample matched, puts vendor reading, order approval, vendor creation and shell access in one child, and order raising, payment release, file access and web access in the other. No toxic pair survives. Two working relationships are cut: reading vendors is separated from raising orders, and reading files from running commands. The first of those will annoy whoever operates the ordering agent, and that is the point. A split that cost nothing would not have been needed.

Something the solver cannot tell you is whether the rules were complete. The approving child also creates vendors, which no rule forbade. Optimisation finds the best answer to the question you asked. Writing the toxic pairs down is still a human job, and the output of a run like this is the first thing to show the people who own those rules.

## What this means for a CISO

Three practical points, none of which need a quantum computer.

**The data for this already exists.** Which tools an agent is allowed, which it actually used, and which it used together in the same task, are all in the gateway's audit records if you have a gateway that records per action. Least privilege for agents starts with reading that, not with buying anything.

**Post-quantum signatures add a constraint humans never had.** If your agent tokens are signed with ML-DSA, the post-quantum standard the NSA and ASD are moving to, each signature is 2.4 to 4.6 kilobytes, inside an HTTP header most proxies cap at 8. The token also carries its delegation chain. So each child agent has a byte budget for its tool list, roughly a kilobyte under the strictest profile, and it shrinks with every level of delegation. A directory never cared how many entitlements a person had. An agent's token does.

**When a vendor shows you a quantum result, ask for the gate count.** Not the qubits. Ask how many two-qubit operations the problem compiled to on the chip, what the same circuit scores on a perfect simulator, and what random guessing scores with the same number of samples. Our ten-tool problem gave real signal at 37 gates. A real enterprise has thousands of agents and hundreds of tools, and a realistic version of this problem compiles to far more than that. The classical solvers will handle it for years yet. What a run like this buys is a formulation that is ready when the hardware is, and a baseline to re-run every time it improves.

## Where do you stand?

Sign in below with an email address and tell us:

- **Do your agents have toxic pairs today?** Has anyone checked an agent's tool list against your segregation-of-duties rules, the way you would check a person's roles?
- **Who owns the split?** When an agent has to be divided, is that a security decision, a platform decision or the developer's call?
- **Would you accept a solver's answer?** If a tool proposed the two child agents above, what would you need to see before approving them?
- **Gate count or qubit count?** Have you seen a quantum proposal that reported either?

We will read every comment and reply to the ones that argue.

---

Sources: Our results are from a run on IBM's ibm_fez processor on 8 October 2026 with Qiskit, using one- and two-layer QAOA with classically tuned angles and 8,192 samples per problem, compared with brute force, a greedy rule and random guessing; the simulator comparisons use IBM's published noise model for the same chip. The statevector and Q-sphere figures are exported from IBM Quantum Composer; the circuit diagram is drawn with Qiskit. Signature sizes are for ML-DSA-44, 65 and 87 under FIPS 204. Our convoy routing comparison is in [The Army put its convoys on a quantum computer](/analysis/army-quantum-convoys-we-ran-ours).
