Authorized versus unauthorized AI usage

Authentication establishes which credential a service accepted. Authorization establishes what that principal was permitted to do. Behavioral analysis can show changes in use, but permission often depends on account terms, workload ownership, delegation, and policy records outside the request log.

Ask four separate questions

QuestionEvidenceWhat it does not establish
Did the credential authenticate?Authentication result and credential stateThat its current user was the rightful holder
Was the requested operation in scope?Applicable route/model permission at request timeThat the downstream purpose was permitted
Was the workload approved?Owner, deployment, and delegation recordsThat every request in a shared account belongs to that workload
Did usage comply with the applicable agreement?Effective policy, account context, and reviewed activityThat an anomaly score can make the decision alone

Keep observations separate from conclusions

An observation might be “this key began requesting a new model from a new network.” A hypothesis might be “someone outside the registered workload is using the key.” A conclusion needs additional evidence that resolves the hypothesis. Store each separately so the investigator can explain what changed their mind.

Record the policy version in force at the time. A later change to an offer or acceptable-use rule should not silently become the basis for interpreting earlier requests.

Two workloads can look the same

Synthetic example: an authorized evaluation and an unapproved extraction job each make 50,000 requests through one key using similar models and timing. If the available metadata is identical, a metadata-only system cannot reliably distinguish the two purposes. The investigator needs the workload's authorization and corroborating context. A higher score does not manufacture missing evidence.

Use a case decision record

Avoid punishing uncertainty

Missing attribution may justify improving logging or temporarily limiting operational exposure under an established process. It should not automatically establish fraud. Review decisions against legitimate edge cases such as shared services, authorized resellers, workshops, and multi-region deployments.

Measure unresolved cases explicitly. If most cases cannot be resolved, improve evidence coverage or narrow the hypothesis before increasing alert volume. “No evidence of misuse in the records available” is different from proving that no misuse occurred.

Continue with credential sharing, distillation defenses, and free-tier eligibility abuse.