Authorized versus unauthorized AI usage
Authentication establishes which credential a service accepted. Authorization establishes what that principal was permitted to do. Behavioral analysis can show changes in use, but permission often depends on account terms, workload ownership, delegation, and policy records outside the request log.
Ask four separate questions
| Question | Evidence | What it does not establish |
|---|---|---|
| Did the credential authenticate? | Authentication result and credential state | That its current user was the rightful holder |
| Was the requested operation in scope? | Applicable route/model permission at request time | That the downstream purpose was permitted |
| Was the workload approved? | Owner, deployment, and delegation records | That every request in a shared account belongs to that workload |
| Did usage comply with the applicable agreement? | Effective policy, account context, and reviewed activity | That an anomaly score can make the decision alone |
Keep observations separate from conclusions
An observation might be “this key began requesting a new model from a new network.” A hypothesis might be “someone outside the registered workload is using the key.” A conclusion needs additional evidence that resolves the hypothesis. Store each separately so the investigator can explain what changed their mind.
Record the policy version in force at the time. A later change to an offer or acceptable-use rule should not silently become the basis for interpreting earlier requests.
Two workloads can look the same
Synthetic example: an authorized evaluation and an unapproved extraction job each make 50,000 requests through one key using similar models and timing. If the available metadata is identical, a metadata-only system cannot reliably distinguish the two purposes. The investigator needs the workload's authorization and corroborating context. A higher score does not manufacture missing evidence.
Use a case decision record
- Observed activity: identifiers, time window, and measured changes.
- Expected authority: principal, scope, owner, delegation, and effective policy.
- Hypothesis: a specific possible violation that evidence could disprove.
- Corroboration: reviewed records and the source of each identity assertion.
- Outcome: explained authorized use, confirmed unauthorized use, or unresolved.
- Action and review: scope, owner, reversal conditions, and appeal route where applicable.
Avoid punishing uncertainty
Missing attribution may justify improving logging or temporarily limiting operational exposure under an established process. It should not automatically establish fraud. Review decisions against legitimate edge cases such as shared services, authorized resellers, workshops, and multi-region deployments.
Measure unresolved cases explicitly. If most cases cannot be resolved, improve evidence coverage or narrow the hypothesis before increasing alert volume. “No evidence of misuse in the records available” is different from proving that no misuse occurred.
Continue with credential sharing, distillation defenses, and free-tier eligibility abuse.