There is no canonical formal answer to what an AI agent is permitted to do.
On whose behalf, under what conditions, against which counterparties — today this is encoded as system prompts, tool definitions, and trust in the model's runtime interpretation. There is no structural separation between the principal's instructions and a counterparty's content, which is what makes prompt injection effective. There is no audit trail of what was permitted versus what was attempted.