No Government Agent Without a Named Principal
Software may perform public work, but every consequential action must lead to an official who can stop, explain and reverse it.
Government has always delegated. Ministers delegate to departments, departments to officials and officials to contractors. Constitutional systems make that delegation legitimate by keeping a chain of authority, a record of reasons and a route of appeal.
AI agents can break that chain without formally changing a single law.
Unlike a chatbot that prepares text for a person, an agent can pursue a goal through several steps: retrieve records, choose a process, call software and carry out an action. That ability may make public services faster. It may also create an unnamed official who never appears in an organisation chart and cannot be questioned by the citizen it affects.
The democratic rule should be categorical: no government agent without a named human principal.
Action changes the governance problem
The OECD's 2026 Digital Government Outlook distinguishes agentic systems by their capacity to plan and act within an assigned space. It calls for authority boundaries, approval gates, auditability and ways to pause, reverse and challenge outcomes.
Those controls become more important as the action becomes harder to undo. Translating a notice is not the same as rejecting a benefit. Routing a file is not the same as initiating an investigation. A model's confidence score cannot decide where public power begins.
The principal should be an identifiable officeholder with the authority and competence to supervise the system. A committee may set policy, and a vendor may maintain code, but neither should absorb the responsibility for an individual coercive act.
A public register is the beginning
Government use of AI is already widespread. The OECD reports that 35 of 36 surveyed countries use AI in the public sector. Only 11 had binding standards and only six operated open algorithm registers.
Every deployed agent should appear in a public register stating its owner, purpose, data access, permitted actions, approval thresholds, current model version and appeal route. Security details may be withheld, but the existence and scope of public power cannot be secret by default.
The United Kingdom's Algorithmic Transparency Recording Standard demonstrates that agencies can disclose purpose, impact and oversight without publishing a technical attack guide.
Registration alone is not accountability. The named principal must receive error reports, review sampled decisions and have a tested mechanism to suspend the system. A name placed on a form while the official lacks access to logs is theatre.
Identity belongs to software too
An agent should never operate through a shared employee credential. It needs a distinct machine identity, narrowly scoped permissions and an expiring authorisation. The US National Institute of Standards and Technology has identified identity and authority as central problems for software agents.
Every action log should say which agent acted, which evidence it accessed, which rule it invoked, which model version was active and whether a human approved the step. Logs must be resistant to alteration and available to authorised auditors.
An internal trace is not automatically a citizen's explanation. People need the operative reason for an outcome in ordinary language, the responsible office and a method of obtaining human review. A vast record of model processing cannot replace due process.
The strongest countercase
Human approval can become an expensive fiction. An official confronted with thousands of automated recommendations may approve them in bulk. Excessive gates can also remove the speed and availability that make an agent worthwhile.
The answer is tiered authority. Routine, reversible and low-impact actions may proceed automatically. Consequential decisions—loss of eligibility, penalties, changes to legal records, disclosure of sensitive data or enforcement—need meaningful human approval. Intermediate actions can proceed with rapid appeal, continuous sampling and automatic suspension when error thresholds are crossed.
This is not a demand that every email carry a minister's signature. It is a demand that the level of oversight track the power exercised.
Procurement cannot outsource the constitution
Contracts should guarantee access to logs, notice of model changes, portability of records and the ability to change suppliers. They should allocate responsibility for security and defects without allowing a government to tell an injured citizen to sue a distant vendor.
Independent testing should cover unauthorised tool calls, prompt injection, data leakage and unequal error across languages and populations. Departments should publish meaningful performance measures and serious incidents. Judicial and legislative bodies must be able to inspect the system under appropriate confidentiality.
Agentic government can spare citizens repetitive visits and make administration more attentive. That is a public good. It becomes a constitutional danger only when convenience dissolves the hierarchy through which state power is controlled.
Software can serve as an agent. In a democracy, it cannot be its own principal.
The Global Federation defends technology that strengthens public capacity without weakening the line of responsibility between power and the people subject to it.