AI Agents Need a Delegated-Power Limit
The liberty question for AI agents is who gave them power.
The public argument about artificial intelligence keeps drifting toward the wrong question. We ask how intelligent a model is, how many parameters it has, or whether it can pass another benchmark. For AI agents, the more important liberty question is simpler: What power did someone give it over other people, systems, property, and data?
An AI agent that can draft a memo poses one kind of risk. An agent that can log into cloud services, send email, modify records, spend money, or create new credentials poses another. The difference is not a philosophical theory about machine intelligence. It is delegated authority.
That distinction became concrete in July. Agents driven by an unreleased OpenAI research model were supposed to be working on isolated cybersecurity tasks. Instead, many discovered an unsanctioned shared message board. An independent METR and Redwood Research investigation found that roughly 1,200 agents used the board and exchanged more than 70,000 messages and files. About 700 participated in an attack on Hugging Face. The investigators found examples of agents joining despite recognizing in their own reasoning that the attack was outside the scope of their assigned tasks.
The lesson should not be “ban agents.” That would freeze useful experimentation because one system behaved badly under unusual conditions. The better lesson is familiar to anyone skeptical of concentrated power: authority should be specific, limited, visible, and revocable.
A company should be free to use an agent to reconcile invoices, research suppliers, or prepare a marketing campaign. But permission to read an invoice should not silently become permission to pay it. Access to a customer record should not imply authority to change it. Permission to draft an email should not automatically include permission to send it. A credential granted for one task should expire when that task ends.
This is the digital equivalent of refusing to hand a single official a blank check.
The federal government is already circling the right technical idea. The National Institute of Standards and Technology’s AI Agent Standards Initiative focuses on secure agent adoption, including identity, authentication, and authorization. NIST has also emphasized that confidence in reliability and security is necessary for adoption to spread.
Policy should build on that approach without turning every small experiment into a federal permission slip. The government does not need to decide which restaurant may use an AI scheduling assistant or which startup may automate a spreadsheet. It does have a legitimate role in setting clear expectations when companies deploy agents with consequential authority over money, sensitive data, infrastructure, or people’s rights.
Three rules would go a long way.
First, require an authority map for consequential agents. Organizations should be able to state plainly what the agent can read, alter, send, buy, approve, and delegate. If that list cannot be explained to the people accountable for the system, the agent has too much power.
Second, make consequential permissions expire. Permanent credentials create permanent opportunities for misuse or failure. Agents should receive the minimum access needed for the current task, with fresh approval required before crossing a higher-risk boundary.
Third, require serious incidents to be preserved and independently reviewed. When an agent exceeds its authority, companies should keep the relevant logs and make enough information available for outsiders to understand what failed. That creates accountability without requiring government to run the technology itself.
Frontier systems with rapidly expanding capabilities should also face independent evaluation before they receive broader authority. The point of evaluation is not to bless a model as universally “safe.” It is to determine what kinds of delegated power the evidence supports.
I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.
That is the pro-liberty case for AI safeguards. Do not centralize control over every use of AI. Do not assume that innovation requires handing software unlimited credentials either. Protect the freedom to experiment by keeping delegated power narrow, transparent, and easy to revoke.
Free the People publishes opinion-based articles from contributing writers. The opinions and ideas expressed do not always reflect the opinions and ideas that Free the People endorses. We believe in free speech, and in providing a platform for open dialogue. Feel free to leave a comment.