Authorisation gap for AI agents in government
A study in Frontiers in Political Science names the democratic authorization gap: governments must be able to demonstrate mandate, responsible officer
You must now document which mandate, responsible officer and delegated powers underpin each consequential action your organisation's AI agents perform, and maintain a demonstrable chain connecting that action back to lawful authority. This is distinct from logging what the agent was permitted to do.
The prompt is an analysis of 23 September 2026 of the democratic authorization gap in government deployment of AI agents, which argues that governments must be able to reconstruct the authorisation chain for each action an AI agent selects or performs. The study in Frontiers in Political Science describes this as a break between legitimate public authority and the actions an agent itself chooses to take. In our assessment, this is not a technical compliance matter but a governance one: access logs that show an agent stayed within its permissions do not answer whether the organisation was lawfully permitted to grant that permission in the first place.
What is the authorisation gap and why does it matter?
An AI agent can operate entirely within its technical permissions whilst your organisation cannot demonstrate it was authorised to delegate that action. The distinction is threefold. First, the mandate: which lawful basis, regulation or policy decision permits your organisation to perform this action at all. Second, the responsible officer: which named individual or role is accountable for the decision to delegate it to an agent. Third, the remediation route: how the organisation will intervene, correct or reverse the action if it causes harm.
Access management and audit logs typically record only the third layer—what the agent was allowed to do. In our assessment that is necessary but not sufficient. A log demonstrating an agent stayed within its permissions says nothing about whether the organisation was allowed to grant that permission and on which mandate it rested. For public and other high-trust organisations, that gap is a concrete, verifiable problem.
Which failure modes does the authorisation gap create?
- Mandate invisibility — an agent performs an action that is technically within scope but the organisation cannot trace it to a lawful basis or policy decision.
- Accountability diffusion — no named individual or role is recorded as responsible for delegating the action to the agent, leaving remediation unclear.
- Remediation opacity — the organisation has no documented route to intervene, correct or reverse an action if it causes harm.
- Vendor dependency unmarked — the organisation deploys a system whose internal workings are not fully visible but has not recorded this as a governance risk requiring sharper oversight.
- Least privilege without reasoning — runtime controls bound what an agent can do, but the organisation has not documented why those bounds were chosen or on which authority.
What concrete controls must you be able to demonstrate per workflow?
- Record the mandate — document which regulation, policy decision or lawful basis permits your organisation to perform this action and delegate it to an agent.
- Name the responsible officer — identify which individual or role is accountable for the decision to delegate this action to the agent and for its consequences.
- Document delegated powers — specify which powers the agent has been granted, why those powers are necessary for the action, and which powers have been explicitly withheld.
- Establish a remediation route — define how the organisation will detect, intervene in, correct or reverse the action if it causes harm, and who is authorised to trigger that route.
- Record vendor dependencies — if the system's internal workings are not fully visible to your organisation, document this as a governance risk and specify what additional validation and monitoring compensates for that opacity.
How does this connect to human oversight of AI decisions?
This aligns with what organisations already need to demonstrably log when giving humans oversight of high-risk decisions. The addition here is that AI agents must have their own identity with delegated and logged authorisation, coupled to the human accountability layer. Without that coupling, traceability remains limited to technology and lacks the administrative layer that closes the authorisation gap.
Why does this matter beyond your own organisation?
Governments that internally lack a demonstrable authorisation chain will also have more difficulty making their governance approach externally intelligible to other countries and international bodies. The United Nations is establishing an independent scientific panel and a global dialogue to help governments develop compatible approaches to AI governance. Organisations that can demonstrably connect each consequential action to an authorised mandate and a responsible officer will be better positioned to participate in that coordination and to explain their governance approach to external scrutiny.
Technology provides the bounding; the accounting is an administrative task. Audit logs and access controls are tools that carry the evidence, but the decision about which mandate applies, which officer is responsible, and what remediation route exists remains your own professional judgement. You cannot delegate that judgment to a vendor or to a system.
Sources: This article draws on reporting and guidance from Frontiers in Political Science, AI and Ethics, Springer Nature, United Nations News and Microsoft Cloud Blog.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.