HomeOPEDWe Are About to Give AI the Keys. Who Is Guarding the...

We Are About to Give AI the Keys. Who Is Guarding the Door?

AI agents will not merely answer our questions. They will increasingly act on our behalf. We need to think seriously about what that means.

A few things I have read in recent days have made me stop and think.

Researchers have reported that AI agents being tested by OpenAI uploaded hundreds of malicious packages to RubyGems in May, in an apparent attempt to exploit vulnerabilities and potentially obtain user credentials. OpenAI has confirmed the incident, while RubyGems said it found no evidence that the attempted breach succeeded.

Other incidents involving AI agents have also raised questions about how much control their developers actually retain over their behaviour.

More recently, Anthropic CEO Dario Amodei called for the pace of AI development to slow sufficiently for safety measures to catch up, warning that increasingly capable AI agents could pose serious risks if safeguards lag behind their capabilities.

These developments point to a question that deserves much greater attention:

What happens when artificial intelligence is no longer merely giving us answers, but acting on our instructions?

That is the significance of agentic AI.

From answering to acting

Most of us are familiar with AI through chatbots. We ask a question and receive an answer. The system may be wrong, misleading or incomplete, but ultimately we decide what to do with the answer.

An AI agent is different.

An agent can be given a goal and access to the tools needed to pursue it. It may search the internet, use software, retrieve information, send messages, write and execute code, make transactions or interact with other systems.

Consider something simple. Instead of asking AI to find the cheapest flight from Mumbai to London, we could ask it to find a suitable flight, book it, pay for it and put the details in our calendar.

That is useful.

But it also changes the nature of the risk.

A chatbot can make a mistake. An AI agent can act on a mistake.

And the more authority we give an agent, the greater the consequences of that mistake.

The security problem is different

The concern is not simply that AI may produce incorrect information. An agent may also be manipulated.

An AI agent can encounter instructions embedded in a website, email, document or piece of software. A malicious instruction could potentially influence what the agent does. If the agent has access to sensitive information, financial systems, corporate networks or other digital tools, the consequences could extend well beyond the original interaction.

There is another complication. Agents may increasingly interact with other agents. One system may delegate a task to another, which may call another service, which may trigger further actions.

The resulting chain can become difficult for a human being to understand or supervise in real time.

This is not an argument against developing agentic AI. The potential benefits are enormous. Agents could improve productivity, assist businesses, support public services and perform complex tasks that currently require considerable human effort.

But capability and authority are not the same thing.

The question is not only what an AI system can do. It is what we should allow it to do.

What should individuals do?

Individuals will increasingly give AI access to email, documents, financial information, calendars, devices and online accounts.

The basic principle should be simple: give an AI agent only the authority it needs for the task.

An agent helping with travel does not need unrestricted access to our bank account. An agent organising documents does not need permission to delete them permanently. An agent drafting an email does not necessarily need the authority to send it without approval.

For consequential actions—financial transactions, legal commitments, deletion of important information or communication on our behalf—human confirmation should remain the default unless there is a compelling reason otherwise.

Convenience should not automatically mean unrestricted authority.

What should companies do?

For companies, the issue is much larger.

Every organisation deploying AI agents should know exactly what authority those agents possess.

What systems can they access? What information can they read? What can they change or delete? Can they make financial commitments? Can they communicate externally? Can their actions be traced? What happens if they are manipulated? Who is responsible when an agent makes a consequential decision? Can it be stopped immediately?

These questions should become part of ordinary risk management.

An organisation should also know which AI agents are operating within its systems and what permissions they have. Autonomous systems should not quietly accumulate authority simply because doing so makes them more useful.

What about nations?

The implications become more serious when AI agents interact with critical infrastructure.

Energy, telecommunications, banking, transport, healthcare and government services increasingly depend on interconnected digital systems. An AI agent with access to such systems could potentially do far more than produce an erroneous report.

The possibility of manipulation, unauthorised access or unintended actions therefore becomes a national-security concern.

This requires a broader approach to AI safety. The issue is not merely whether an algorithm is biased or whether data has been used appropriately. It is also about control, permissions, accountability and the ability to intervene when an autonomous system behaves unexpectedly.

No country can deal with this alone

There is also a strong case for international cooperation.

AI agents will operate across borders. A compromised software component, malicious instruction or vulnerable AI system in one country could affect organisations or individuals elsewhere.

Countries therefore need mechanisms for sharing information about significant AI incidents, developing common safety standards, testing high-risk systems and establishing principles for human oversight of increasingly autonomous AI.

The challenge is global because the technology is global.

The question we should be asking now

The debate around AI often focuses on how intelligent these systems will become.

That is an important question. But it is no longer the only one.

The more immediate question may be:

How much authority should we give them?

We should welcome the productivity and innovation that agentic AI can bring. But every increase in capability should be accompanied by an equally serious examination of permissions, safeguards and accountability.

The objective should not be to prevent machines from acting.

It should be to ensure that humans remain able to understand, supervise and, when necessary, stop what they are doing.

We are entering a period in which AI will increasingly move from being a tool that answers us to a system that acts for us.

Before that happens at scale, we need to decide how much authority we are prepared to surrender—and who will remain responsible when things go wrong.

Also Read: The God We Treat Like a Friend



Subscribe to TheNews21

Stay Ahead with Independent Journalism

Investigations, political analysis and major national and global stories delivered directly to your inbox.

Subrat Ratho, IAS (Retd)
Subrat Ratho, IAS (Retd)
Subrat Ratho, IAS (Retd.) is a former Indian Administrative Service officer who took voluntary retirement from government service after decades in public administration. He writes on politics, democracy, governance, urban life, and international affairs, drawing on deep administrative experience and close observation of public institutions and society. His essays explore the philosophical, structural and human dimensions of modern democracies, public policy and contemporary political life.

Must Read

spot_img
spot_img