An AI agent can technically stay within its permissions while a government body cannot demonstrate it was allowed to delegate that action; the study in Frontiers in Political Science calls this the democratic authorization gap. Record per action which mandate, responsible officer, delegated powers and remediation decisions underpin the action.
On 9 September 2026, Frontiers in Political Science published the study Before agentic AI scales in government: the democratic authorization gap. The study emphasises a broader question than technical authority alone: is the action demonstrably connected to a lawful and democratic mandate, and can the organisation reconstruct that authorisation chain afterwards? For public and other high-trust organisations, that is a concrete, verifiable difference.
What exactly does the democratic authorization gap from the Frontiers study involve?
The study describes the democratic authorization gap as a break between legitimate public authority and the actions an AI agent itself selects or performs. The authors distinguish four mechanisms that cause that break:
- Mandate translation: a legal or administrative instruction is converted into machine instructions, whereby meaning can shift.
- Recursive delegation: an agent invokes subagents and tools that in turn delegate further.
- Action proliferation: one instruction leads to a series of follow-on actions that no one authorised individually.
- Delayed contestability: objection or correction only comes into view after the consequences have already occurred.
For pilots the study proposes five conditions: bounded authorisation, inheritance of powers, traceability at action level, named institutional responsibility and operational interruption with remediation. This is the core of the news and the starting point for the rest of this piece on governance of agentic AI and autonomous AI agents.
Why do IAM and audit logs not suffice to account for AI actions in government?
Access management and audit logs typically record what an agent was allowed to do: which role, which rights, which tool invocations. In our assessment that is necessary but not sufficient for the question the Frontiers study poses. A log that demonstrates an agent stayed within its permissions says nothing about whether the organisation was allowed to grant that permission and on which mandate it rested.
The distinction is threefold. We editorially translate the study into three layers that can each be made demonstrable within a governance process:
- Administrative authorisation of the purpose: the legal or organisational mandate that legitimises the task.
- Operational authority of the organisation: the authority to delegate that task to an automated system, including the human officer who remains responsible.
- Concrete execution: the actual actions of the agent, subagents, tools and people, with intervention and remediation moments.
Those who log only the third layer do not close the authorisation gap. The same logic applies when setting up least privilege as runtime control on AI agents: bounding during execution is something other than an account of why the bounding was chosen as it was.
Which pieces of evidence must a government be able to show per AI workflow?
The five conditions from the study can be translated into a concrete set of pieces of evidence per sensitive workflow. We list them as an editorial operationalisation of the study, not as a quotation:
- The legal or organisational mandate that covers the purpose of the workflow.
- The named responsible officer who remains accountable.
- The inherited powers of subagents and tools, with the limits they may not exceed.
- The data used: origin, access and retention period.
- The actions at action level, so that every consequential action is traceable to a mandate.
- The human interventions and the moments at which a person could intervene.
- The stop capability and the associated remediation decision if an action must be reversed.
That aligns with what organisations need to demonstrably log human oversight of high-risk decisions and to give AI agents their own identity with delegated and logged authorisation. Without that coupling, traceability remains limited to technology and lacks the administrative layer.
Why does the deploying organisation remain operationally responsible, even with black-box APIs?
The study Operational responsibility in AI governance in AI and Ethics by Springer Nature treats AI as an instrument and places primary operational responsibility with the user or deployer, while developers retain additional obligations. The authors link that responsibility to the actual decisions about deployment, context, oversight and monitoring.
Important for governments is the nuance the study introduces: limited transparency of API systems does not make the deployer's responsibility smaller, but heavier. Those who deploy a system whose internal workings are not fully visible must compensate for that with sharper agreements on deployment, validation and oversight. In our assessment this means that vendor dependency itself is a governance topic that must be recorded per workflow.
As practical substantiation, the Microsoft Cloud Blog, in a publication of 10 September 2026, emphasises that responsible public AI deployment requires organisations to know how systems were trained, how output is validated, where data is stored, who has access and how risks are continuously monitored. Microsoft states that responsibility remains with people and institutions. This is not a contradiction of the academic sources, but an operational filling-in of the same requirement.
How does international AI governance fit into national responsibility?
The authorisation gap is a national administrative matter, but is not separate from broader coordination. United Nations News describes the establishment of an Independent International Scientific Panel on AI and a Global Dialogue on AI Governance. The scientific pillar is to inform governments about known and unknown risks; the dialogue is to help countries and stakeholders develop compatible governance approaches.
The UN source describes the establishment of an independent scientific panel and a Global Dialogue that are to help governments and other stakeholders to share knowledge and develop compatible approaches to AI governance. Editorial analysis: this can be read as a connection between the international and national layers. Governments that internally lack a demonstrable authorisation chain will also have more difficulty making their governance approach externally intelligible. Editorial analysis: this gives the democratic authorization gap significance for the credibility and comparability of national governance approaches in international coordination too.
For administrators the practical line is clear. The news value lies with the new academic formulation of the Frontiers study; the editorial consequence of this analysis is that organisations should strive to demonstrably connect every consequential AI action to an authorised mandate, a responsible officer and a remediation route. Technology provides the bounding, but the accounting is an administrative task.
Sources and references
- Before agentic AI scales in government: the democratic authorization gap
- Operational responsibility in AI governance: a user-centric liability framework
- Who should set the rules for AI? The UN is pushing for a safer digital future
- New e-book outlines how public sector leaders can turn AI into action
Sources: The article draws on the study in Frontiers in Political Science, a responsibility study in AI and Ethics by Springer Nature, United Nations News and the Microsoft Cloud Blog.