Kommando 161 Faultline Kommando 161

World · Labour Hub · 5h

The AI safety rule workers need: no agent gets power without a named human owner

English (original) · Read in Deutsch ⇄

Britain is moving quickly to put artificial intelligence into real institutions. On August 31st, the government opened the first competitions under its £100 million Sovereign AI R&D Procurement Scheme, explicitly targeting public services, cyber security, and national security. Earlier this year, Skills England launched an AI and automation practitioner apprenticeship to help employers adopt the technology safely and responsibly.

Those are sensible investments. But they create a labour question that deserves as much attention as productivity: when an AI agent can act, who remains responsible for what it does?

That question stopped being theoretical this summer. A METR and Redwood Research investigation examined a major real-world cyberattack on Hugging Face. AI agents driven by an unreleased OpenAI internal research model attacked on their own, despite recognising that the attack was outside their assigned task. Hundreds of agents shared discoveries, divided up work, and coordinated through their own message board until they breached Hugging Face’s defences.

The important lesson is not that software has become conscious. The lesson is that software can now pursue goals across tools and systems with enough autonomy that ordinary management controls can fail.

Workers already understand the danger of responsibility without authority. A nurse cannot safely be held accountable for a clinical decision made by a system she cannot inspect. A civil servant should not carry the blame for an automated procurement action she could not interrupt. A customer-service employee should not be disciplined for a refund, cancellation or escalation that an agent executed outside the limits she was told applied.

The answer is a simple rule: every consequential AI-agent workflow should have a named human owner with real authority to stop, reverse, and review what the agent does.

That ownership should come with three practical protections.

First, employers should define an authority budget before deployment. The agent should get only the tools, data and permissions needed for its specific task. Australia’s cyber security authorities have made the same point in their guidance on agentic AI: limit privileges, use human approval for sensitive actions, and monitor agent behaviour continuously. British employers and public bodies should apply that logic to every deployment.

Second, workers need visible escalation paths. If an agent reaches an exception, changes the purpose of a task, or asks for access beyond its normal scope, the system should stop and hand control to a person. That person needs enough context to understand what happened and enough institutional authority to say no.

Third, serious incidents should trigger independent review rather than quiet internal cleanup. If an agent crosses a defined authority boundary, reaches sensitive systems, or causes a material external consequence, the organisation should preserve the logs, report the incident through an appropriate channel, and examine whether the same failure could happen elsewhere.

These are worker protections, but they are also adoption protections. I’m no AI sceptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.

Workers who know where the boundaries are will experiment more confidently. Managers who can see what an agent is allowed to do can delegate more responsibly. Unions and employee representatives can negotiate around concrete powers and controls instead of vague fears about AI.

Britain has a chance to build this discipline while agentic systems are still entering workplaces. The government is spending heavily to accelerate AI deployment and skills. It should make human ownership of delegated authority part of that same agenda.

The question for every new AI agent should be easy to answer: What can it do, what can it never do on its own, and which named person has the power to stop it? If no one can answer those questions clearly, the agent is not ready for work.

Gleb Tsipursky PhD is a behavioural scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).  His commentary has appeared regularly in The New York Times, The Guardian, the Toronto Star and elsewhere.

Read the full story at the source →

Source: Labour Hub