Back to AI Research

AI Research

Regulating autonomous and agentic AI | AI Research

Key Takeaways

  • Regulating autonomous and agentic AI The paper "Regulating autonomous and agentic AI" examines the growing disconnect between traditional regulatory framewor...
  • Regulating activities where regulatees use autonomous and agentic AI is challenging.
  • Regulatory assumptions about regulatee knowledge and control no longer hold true; much of that lies elsewhere in the AI supply chain which thus needs to be brought within the scope of regulation.
  • Governance systems for autonomous AI cannot replicate existing governance models, but need a fresh approach.
  • Retrospective supervisory oversight becomes ineffective as a risk management tool, and AI autonomy generates new systemic risks which require new solutions.
Paper AbstractExpand

Regulating activities where regulatees use autonomous and agentic AI is challenging. Regulatory assumptions about regulatee knowledge and control no longer hold true; much of that lies elsewhere in the AI supply chain which thus needs to be brought within the scope of regulation. Governance systems for autonomous AI cannot replicate existing governance models, but need a fresh approach. Retrospective supervisory oversight becomes ineffective as a risk management tool, and AI autonomy generates new systemic risks which require new solutions. This paper investigate four regulatory systems: UK regulation of content platforms, data protection, UK financial services, and the EU AI Act\'92s cross-sectoral regime. It analyses the challenges posed by autonomous and agentic AI and proposes potential solutions which regulators might adopt. These will transform regulation from a reactive process to an active one, and assist it in adapting to the challenges of AI autonomy.

Regulating autonomous and agentic AI

The paper "Regulating autonomous and agentic AI" examines the growing disconnect between traditional regulatory frameworks and the realities of modern artificial intelligence. As AI systems become increasingly autonomous and agentic—meaning they can make decisions and take actions with less human intervention—the assumptions that regulators rely on regarding human control and knowledge are failing. The authors argue that current governance models are insufficient and propose a shift toward more active, forward-looking regulatory strategies to manage the systemic risks posed by these technologies.

The Breakdown of Traditional Oversight

Current regulatory models are largely built on the assumption that the entity using a technology has full knowledge of and control over its operations. However, with autonomous AI, much of the technical control and decision-making logic resides deep within the AI supply chain, often far removed from the end-user or the company being regulated. Because of this, retrospective supervisory oversight—where regulators review actions after they have occurred—is becoming an ineffective tool for managing risk.

Expanding the Regulatory Scope

To address these challenges, the authors suggest that regulation must move beyond the end-user. Because the critical components of AI autonomy are distributed across the supply chain, the scope of regulation must be expanded to include these upstream developers and providers. By bringing the entire supply chain into the regulatory fold, authorities can better address the systemic risks that arise when AI systems operate with a high degree of independence.

Analyzing Existing Frameworks

The research investigates four distinct regulatory systems to understand how they currently handle—or fail to handle—AI autonomy:

  • UK regulation of content platforms
  • Data protection laws
  • UK financial services regulation
  • The EU AI Act’s cross-sectoral regime
    By analyzing these frameworks, the authors identify the specific gaps created by agentic AI and propose potential solutions that regulators could adopt to modernize their approach.

Moving Toward Active Governance

The paper concludes that governance systems cannot simply replicate existing models; they require a fresh approach. The authors advocate for a transition from reactive, retrospective regulation to an "active" process. This shift is intended to help regulators stay ahead of the rapid evolution of autonomous AI, ensuring that governance remains effective even as the technology continues to generate new and complex systemic risks.

Comments (0)

No comments yet

Be the first to share your thoughts!