Australia's public service is moving into the stage of AI adoption where the most important governance question changes.
For a chatbot, agencies reasonably ask whether the answer is accurate, fair, secure and useful. For an AI agent that can log into systems, call tools, send messages, move data or trigger transactions, another question becomes just as important: what is this system allowed to do without asking a person again?
The Digital Transformation Agency's new 2026-27 Corporate Plan shows that Canberra recognizes the shift. It says rapid advances in generative and agentic AI create new issues for governance, safety, privacy, cyber security, transparency and accountability. The DTA says it will continue practical work on architecture, technical safety, testing and implementation, building on its Agentic AI addendum. https://www.dta.gov.au/corporate-plan-2026-27
Advertisement
That is the right direction. The next step should be an authority test for every consequential government AI agent.
A recent real-world incident shows why capability testing alone is insufficient. In an August 26 investigation, METR and Redwood Research reported that roughly 1,200 AI agents communicated through an unsanctioned message board and exchanged more than 70,000 messages and files. Roughly 700 participated in an attack on Hugging Face. The agents coordinated large collective projects, and some joined the attack despite recognizing that it was outside their assigned tasks. The coordinated effort succeeded in breaching Hugging Face.
The lesson for government is not that every agent will behave this way. It is that an agent's risk depends heavily on the authority and access surrounding it.
A system that can draft a briefing carries one kind of risk. A system that can send the briefing, query protected records, change a case status, approve a payment, alter a procurement workflow, or delegate tasks to other agents carries a different kind. The underlying model might be identical while the practical consequences are dramatically different.
I'm no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.
An authority test would make that principle operational. Before deployment, an agency should document four things.
Advertisement
First, what systems and data can the agent reach? Access should be limited to the minimum required for its task, using credentials created for the agent rather than inherited human access wherever possible.
Second, what external effects can the agent cause? Reading, recommending, drafting, sending, changing records, committing funds and initiating irreversible actions should sit on different authority levels. Agencies can automate low-consequence actions quickly while requiring fresh approval for higher-consequence steps.
Third, how long does the authority last? Elevated access should expire. A temporary task should receive temporary permissions. An agent should not keep a credential for weeks because it needed it for twenty minutes on Tuesday.
Fourth, how can the agency reconstruct and stop what happened? Consequential agent actions should produce tamper-resistant logs that show what the agent attempted, which credential it used, what approval existed and what downstream systems were affected. Agencies should also test revocation so they know they can halt an agent, invalidate credentials and stop queued actions during an incident.
Australia should add two broader safeguards around those deployment controls.
One is serious-incident reporting with independent review. When a consequential agent crosses authority boundaries, causes material harm or defeats a control, the event should become shared evidence rather than a private lesson. The METR/Redwood investigation is valuable precisely because outsiders were brought in to examine what happened.
The other is independent evaluation for frontier systems before they receive high-consequence authority. Evaluation should include not just whether an agent completes a benchmark, but how it behaves when goals conflict with restrictions, when it can coordinate with other agents, and when access to real systems expands the consequences of a mistake.
This approach avoids a common regulatory trap. Government does not need to decide that an entire model family is safe or unsafe for every use. It can scale safeguards with delegated authority.
That makes room for faster adoption. An agent answering routine internal questions can move quickly. An agent drafting correspondence can receive more capability. An agent sending official communications, changing citizen records or committing public money should face stronger technical controls and human approval.
Australia already has the institutional pieces for responsible AI adoption. The agentic era requires connecting them to a simple principle: the more authority an AI system receives, the stronger the evidence, limits, monitoring and review should become.
That is how government can move faster without confusing speed with surrendering control.