![]() |
| Pix credit here |
This working paper undertakes a structured comparative reading of thirteen instruments addressing the governance of agentic artificial intelligence — systems capable of sustained, multi-step, tool-using autonomous action — issued between late 2024 and mid-2026 by jurisdictions with markedly different political-economic systems and governance traditions. The instruments span binding legislation (the EU AI Act; Japan’s Act on Promotion of AI-Related Technologies), executive orders and presidential memoranda (the Trump Executive Order of June 2026, Trump NSPM-11, Biden Executive Order 14110, Biden NSM-25), intergovernmental recommendations (the OECD Recommendation on Artificial Intelligence), regional development strategies (the African Union Continental AI Strategy), voluntary governance frameworks (Singapore’s Model AI Governance Framework for Agentic AI v1.5, the Safeguards for Agentic Finance at Runtime framework), cybersecurity guidance (the Five Eyes/Australia advisory on careful adoption of agentic AI services), government employee guidance (Canada’s Treasury Board Secretariat Guide), analytical frameworks (the Gradient Institute’s risks-and-controls framework for multi-agent systems), and aspirational international instruments (UN General Assembly Resolution 79/325, the UN High-Level Advisory Body report). The primary object of inquiry is China’s Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents (2026).
Drawing on my earlier work — which conceptualizes AI governance through the lenses of AI as strategic infrastructure, the development-security dialectic, platforms as governance intermediaries, the instrumentalisation question (the risk that the relationship between autonomous technology and its wielders may be reversed), and the ‘cognitive cage’ metaphor for the political-economic structures that constrain regulatory imagination — the analysis suggests that the near-simultaneity of these instruments may reflect a shared recognition that agentic AI poses governance challenges existing frameworks do not adequately address. Yet the convergence on vocabulary — autonomy, oversight, accountability, transparency — appears to mask sharp operative divergences that become visible only when these terms are traced to their institutional and normative contexts. The instruments may be read as revealing competing conceptions of what governance is for: fundamental rights protection (EU), market integrity (Singapore), cybersecurity (Five Eyes), bureaucratic accountability (Canada), development and the bridging of capability gaps (AU), socialist modernization under party-state coordination (China), and market sovereignty fused with national security (US). The instrumentalisation question — what happens when agents do not merely assist governance but perform it — remains, the analysis suggests, inadequately addressed by all instruments examined.
The paper concludes by considering path dependence and what might be characterized as techno-bureaucratic mimicry — Nietzsche’s herd instinct refracted through the practices of benchmarking and landscape analysis — while observing the paradox that the very conformity these practices produce also generates variation, and that the gap between rhetoric (which foregrounds difference) and operative text (which may reveal a narrower bandwidth of actual divergence) poses questions about the depth of the disagreements the instruments appear to embody.
Executive Summary follows below. The full paper may be accessed at SSRN HERE.
Executive Summary
This paper examines thirteen governance instruments from twelve jurisdictions and institutional settings, issued between 2023 and 2026, that address the regulation of artificial intelligence systems capable of autonomous action, multi-step planning, tool use, and environmental modification — commonly described as agentic AI. The primary object of analysis is China’s Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents, read against instruments from Singapore, the European Union, Australia and the Five Eyes alliance, Canada, Japan, the United States, the African Union, and the United Nations, as well as the OECD Recommendation on Artificial Intelligence and a sector-specific financial services framework developed under the Monetary Authority of Singapore. The paper draws throughout on the analytical framework developed by Larry Catá Backer in his 2026 comparative lecture series, which argues that the major regulatory blocs do not merely regulate AI differently but construct it differently as a regulatory object.
Key Findings
Definitional divergence creates interoperability challenges. There is no agreed international definition of agentic AI. Singapore disaggregates agency into two distinct dimensions — the action-space available to a system and its degree of autonomy — permitting granular, deployment-specific risk assessment. The Five Eyes guidance narrows its focus to LLM-based agentic systems, foregrounding inherited model vulnerabilities and cybersecurity attack surfaces. China’s Implementation Opinions encompass embodied agents — including robots, smart agricultural machinery, and disaster rescue systems — alongside software agents, reflecting a broader conception of the governance domain that includes industrial automation and agricultural modernization. The United States defines “covered frontier models” through classified national security benchmarks determined by the National Security Agency. The EU AI Act does not address agentic AI as a distinct category; its risk-tiered classification was designed before the current wave of agentic systems. Policymakers designing cross-border governance arrangements must account for these definitional gaps, which affect the scope and direction of every subsequent regulatory decision.
Risk frameworks are not commensurable. Singapore offers an eight-dimension risk-factor matrix spanning domain, data access, scope of actions, reversibility, autonomy, task complexity, system complexity, and third-party involvement. The EU AI Act uses a four-tier risk classification — prohibited, high-risk, limited-risk, and minimal-risk — defined primarily by domain of application and potential for harm to fundamental rights rather than by the functional characteristics of agentic systems. China organizes risk through a development-security dialectic in which neither safety nor innovation is subordinate to the other, with sector-specific administrative supervision determined by the government body already responsible for a given domain. The United States approaches risk primarily through voluntary cybersecurity cooperation and criminal enforcement against malicious actors, with no general-purpose AI governance framework. No framework maps onto another, complicating any effort at mutual recognition or regulatory equivalence.
Human oversight requirements vary fundamentally in purpose and mechanism. Singapore mandates meaningful human accountability with explicit attention to automation bias, alert fatigue, and the erosion of situational awareness, defining significant checkpoints for high-stakes, irreversible, or atypical actions. The SAFR framework provides per-action runtime governance checkpoints through a Disposition Engine that evaluates each agent action independently, ensuring that prior authorization does not carry forward across steps. The Five Eyes guidance emphasizes least privilege, defense in depth, and graduated autonomy with phased deployment. The EU AI Act requires in-built operational constraints that the system itself cannot override. Canada introduces bounded autonomy and recoverability as organizing principles, requiring that agents operate within tight, explicit parameters and that they can be paused, stopped, or returned to a known safe state at any point. China guarantees user informed consent and preserves the user’s final authority over agent actions, but also deploys agents in functions such as public opinion guidance, raising questions about whether oversight serves to protect individual autonomy or to ensure alignment with broader governance objectives. The US instruments (under the Trump administration) contain no general human oversight requirements for civilian AI, relying instead on constitutional chain-of-command accountability within the national security enterprise.
Platform governance is a major fault line. China assigns platforms a structurally distinct role as governance intermediaries executing state directives through credit evaluation mechanisms — a form of delegated governance rather than mere regulatory compliance. Singapore maps a six-role agentic AI value chain from model developers through end users, distributing accountability across the chain. SAFR specifies a runtime governance infrastructure in which the platform mediates every agent action through a configurable controls repository. The EU imposes provider and deployer obligations along its value chain. The United States imposes no platform governance obligations for AI systems. This divergence has immediate operational implications for multinational technology companies that must navigate fundamentally different expectations regarding their governance role.
The US approach is structurally distinctive. The United States is the only jurisdiction to explicitly prohibit mandatory licensing, preclearance, or permitting of AI models. Innovation and national security are fused as co-constitutive objectives rather than balanced against each other. Deep public-private interpenetration — including voluntary frameworks for early government access to frontier models, joint cybersecurity clearinghouses, and classified benchmarking processes — replaces arm’s-length regulation. No general-purpose AI governance framework exists at the federal level. US banking regulators (SR 26-2) explicitly excluded agentic AI from the scope of their first refresh of model risk management guidance in fifteen years, describing such systems as “novel and rapidly evolving”.
No instrument adequately addresses the problem of agents becoming embedded in core institutional processes. As AI agents are integrated into government services, judicial assistance, financial infrastructure, and national security operations, the boundary between tool and institution dissolves. When an agent handles aspects of case management, evidence analysis, or adjudication assistance as an integrated component of the judicial process, it is no longer merely assisting governance — it is performing governance. No instrument in the comparative set provides a satisfactory framework for governing a process in which the governance instrument itself becomes a participant.
Global coordination remains fragmented. The UN has established institutional architecture — an Independent International Scientific Panel of forty members and a Global Dialogue on AI Governance — but the Panel’s outputs are explicitly non-prescriptive. The EU achieves de facto extraterritorial reach through market power, applying its regulation to providers placing systems on the EU market regardless of where they are established. The Five Eyes pursue operational convergence among security allies through harmonized cybersecurity guidance. China proposes an Agent Interconnection Protocol with global reach and calls for actively cultivating a global ecosystem for intelligent agents. The United States pursues bilateral allied coordination under America First principles. These competing visions of international order have not been reconciled.
Implications for Operationalization
Organizations operating across jurisdictions face a compliance landscape with no common baseline. The shared vocabulary of autonomy, transparency, and accountability masks divergent operative requirements — transparency may mean the right of an individual to understand how a decision affecting them was made, or it may mean a requirement that AI systems operate in a manner consistent with social stability and state-defined values. The absence of agreed risk assessment methodologies means organizations must develop internal frameworks capable of satisfying multiple regulatory expectations simultaneously. Runtime governance mechanisms of the kind SAFR specifies for financial services — per-action evaluation, structured escalation, and tamper-evident audit logging — represent the most operationally concrete model currently available, but they have been developed for a single sector and their transferability to other domains remains untested.
Path dependence suggests that early governance choices — definitional scope, risk categories, enforcement mechanisms — will constrain future options. Organizations have a window to influence these choices through standards-body participation and regulatory engagement, particularly as several instruments are explicitly framed as provisional or iterative. The gap between governance rhetoric and operative text means that compliance officers should attend to the actual requirements of instruments — the specific obligations, timelines, and enforcement mechanisms they contain — rather than their public framing. The instruments examined here are each partial responses to a challenge that exceeds the capacity of any one instrument or any one governance tradition to resolve; what the comparative exercise demonstrates is not the superiority of one approach over another but the extent to which different political systems, confronting structurally similar technological developments, produce governance responses that reflect their deepest assumptions about the relationship between the state, the market, the individual, and the technology that increasingly mediates among them.

No comments:
Post a Comment