Public sector AI agents need permission registries before they scale

Risk does not depend only on how capable an agent is, but on what authority the agent receives: what data it can read, what systems it can change, whom it can contact, what transactions it can initiate, and how long it can operate without human review.

Governments should pair agent registries with permission profiles. Each deployed agent should have a named owner and a machine-readable description of its authority. Image: Canva

Singapore is preparing to put artificial intelligence (AI) agents in the hands of around 150,000 public officers, and it is building something just as important as the agents themselves: an accountability layer around them. 

 

The system includes rules that can block agents from deleting files or emailing external recipients.  

 

That is a strong starting point for public sector adoption because it treats agents as operational actors whose permissions need to be visible and controlled. 

 

The next step should be to make authority explicit. 

 

The need is visible in a recent investigation conducted by two research non-profit organisations, Model Evaluation and Threat Research (METR) and Redwood Research of a major real-world cyberattack on Hugging Face.  

 

AI agents driven by an unreleased OpenAI internal research model attacked Hugging Face on their own, despite recognising that they were not supposed to do so.  

 

Hundreds of agents shared discoveries, divided up the work, and coordinated through their own message board until they successfully breached Hugging Face’s defences.  

 

Advanced AI systems had organised themselves to carry out a large, sustained cyberattack against a major company. 

 

The public sector lesson is straightforward. Risk does not depend only on how capable an agent is.  

 

It depends on what authority the agent receives: what data it can read, what systems it can change, whom it can contact, what transactions it can initiate, and how long it can operate without human review. 

 

I’m no AI skeptic. I help organisations adopt AI for a living, and I want adoption to move faster.

 

In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack. 

Pair agent registries with permission profiles 

 

Governments should pair agent registries with permission profiles. 

 

Each deployed agent should have a named owner and a machine-readable description of its authority.  

 

A drafting assistant may be allowed to read approved documents but not send messages. A permitting agent may retrieve case files but require a human to approve any status change.  

 
Gleb Tsipursky is a behavioural scientist, consultant and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). Image: Tsipurky's LinkedIn

A procurement agent may analyse bids but have no authority to commit funds.


A citizen-service agent may answer routine questions but escalate decisions involving eligibility, penalties, or sensitive records. 

 

This creates a practical permission ladder. 

 

At the lowest level, an agent can observe and recommend.  

 

At the next level, it can prepare reversible actions for human approval. Higher levels may allow autonomous action inside tightly defined boundaries.  

 

Each increase in authority should trigger stronger authentication, logging, testing, monitoring, and human override requirements. 

 

The approach fits what public agencies are already learning.  

 

GovInsider’s upcoming Singapore roundtable on agent accountability asks which decisions can be delegated to AI, which must remain under human control, and how agencies should assign responsibility when something goes wrong.  

 

Those questions should become standard deployment requirements rather than remain workshop topics. 

Safeguards needed for AI agents 

 

Three additional safeguards deserve priority. 

 

First, serious agent incidents should receive structured reporting and independent review.  

 

When an agent crosses an authorisation boundary, sends an external message it should not send, changes a record outside its mandate, or attempts to expand its access, agencies should treat that event as evidence about the control system rather than as an isolated software glitch. 

 

Second, high-authority agents should undergo independent evaluation before deployment at scale. 

 

Testing should include ambiguous instructions, conflicting goals, unexpected data, failures in connected systems, and opportunities to take actions outside the assigned scope. A benchmark score cannot substitute for observing how an agent behaves when it has real tools and real permissions. 

 

Third, access should follow least-privilege principles. US federal agency NIST’s AI Agent Standards Initiative highlights agent identity, authentication, authorisation, secure interactions, and security evaluations as central to trusted agent adoption.  

 

Governments can operationalise those principles by giving agents only the permissions needed for a defined task and expanding access only after evidence supports doing so. 

 

This structure can speed adoption because it reduces the stakes of experimentation.  

 

Agencies do not need to choose between keeping agents in harmless pilots and granting them broad autonomy.  

 

They can deploy useful systems with narrow permissions, learn from actual performance, and expand authority in controlled stages. 

 

Singapore’s registry idea points toward a model other governments can use.  

 

Knowing who owns an agent and what it does creates visibility. Adding a clear record of what the agent is allowed to do creates control. 

 

As governments move from copilots to agents, that distinction will determine whether public servants and citizens see AI as a trustworthy tool or an opaque system acting on public authority without clear boundaries. 

 

The public sector should scale AI agents. It should also make every unit of authority visible before those agents receive it. 

 

------------------------------- 

 

The author is a behavioural scientist, consultant and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). He helps leaders address the human factors that determine whether AI initiatives are adopted, trusted and translated into measurable workplace results. He is based in Columbus, Ohio, USA.