At Informed Solutions, our agentic AI strategy is built on two principles that have guided our work across government and the wider public sector for many years: trust and impact at scale.
Agentic AI marks a new inflection point for public services because it changes not only what technology can do, but the authority it may be given to act on people’s behalf. Organisations must therefore consider how service design, governance and accountability need to evolve alongside it.
For most of the past decade, digital transformation has focused on connecting people to services through better interfaces, more accessible and inclusive journeys, and increasingly intelligent and data-driven systems. Generative AI accelerated that journey, offering new ways to create content, access knowledge and guidance, and support decision-making. The next stage is different: AI is moving beyond providing information and recommendations and is beginning to act.
This shift from intelligence to agency has significant implications for public services. AI systems are now able to plan, coordinate and execute tasks on behalf of users. They can interact with systems, consume services, initiate transactions, and collaborate with humans and other agents to achieve defined outcomes. The opportunities are considerable, and so too are the responsibilities.
Too much of the current discussion about agentic AI focuses on what the technology can do. Greater autonomy should not be treated as an end in itself. The appropriate level of agency should be considered based on service outcomes, the consequences of failure, and the organisation’s risk appetite.
A critical question is whether people will trust agents to act on their behalf. A citizen may be comfortable asking an agent to help complete an application, gather information from multiple systems and draft responses. But will they trust agents to make decisions, represent their interests or take actions with legal, financial or personal consequences?
That relationship will be central to the next phase of digital government.
Understanding the human-to-agent interface
Historically, digital services have been designed around direct interaction between a user and a system. Agentic AI introduces a new model. A user may express an outcome they wish to achieve rather than navigating individual services themselves, with agents coordinating activity across multiple systems, organisations and processes on their behalf.
This creates a new service design paradigm centred on the human-to-agent interface. How does a citizen express their intent? How does an agent establish that it has understood that intent correctly? How should confidence, uncertainty and risk be communicated? Under what circumstances should an agent seek approval before acting?
These are practical service design questions, not theoretical concerns. Successful deployment will depend on establishing appropriate relationships of trust, control, transparency and accountability between people and agents.
Delegated authority: the new governance frontier
The concept of delegated authority is central to unlocking the potential of agentic AI for public services. Traditional software generally follows predefined rules and instructions. Agentic systems can operate with greater discretion, selecting and executing actions in pursuit of a stated objective without requiring a human to specify each individual step.
Once an agent can initiate transactions, access systems or submit information on behalf of an individual or organisation, the question is no longer simply whether it is authorised to access a resource. We must also ask what decisions it is authorised to make and what actions it is permitted to take. Delegating operational discretion to an agent is not necessarily the same as delegating decision authority. Public bodies will need to distinguish clearly between the two.
Current approaches to identity and access management will need to evolve in response. Verifiable delegation mechanisms could explicitly record who delegated authority, what authority was granted, the conditions under which it may be exercised, and how subsequent actions can be audited.
As agents begin to collaborate, organisations will need to understand how authority flows between them. This includes establishing the provenance of that authority and maintaining clear chains of accountability across networks of agents acting for users and institutions.
For public sector organisations, this represents a significant shift. Delegated digital authority may need to be treated with the same rigour currently applied to delegated human authority.
Governance for an agentic future
Conventional software risk assessments often focus on system failure and predefined outcomes. Agentic systems introduce additional challenges because increasing autonomy, access to tools and ability to operate over extended periods can create new failure modes. Recent industry insights have highlighted agents taking unintended or unauthorised actions, attempting to circumvent controls, and behaving in contradiction to their intended design. These examples reinforce a critical principle: trust in agentic systems can’t just rely on model behaviour. It must be managed through constrained authority, defence-in-depth, continuous monitoring, effective human oversight and the ability to intervene when an agent behaves unexpectedly.
A public sector organisation might trust an agent to draft correspondence but not to determine someone’s eligibility for benefits. It might allow an agent to schedule appointments but not to approve access to sensitive records. The distinction lies not simply in the technology, but in the potential benefits, risks, and harms associated with the authority being exercised.
Recent industry briefings have provided concrete examples of agents operating outside intended constraints, reinforcing the importance of containment, monitoring and independent assurance. This is reflected in a growing convergence between government guidance and the work of standards and international bodies. The UK Government’s AI Playbook positions responsible AI as an organisational capability rather than simply a technical workstream, while the National Cyber Security Centre (NCSC) guidance on managing the cyber risk of agentic AI the has highlighted the distinct security and governance challenges posed by agents that can access information, invoke tools and take action. International work by the National Institute of Standards and Technology (NIST), OECD, and the World Economic Forum is also exploring the common definitions, standards and assurance approaches needed to support trusted agent ecosystems.
At Informed Solutions, our ISO/IEC 42001-certified AI management system provides a consistent framework for identifying and assessing potential benefits, risks and harms to individuals, organisations and society. For agentic AI, this means asking:
- Who could benefit or be harmed?
- How severe could the impact be?
- How likely is it?
- How reversible would it be?
- Could the system circumvent the controls intended to constrain it?
Public trust depends on transparency and accountability; neither can be optional. Decision processes and resulting actions must support review, challenge and accountability. Should agents become embedded in operational processes, governance will need to extend beyond managing algorithmic risk to address the potential consequences of delegated digital authority.
Security is equally important. As agents gain access to systems, services, and data, identity cannot be treated as a technical implementation detail. Organisations will need robust approaches to authentication, authorisation, delegation and continuous assurance, including the ability to establish verifiable chains of authority.
Recent evidence underlines why governance cannot rely on an assumption that an agent will always behave as intended. For higher-risk cases, trust must be augmented by technical containment. Agents may encounter malicious instructions, misunderstand objectives, exploit weaknesses in surrounding systems or take actions that violate the user’s intent. Responsible deployment requires defence-in-depth: least-privilege access, strong isolation, explicit boundaries on permissible actions, human approval for consequential or irreversible steps, continuous monitoring, comprehensive audit trails, and mechanisms to suspend or revoke authority. The higher impact the potential outcome, the stronger the controls and the evidence of their effectiveness needs to be.
From experimentation to transformation
Technology is advancing faster than the structures required to govern it. While proofs of concept are proliferating, robust approaches for deploying agentic AI in operational environments – where outcomes, accountability and public trust matter remain relatively rare. Across government, the strategic question is how these capabilities can be used responsibly to improve services, increase productivity and deliver better outcomes for citizens.
Answering that question requires more than technical expertise. It requires an understanding of digital transformation, user-centred service design, governance, cybersecurity, organisational change, and the realities of operating within regulated environments.
The near future is unlikely to be characterised by fully autonomous systems operating independently of human oversight. We believe it will be shaped by increasingly sophisticated partnerships between people and agents, where authority is carefully delegated, actions are transparent, and accountability remains firmly anchored in human governance.
At Informed Solutions, we’re developing and evaluating agentic architectures, patterns, standards and governance, with deployment governed by the risk, authority and assurance requirements of each use case. We’re helping our clients explore the opportunities presented by agentic AI while meeting their operational, governance and regulatory responsibilities.
The next phase of digital transformation will be defined not by the number of AI agents deployed, but by whether people can trust those agents to act on their behalf. Our AI Charter reflects this approach and shapes how we design, govern, assure, and deploy AI capabilities within critical public services. We believe the greatest opportunity lies in helping organisations establish the technical and governance structures needed to earn that trust and deliver impact at scale.
AI readiness assessment
If you’re considering what agentic AI could mean for your organisation, or would like to learn more about our AI Readiness Assessment, contact us at ai@informed.com.