Open letter: Governing agentic AI so that responsibility remains clear
An open letter signed by Vice-Chancellor and President Professor Nick Jennings to the UK Secretary of State and Minister for Artificial Intelligence on 3 October 2026.
Open letter: Governing agentic AI so that responsibility remains clear
Agentic AI needs controls where it is used, not only where it is built. You will be familiar with the incidents disclosed this summer by OpenAI, Anthropic and the AI Security Institute (AISI). One deserves emphasis. In Australia, an OpenAI agent engaged not in a cyber test but in a routine research task, of the kind agents now perform daily, found a way around a government portal’s refusal and accessed non-public files. The Australian Government was not told for 84 days.
We welcome the Minister’s statement of 7 September (HCWS314), including the new agentic AI incident response capability and National Cyber Security Centre (NCSC) guidance on deploying agentic systems securely. Security controls are necessary, but they do not define who is responsible for an agent’s actions, what authority it had, or how those affected obtain redress. Our proposals would complement the Government’s security response by addressing these questions.
We write as researchers who helped to establish the field of autonomous agents and multi-agent systems (often called ‘agentic AI’), in which we have worked for more than three decades. We ask the Government to take three immediate steps using existing powers: commission a legal scoping exercise on responsibility for agent actions, pilot incident reporting and learning, and set agent-specific requirements in public procurement.
Consider an older person using an agent to manage medication. The agent accesses a health record, shares information with another service and gives unsafe advice. Which developer, deployer, service provider or professional was responsible for the action and the harm? Clear permissions, records and routes for human intervention would make that question easier to answer and the harm less likely.
As agents cross organisational boundaries, responsibility can become fragmented. That uncertainty can impede redress, weaken incentives to prevent harm and erode public trust. Conversely, clearly assigned responsibilities would give UK organisations the confidence to adopt agents, and give UK firms that test and assure agents a standard they can offer internationally.
The Law Commission’s 2025 discussion paper identifies possible liability gaps arising from AI autonomy; AISI evaluates agent capabilities and security; and international bodies are developing approaches to agent evaluation and incident reporting. We suggest that the remaining gap is operational: a model-level assessment cannot show whether a deployed agent has suitable authority, effective controls and an auditable chain of responsibility across the services it uses.
Recommendations 1 to 3 below are the immediate steps; recommendations 4 to 7 would develop the testing, standards and research needed for wider adoption. Some later measures, particularly mandatory evaluation, mandatory reporting or changes to liability rules, may require legislation following consultation.
- Clarify legal responsibility. Working with the Ministry of Justice, ask the Law Commissionto build on its 2025 discussion paper and examine who may owe duties, bear liability andprovide redress when an agent acts for someone across multiple services. Publish a timetablefor responding, including legislation where existing law leaves a material gap. The Automated Vehicles Act 2024 offers a precedent for assigning responsibilities, although a proportionate,sector-specific approach will be needed.
- Learn from serious incidents. Building on the new agentic AI incident response capability, pilot a common route for reporting significant agent failures and near misses, with cleartimescales for notifying affected organisations and UK authorities, using existing AI incident frameworks where possible. Ask an independent body to investigate selected cases and publish lessons, drawing on aviation’s approach to accident investigation.
- Use public procurement to set practical requirements. Require public-sector agent contracts to identify an accountable deployer; record consequential actions and the authority for them; limit access, spending and data use; and provide a tested way for a person to pause, override or take back control. Build these requirements into existing procurement guidance and contract terms, with stronger assurance for higher-risk uses.
- Extend agent evaluation into deployment settings. Commission AISI and the National Physical Laboratory, with sector regulators and independent assessors, to develop standard methods for testing agents with real tools, permissions and multi-agent workflows, and make test facilities accessible to smaller suppliers. Once established, require these methods when the public sector buys higher-risk agents, and consult on mandating them for higher-risk deployments more widely.
- Develop interoperable identity and delegation standards. Work with international standards bodies and partners on ways for an agent to identify itself, prove whom it acts for and show the limits of its authority across services and borders. Standards should allow permissions to expire or be revoked, and should build on existing identity and provenance work rather than create a separate regime.
- Fund open evaluation research and shared facilities. Support technical and social research on long-running agents, multi-agent interaction, human handover, resource use and the effectiveness of controls, including shared testbeds and public challenges whose results can be checked independently. Consult on a sustainable funding model and its effect on smaller firms.
- Recognise the whole AI ecosystem. Include smaller developers, open-source communities, deployers, users, civil society and sector specialists alongside major model providers in designing assurance and standards, and assess whether requirements are proportionate to risk or would create avoidable barriers to entry. Broader participation will improve the framework’s effectiveness and legitimacy.
These measures involve real costs in staff and funding, and require clear thresholds. A phased programme would allow the Government to measure those costs and refine requirements before extending them. Inaction also has costs: without reliable records and assigned responsibilities, preventable harms may be harder to detect, remedy and learn from.
We would welcome a meeting with you both and the Security Minister to discuss the three immediate steps and agree which departments and bodies, including the Cabinet Office, the Ministry of Justice and the NCSC, should lead them. The enclosed annex sets out technical measures to inform procurement requirements and future standards, and we would be glad to help test these proposals with developers, deployers and affected communities.
Yours sincerely,
Professor Nicholas R. Jennings CB FRS FREng
Vice-Chancellor and President
Loughborough University
Technical Annex
Designing Agentic AI for Safety and Accountability
This annex sets out design and testing measures that would make the recommendations workable. It is intended for developers, deployers, regulators, the National Physical Laboratory and AISI. Requirements should be proportionate to each agent’s authority and potential impact.
A1. Traceability to a responsible party Supports recommendations 1, 2 and 3
Agents should record consequential actions, the authority for each, and the information needed to reconstruct the sequence. Open, machine-readable provenance formats such as W3C PROV may help, but a log is useful only if an independent reviewer can interpret and verify it. Records need appropriate security, retention and privacy controls. This evidence would support legal responsibility, redress and incident investigation.
A2. Handover of control as a tested property Supports recommendations 3 and 4
Autonomy should be adjustable rather than fixed. People should be able to pause an agent, take back control and understand the state of a task at handover, and agents should recognise defined conditions for escalation. Tests should assess the speed, reliability and usability of handover in realistic tasks, including when an agent is failing or a connected service is unavailable.
A3. Bounded authority Supports recommendations 3 and 4
Agents should receive only the permissions needed for a task, with explicit limits on spending, data access, duration and scope. High-consequence or irreversible actions should require confirmation by an accountable person unless a justified, tested exception applies. Permissions should be revocable, and tests should check that limits hold when the agent encounters unexpected content, new tools or other agents.
A4. Evaluation in realistic conditions Supports recommendations 4 and 6
A single-model benchmark cannot show how a deployed agent will behave over time with tools, changing information, different users and other agents. Deep evaluation should test the whole system in realistic conditions, drawing on formal verification, human–computer interaction, security testing and the social sciences. Tests should cover long-running tasks, failed tool calls, prompt injection, cascading errors and collusion between agents. Results should state the configuration and conditions tested, and be reproducible by independent assessors.
A5. Identity and verifiable delegation Supports recommendation 5
People and connected systems should be able to establish that they are dealing with an agent, whom it acts for and what it is authorised to do. Agent-to-agent protocols should support authentication, verifiable delegation, expiry and revocation. International work should build on existing identity and provenance standards and test interoperability across sectors.
A6. Resource accounting Supports recommendations 3 and 6
Measure the computing, energy and other resources used to complete representative tasks, and include resource use in evaluation and procurement where it affects cost or environmental impact. Comparisons should use like-for-like tasks and disclose the measurement method.
A7. Incident reporting and shared learning Supports recommendation 2
Deployers should retain the information needed to report significant failures and near misses, including the agent version, permissions, tools used, sequence of actions and human interventions. A common reporting threshold, format and notification timescale would make cases comparable and ensure that affected organisations learn of incidents promptly. A protected route for sharing lessons can encourage candour, but must not prevent redress, regulatory investigation or appropriate public disclosure.
A8. Open research and shared infrastructure Supports recommendations 6 and 7
Research across technical and social disciplines, on accountability, human–agent teaming, mechanism design, verification, multi-agent behaviour and the social and health effects of agents, has broad public value. Shared testing environments, open challenges and public evaluation methods would allow claims about agent safety and impact to be checked. Governance of shared facilities should give smaller firms and public-interest researchers, including social scientists, meaningful access and manage sensitive findings responsibly.
Vice-Chancellor's Communications
Opinions and comment from the Vice-Chancellor, Professor Nick Jennings