AI Policy Wiki
Dashboard

Agentic AI: The Governance Race We Must Not Lose (SCSP, June 2026)

medium confidence · updated 2026-07-25

Special Competitive Studies Project assessment arguing that agentic capability lives in the scaffolding around a model rather than in the model itself, so model-directed governance misses the risk; that an accountability deficit exists across responsibility, evaluation, and privacy; and that minimum US actions are codifying and resourcing CAISI's agentic-evaluation mandate, mandating tamper-evident action logs through federal procurement, assigning non-delegable liability to an identifiable legal person per deployed agent, closing the talent gap, and setting allied standards.

"Agentic AI: The Governance Race We Must Not Lose" is a June 18, 2026 assessment by Ylli Bajraktari, president of the Special Competitive Studies Project, and Rama Elluru, published on SCSP's Substack. It argues that US governance of agentic AI is losing ground to the technology, identifies where the governance target has been misplaced, and sets out five actions it frames as minimum necessary. It is an advocacy assessment from a national-security-oriented organization and is treated here as an argument.

The strategic-competition framing

SCSP opens from competition, on the premise that the US must simultaneously harness agentic AI's benefits and defend against its threats. It characterizes China's approach as governing agentic AI through existing regulation, standards, and specifications rather than agentic-specific hard rules — a choice it reads as preserving deployment flexibility while avoiding premature constraint on domestic development. See Chinese AI Policy.

Its restatement of the competitive threat is the assessment's distinctive move: the risk "is not simply that China may field agentic AI first, but that adversaries will deploy agentic systems precisely in the domains where U.S. governance is weakest." Agentic systems acting across networked environments are described as instruments of coercion, espionage, and influence, and an agent "that can navigate bureaucratic systems, identify exploitable vulnerabilities, and act without a clear attribution trail" as "a qualitative expansion of adversarial capability." SCSP expects these capabilities to improve fastest in cyber operations, influence campaigns, and economic-intelligence collection, where adversarial feedback loops are tight, and expects adversarial capability in those domains to advance as fast as or faster than US capability. Its conclusion reframes the race: the countries that succeed "will be those that learn to deploy, govern, and scale agentic systems effectively, not merely those that build them first."

Govern the capability, not the model

SCSP argues the word "agent" has been overloaded into a catch-all and that policymakers should target agentic capability. Its operative distinction: a tool executes instructions step by step, while an agent is handed a goal and determines the execution steps itself — "the difference between a calculator and a subordinate, between automation and delegation."

What makes such systems transformative, on this account, is not the model engine but the scaffolding around it, in five layers:

LayerFunction
ConnectorsBridge the model to real-world infrastructure — email, booking, financial platforms
MemoryLet the system learn and adapt over time
PlanningDecompose objectives, identify failure, and route around obstacles without human intervention
Permission structuresDefine what the system can access and act upon
GuardrailsDetermine what it will refuse to do — spending limits, human sign-offs

The policy consequence SCSP draws is direct: governance aimed at "the model" misses where agentic capability and real risk live, "since two systems running identical models can behave entirely differently depending on scaffolding." See Agent Architecture Patterns, Agent Autonomy Spectrum (5 Levels).

Where the technology is heading

SCSP characterizes progress as following "a heat map, not a tide" — fastest where right and wrong answers can be verified (software engineering, mathematical reasoning, structured data analysis), fragile where success is hard to define.

Near term (0–12 months): movement into paperwork-intensive professional domains — legal drafting, tax preparation, financial analysis, regulatory compliance — and toward orchestration, in which systems direct and coordinate networks of specialized agents in parallel, "with capability compounding as orchestrators supervise other orchestrators."

Medium term (2–5 years): entry into physical environments through robotics and embodied AI in controlled industrial settings, and consequential healthcare use cases — records infrastructure, clinical decision support, laboratory research — that existing regulatory frameworks are not designed to handle.

The single trend SCSP says policymakers must track above all others is AI helping build better AI, "a self-accelerating loop it describes as no longer theoretical." See Recursive Self-Improvement (RSI).

The accountability deficit

The assessment's central finding is three concrete failures already visible:

  1. Responsibility is unassignable. No one can reliably say who is responsible when an agent acts on a user's behalf and spawns sub-agents. SCSP cites the Air Canada tribunal ruling — holding the airline liable for its chatbot's misinformation — as a signal that institutions will not be able to disclaim responsibility for their agents, "even though the legal and technical architecture to operationalize that does not yet exist." See AI Liability.
  2. Evaluations ask the wrong question. They test whether an agent completed a task rather than whether it did so safely, could be manipulated, or caused non-obvious harm.
  3. Privacy risk is structural, not incidental. Agents build persistent inferential profiles of the individuals they serve, which existing privacy frameworks were not designed for.

The backlash argument

SCSP warns that a cascade of high-profile failures, or a single catastrophic one, "could produce a public and political reaction that sets back beneficial applications for years," citing the roughly six-year stall in self-driving vehicles after the 2018 Tempe, Arizona fatality.

The inference it draws runs against the usual framing of governance as a brake: "the absence of serious governance creates the conditions for the kind of failure that produces overcorrection," so responsible speed and responsible governance are mutually reinforcing. It adds a capacity constraint — the number of people who understand agentic AI well enough to govern it is small, unevenly distributed, and concentrated outside government — and treats closing that gap as a prerequisite for everything else.

SCSP frames five items as minimum necessary:

  • Resource and codify CAISI's agentic-evaluation mandate. SCSP states the Center for AI Standards and Innovation operates "on a fraction of the budget its mandate implies and on fragile statutory footing."
  • Use federal procurement as a forcing function. Require any agentic system sold to the government to include a tamper-evident action log recording who authorized what, which sub-agents were generated, and what each accessed and did — which SCSP argues would set a de facto national standard through OMB and GSA rather than through legislation.
  • Establish accountability architecture. Every deployed agent should map to an identifiable legal person holding non-delegable liability, modeled on financial-services practice.
  • Close the talent gap beyond CAISI. Extend fellowships, rotational programs, and direct-hire authorities to sectoral regulators, the national-security apparatus, and congressional committees.
  • Engage allies before adversaries arbitrage US governance weaknesses, working toward common standards in the highest-consequence domains — healthcare, cyber, finance, critical infrastructure.

The assessment closes by placing agentic AI alongside nuclear weapons, space, and the early internet as strategic competitions the US has navigated, arguing it did best when it combined urgency with seriousness: "The bottleneck is not the AI. It is our willingness to govern it with the same urgency we bring to building it."

Provenance

Published on scsp222.substack.com, SCSP's own channel. The gap-identifier verified it on 2026-06-24 against that host and against Inside AI Policy's June 22, 2026 reporting on the same assessment.

Relationships