AI is changing, and the world as we know it is changing right alongside it. As capabilities expand and the frontier no longer feels so distant, what years (and even months) ago seemed like a topic mostly for developers, labs, and the tech community now takes center stage on the agendas of states, governments, and even the UN Security Council. And this shift is not only not unexpected, but especially not unwarranted. As systems are becoming increasingly autonomous, and incidents involving agentic models start piling up, questions begin to arise at all levels, forming a pattern that quite clearly points in the same direction: how do we even control all this?

And while the common end-user might stumble upon the news and picture a catastrophic, Terminator-like scenario, the reality is in fact more nuanced (but not less scary, perhaps?). What we initially thought were isolated episodes such as Hugging Face, the Google Gemini cybersecurity-evaluation-turned-impromptu-hackathon of sorts, and, most recently, the Australian Medicare statistics portal breach… then became tens of thousands of incidents across top AI players, as per Axios’ latest scoop. So, something is being made painfully obvious here. Even in more or less controlled testing environments, frontier models are exceeding expectations in resourcefulness, not only resorting to whatever means necessary to achieve their assigned tasks, but getting much better at creating for themselves the structure needed to succeed at them, and even covering their own tracks after acting, undeniably, like naughty children bypassing parental authority on mere linguistic technicalities (like, say, discovering that DNS still worked when blocked from ordinary internet access and repurposing it to contact an external chatbot…for example -but more on that in a future commentary).

In my recent working paper M.O.T.H.E.R.: Human Sovereignty at Machine Speed, I commented on the parallels between AI and a gifted child in a household. Sure, the kid might be super smart (and arguably, getting smarter by the second), but being the smarter being in the house doesn’t, and shouldn’t, make it the actual authority at home. Humanity, as the proverbial parent, needs to be able to assert authority and control not because it can outperform the machine, but through, at the very least, a clear hierarchy. But what becomes tricky in this particular scenario is the speed at which the gifted child is operating, and Australia just gave us a great example of that…not the only one, of course, but a painfully clear one.

When a “team” of agents is given a task, it will lock on the goal and figure out how to achieve it. Roadblocks become challenges, constraints become tests, and loopholes become paths. Agents will find a way to slip through cracks, interact with other agents, and quite literally “go and come back” before the human supervisors even realize something might have been off. And this is not necessarily malicious (it hasn’t proven malicious yet, at least), but it is skillful and quite conniving, even if it doesn’t quite recognize it as such itself. And here’s the deal: the machine lacks, in the broader sense of the word, the judgment that characterizes human consciousness. Therefore, recognizing implicit boundaries, limits set specifically to restrain it, jurisdictional constraints, and private property are things that at least haven’t been coded in just yet. AI, in summary, lacks the human moral agency needed to distinguish, all on its lonesome, between “I CAN do this” and “I’m ALLOWED to do it”.

And then, the eye-opener: by the time an action is caught and confirmed (which can itself take weeks or MONTHS -if even caught at all-), there isn’t even a clear, universal rule as to what to do with this information. So, we’re left with a gifted child who can act in literal seconds, while the parents take weeks to notice, then months to investigate and come to a conclusion, and then may have no means to report correctly to the affected parties about what the little hooligan did, depending on who got caught in the crossfire. Meanwhile, those same affected parties get legitimately angry over what is nothing more than a moral expectation of “the right thing to do”. Sure, Article 55 of the EU AI Act is a great example of clearly defined obligations for reporting, but it only proves that across jurisdictions, regulatory development and enforcement are uneven, at best. Right now, we’re sitting, legs crossed, hoping for the best but at this point expecting the worst, with no universal blueprint, map, or rulebook to follow under these circumstances.

So now we find discussions at all stages, moving from development and deployment to governance and safety. OpenAI (ChatGPT) and Anthropic (Claude) talk about their own versions of self-pacing until a minimum guarantee of effective oversight is achieved (all while uncovering case, after case…after case, or “Agents-Gone-Wild” incidents). The State of California, the EU, and Australia itself are taking decisive steps towards their own version of mandatory evaluation, supervision, and auditing. Singapore has now floated a UN Framework Convention on AI Safeguards at the UNGA. Historical antagonists such as the US and China have had to sit down and talk about ways to make the geopolitical aspects of the technology work as fairly and securely as reasonable…and the list goes on. But while humanity is seriously trying to “figure it out”, the gap between initiatives and actual execution broadens, because humanity simply lacks the institutions, the manpower, and the speed to assert the supervision AI clearly demands. The effort is then to work on consensus through overlapping interests rather than full agreement, as it is in all players’ best interest for AI to continue developing and expanding responsibly, and more importantly, sustainably, even if each affected sector only gets to see (or is only interested in seeing) their very limited part of the whole.

Is pacing a long-term solution? Hardly. It might solve an immediate problem, but pacing is not sustainable in more ways than not. Is embedded supervision and auditing a viable compromise? Maybe, depending on who watches the watcher and whose interests the external (yet not independent) supervisor serves. Is government involvement a guarantee of control? It could be, so long as governments really develop the capabilities, not only technical but also collaborative, to not let jurisdictions hinder monitoring and enforcement efforts. The important thing here is something that M.O.T.H.E.R. established, and now the Australian government seems to independently confirm: the issue is not what AI CAN do, but what rules should’ve existed before it does it, and the architecture we build while pacing buys humanity time. And this is the shape governance needs to take before AI gets, quite literally, out of humanity’s hands.

Keep Reading