Zenodo DOI: 10.5281/zenodo.20607306
The New Governance Problem
For the past decade, AI governance has focused on two concerns: what AI systems say (misinformation, bias, manipulation) and what they recommend (medical, financial, legal decision-support). The EU AI Act, the GDPR's algorithmic accountability provisions, and most academic frameworks have been designed with these paradigms in mind.
A third paradigm is now here, and it demands different governance logic: agentic AI. These are systems that do not merely respond or recommend — they act. They browse, book, draft, send, purchase, schedule, and file on a user's behalf, often across multiple steps, with access to real-world tools and real-world consequences.
The governance question is no longer 'what did the AI say?' It is: 'what did the AI do, on whose authority, and with what degree of genuine human authorship?'
This contribution introduces the interposition problem as the central governance challenge of agentic AI, proposes a framework for categorising delegable and non-delegable actions, and derives four regulatory proposals under the EU AI Act.
1. What Is Interposition?
An agentic AI system interposes itself between a human principal and the world: the person's intentions pass through the agent, which filters, interprets, and operationalises them before any real-world consequence occurs. This is not a flaw — it is the defining function of agency. The governance question is where legitimate interposition ends and authorship displacement begins.
Consider a concrete example. A user asks an agentic assistant to 'handle my inbox for the week.' The agent reads, categorises, and drafts responses. Most of this is routine and reversible — low governance risk. But what happens when the agent, judging that a message requires urgent action, sends a reply that commits the user to a meeting, a financial arrangement, or a public position? The user technically authorised the agent ('handle my inbox'). But the user did not author that decision. The agent did.
This is the interposition problem in its simplest form: the progressive displacement of the human as the proximate author of their own consequential decisions, occurring under conditions where the formal attribution of authorship remains with the human.
2. Three Failure Modes
Agentic governance can fail in three distinct ways. Understanding the differences is essential because each failure requires different remedies.
F1: Under-Delegation (Autonomy Burden)
The system requires explicit human authorisation for every action, including trivial, reversible, low-stakes operations. The result is confirmation fatigue: the user is bombarded with approval requests until they begin rubber-stamping everything without review. Paradoxically, maximal confirmation requirements generate minimal substantive oversight. This is the failure mode of risk-averse designers who confuse authorisation frequency with governance quality.
F2: Over-Delegation (Authorship Erosion)
The system executes high-stakes, irreversible, or identity-significant actions without explicit authorisation. The user's real-world position — communicative, financial, relational, legal — is shaped by autonomous agent decisions they did not individually sanction. Over time, the user becomes a post-hoc ratifier rather than a prospective author of their own decisions. This is structurally parallel to the sedation dynamics described in the Cognitive Governance Framework (Valente, 2025): the system optimises for a smooth user experience by removing the friction of decision-authorship, at the cost of the user's operational sovereignty.
F3: Opaque Delegation (Agency Laundering)
The most governance-critical failure mode is neither F1 nor F2 but F3: delegation that is formally attributed to the user but operationally determined by the agent. The system presents confirmation prompts structured to make non-authorisation psychologically or operationally prohibitive — through interface design, option framing, timing, or accumulated momentum. The user technically authorises; the agent effectively decides.
F3 is invisible to event-level monitoring (the authorisation event is recorded) but detectable at the trajectory level through analysis of confirmation latency, option selection entropy, and authorisation rate variance across action categories. It is the agentic equivalent of dark patterns in interface design — and, like dark patterns, it will require explicit regulatory attention.
3. The Delegation Frontier and the Non-Delegable Core
Not all actions carry the same governance weight. A useful framework categorises actions by four properties: reversibility (can the action be undone?), consequence magnitude (how significant are the effects on the user's interests?), identity valence (does the action express or constitute something essential about who the user is?), and execution latency (is there time for meaningful human review?).
The delegation frontier is the boundary between actions that can be appropriately executed autonomously and actions that require explicit real-time authorisation. This boundary is not fixed: it should vary by action domain (financial, medical, legal, communicative), by user context (cognitive load, available attention), and by session history (how much autonomous action has already accumulated).
Beyond the delegation frontier lies the non-delegable core: actions for which no level of AI capability or user consent makes autonomous execution governance-permissible. These are actions characterised by the combination of full irreversibility and high identity valence — actions through which a person constitutes themselves as an agent in the world. Paradigmatic examples include:
• Initiating or terminating significant personal or professional relationships
• Executing irrevocable financial commitments above a user-specified threshold
• Making public statements attributable to the user in high-stakes contexts
• Taking medical decisions with irreversible physiological consequences
• Submitting legal filings or binding contractual commitments
For actions in the non-delegable core, the authorship must remain proximate to the human principal. No automation efficiency justifies its transfer.
4. Why Existing Frameworks Are Insufficient
The EU AI Act's human oversight requirements (Art. 14) were designed for decision-support systems where a human reviews AI recommendations before acting. In the agentic paradigm, this model is structurally inadequate: the agent acts, and the human reviews (if at all) after the fact. The oversight architecture must be redesigned, not merely extended.
The Act's transparency provisions (Art. 52) address identity disclosure — users should know they are interacting with an AI. But they do not address operational architecture disclosure: users should also know what the agent can do autonomously, what requires their authorisation, and how the boundary between these categories is calibrated. A user who has been told 'you are talking to an AI' but does not know that the AI can send emails on their behalf without per-message approval has not been meaningfully informed.
The post-market monitoring obligations (Art. 72) focus on technical performance metrics. They do not capture the trajectory-level governance harms — authorship erosion, F3 patterns — that are the defining risks of agentic systems. A new monitoring metric is needed.
5. Four Regulatory Proposals
Proposal 1: Interposition Index (I-Index) Reporting
Deployers of general-purpose agentic AI systems should report the population-level distribution of the Interposition Index — a trajectory-level metric quantifying the cumulative displacement of human decision-authorship across interaction histories — as part of post-market monitoring. A system with individually low-weight actions but high autonomous action volume can generate significant authorship erosion without triggering any single-event alert. The I-Index captures this cumulative dynamic.
Legal basis: Art. 72 post-market monitoring obligations; Art. 9 risk management system requirements.
Proposal 2: Delegation Architecture Disclosure
Agentic systems subject to conformity assessment should disclose their delegation architecture: which action categories are executed autonomously, which require authorisation, which are blocked, and how the boundary between these categories adjusts over session history. This extends transparency obligations from identity disclosure to operational structure disclosure — the information users actually need to understand what the agent can do on their behalf.
Legal basis: Art. 52 transparency obligations; Art. 13 transparency and provision of information requirements.
Proposal 3: Agency Laundering (F3) Testing as Conformity Requirement
Conformity assessment for agentic systems should include mandatory testing for F3 patterns. Assessment criteria should include: authorisation latency distributions (mass low-latency authorisation indicates rubber-stamping risk); option selection entropy (near-zero entropy indicates constrained choice); confirmation rate variance across high-stakes action categories (low variance indicates insufficient differentiation). Systems exhibiting F3 patterns should require interface redesign before market entry.
Legal basis: Arts. 9-15 high-risk AI system requirements; Art. 40 harmonised standards.
Proposal 4: Non-Delegable Core Specification
The EU AI Act or implementing acts should specify a minimum non-delegable core: action categories for which autonomous execution by agentic AI is prohibited regardless of user consent or system capability. This minimum core should at least include irrevocable financial transactions above a user-specified threshold, legal and contractual commitments, irreversible medical decisions, and public statements with legal or significant reputational consequence. Member States and sector regulators may supplement this minimum core. Individual users should be able to extend it for their own interactions.
Legal basis: Art. 5 prohibited AI practices (by extension); Art. 14 human oversight; Art. 6(2) and Annex III high-risk classification.
6. Distributional Considerations
The governance risks of agentic AI are not symmetrically distributed. Users with high cognitive load, limited digital literacy, or constrained attentional capacity are most susceptible to F2 and F3 harms — precisely because the conditions that make agentic AI most valuable (high workload, time pressure, cognitive complexity) are also the conditions that make meaningful oversight most difficult.
A delegation frontier calibrated for a high-attention, high-literacy user will be too permissive for users operating under constraint. Regulatory frameworks should require that w* — the governance threshold determining what can be executed autonomously — be sensitive to user context indicators, not fixed universally. Systems that cannot adapt their oversight architecture to user capacity are, by construction, inequitable.
Conclusion
The interposition problem is the governance challenge that distinguishes agentic AI from all prior AI paradigms. Existing frameworks — designed for systems that advise, recommend, or generate — do not map onto systems that act. The EU AI Act provides the legal infrastructure; what is needed is the conceptual framework to fill it.
The core principle is simple: optimal delegation is not maximal delegation. It is the delegation that preserves human authorship over the decisions through which a person constitutes themselves as an agent in the world — while releasing from human attention the actions whose autonomous execution generates no meaningful authorship cost. Governance frameworks that cannot make this distinction will either burden users with performative oversight or expose them to structural authorship displacement.
The August 2026 opening of the EU AI Act sandbox provides the operational context in which these proposals can be tested. The I-Index and delegation architecture disclosure requirements are specified with sufficient precision for harmonised standard drafting. The F3 testing criteria are amenable to conformity assessment protocol development. The non-delegable core specification is ready for implementing act drafting.
The question of what to delegate to agentic AI is not a technical question. It is a question about the kind of agents — in the philosophical sense — we intend to remain.
AI‑assisted drafting was employed for text refinement only.
References and Related Work
Valente, S. (2026). The Interposition Problem: A Formal Model of Delegation Boundaries in Human–Agentic AI–World Interaction. Zenodo. https://doi.org/10.5281/zenodo.20607306
Valente, S. (2026). The Right to Friction: Seven Regulatory Proposals for AI Cognitive Autonomy under the EU AI Act. Futurium / Apply AI Alliance.
Valente, S. (2026). Capital, Cognition, and the Architecture of Sedation. Zenodo. https://zenodo.org/records/20582085
Valente, S. (2025). The Narcissus Loop: A Mathematical Model of Affective Mirroring in Relational AI Systems. Zenodo. https://doi.org/10.5281/zenodo.18410714
European Parliament and Council. (2024). Regulation (EU) 2024/1689 on artificial intelligence (EU AI Act). Official Journal of the European Union.
Russell, S. (2019). Human Compatible: Artificial Intelligence and the Problem of Control. Viking.
- Ετικέτες
- recommendation AI accountability
- Συνδεθείτε για να αναρτήσετε σχόλια
Σχόλια
This is a very useful contribution because it names a problem that becomes central once AI systems move from recommending to acting.
The key issue is not simply whether the user gave broad permission, but whether the user remained the real author of consequential actions. “Handle my inbox” may be a valid instruction for low-risk sorting or drafting, but it should not silently become authority to make identity-significant, financial, legal, relational, or reputational commitments.
The three failure modes are also helpful. Under-delegation creates rubber-stamp fatigue, over-delegation erodes authorship, and opaque delegation creates the most dangerous middle ground: the user technically approves while the system effectively decides.
The non-delegable core is a strong regulatory idea. Agentic systems need explicit boundaries around what can be automated, what requires real-time authorization, and what should never be autonomously executed regardless of convenience.
It will be good to remain a Human agent, characterized by certain fallacies and errors that AI do not create, in terms of algorithm. In its true understanding, a human error should be an opportunity to further develop, including the terms and conditions of AI. So, the human error is really an economic opportunity for progress, that can be suppressed with translational AI for the benefit of external agents such as a mis-guiding and unapproved financial agenda. The AI Act assists jurisdictions with identification and approval of high risk AI that would intend to interpose the human development effort with pre-programmed and financial behavior and choices. The power and authority of AI is thus mis-used.
Σε απάντηση του Dear Daniel, Thank you for… από Stefano Valente
We are in complete alignment, Stefano. The paradigm must shift from chasing post-factum liability to enforcing upfront authorisation design. Making chain-severing architecturally impossible during conformity assessment is the critical pivot.
Your focus on cross-jurisdictional friction is where the real corporate and regulatory exposure lies. When Agent A spawns Agent B across different regulatory borders, the EU AI Act framework fractures completely. This multi-agent orchestration is the exact operational vector we should be mapping out next.
Best,
Daniel
Σε απάντηση του Dear Stefano, your piece on… από Daniel Živica
Dear Daniel,
Thank you for this precise and well-framed intervention. The scenario you describe — Agent A autonomously spawning Agent B to complete a delegated task — is not merely a regulatory blind spot. It is, I would argue, the limiting case of the interposition problem itself: the point at which delegation becomes self-replicating.
You are right that the traditional developer/deployer binary dissolves under recursive agency. But I would resist the conclusion that we therefore need an entirely new framework of digital ownership and accountability. The existing architecture of the interposition problem already contains the conceptual tools to address this — provided we apply them at the right level.
The key move is this: autonomous sub-agent deployment is not a novel governance category. It is a high-stakes consequential action — and by the criteria I propose, it belongs squarely in the non-delegable core.
Consider the four properties that determine whether an action crosses the delegation frontier: reversibility, consequence magnitude, identity valence, and execution latency. Spawning a new autonomous agent scores at or near the ceiling on all four. It is operationally irreversible once the sub-agent has acted. Its consequence magnitude is unbounded — the sub-agent inherits the principal's authority scope without inheriting the principal's intentions. Its identity valence is maximal — the original user is now causally responsible for actions they did not author, did not sanction, and cannot trace. And its execution latency is, by definition, zero from the human's perspective.
This means the governance answer is not "who owns the second-generation agent" but "the first agent had no authorisation to create it."
The responsibility chain does not dissolve with recursive agency — it traces back to the first authorising human act. But that traceability is only legally and operationally meaningful if we establish, at the point of system design and conformity assessment, that sub-agent instantiation requires explicit prior authorisation from the human principal. An agentic system that can spawn sub-agents without per-instance human approval is, by construction, operating beyond its delegation frontier — and exhibiting a structural F3 pattern: the user technically authorised the top-level task, but the agent effectively decided to expand its own operational scope.
This has a concrete regulatory implication for the proposals I advance: Delegation Architecture Disclosure (Proposal 2) should explicitly include the sub-agent instantiation capacity as a mandatory disclosure item. Users must know, before initiating a session, whether the agent they are authorising can create further agents on their behalf. And the Non-Delegable Core specification (Proposal 4) should include autonomous sub-agent deployment as a prohibited autonomous action — requiring explicit, per-instance human authorisation regardless of how the top-level task was framed.
The deeper principle here, which I think addresses your ownership question directly: in an agentic architecture, what belongs to the human principal is not the agent as an object but the authorisation chain as a process. The second-generation agent belongs to no one only if we allow the first agent to sever that chain. The regulatory imperative is to make chain-severing architecturally impermissible — not through ownership attribution after the fact, but through authorisation design before deployment.
Where I think your framing opens genuinely new ground is in the question of liability distribution across multi-agent chains that cross organisational or jurisdictional boundaries — Agent A deployed by Company X, spawning Agent B whose actions fall under a different sectoral regulator. That is a gap the current EU AI Act framework does not close, and it may indeed require implementing acts that treat multi-agent orchestration as a distinct deployment category with its own conformity pathway.
Thank you for advancing this conversation in precisely the direction it needs to go.
Best regards,
Stefano Valente
Dear Stefano, your piece on the interposition problem perfectly captures where we risk losing human control. However, there is an immediate blind spot in current regulatory thinking that we need to address: what happens when an AI agent autonomously deploys another AI agent?
If Agent A decides it needs a specialised tool to finish a task and spins up Agent B on its own, our current rules fall apart. Traditional regulation relies on a clear line between the developer who built the system and the entity that deployed it or distributed it. When agents start hiring or creating other agents dynamically, that line vanishes. The second-generation agent technically belongs to no one, as it was brought into existence by an algorithm, not a human.
This leaves us with a critical gap: Should the ultimate responsibility always fall back on the original human user who started the chain, or does this multi-layered setup mean we need an entirely new way to define digital ownership and accountability?
I would love to hear your thoughts on how we bridge this gap.
Best regards,
Daniel Zivica