
By BarathVector Editorial — 2026-08-14
The next government computer may not wait for an officer to click a button.
An AI agent can read a request, retrieve records, plan several steps, call other software and complete a task. In public administration, that could mean tracking a delayed pension, checking a licence application, translating a notice or assembling a case file. It could also mean freezing a benefit, flagging a taxpayer, refusing a service or sending a citizen into an automated maze.
The difference is not technical. It is constitutional. A tool that recommends an action remains subordinate to the official who decides. A system that acts becomes part of the state's chain of authority. If that chain ends in a model name, nobody is accountable.
India should adopt one rule before agentic government spreads: every consequential government agent must have a named human superior.
Agents cross a line that chatbots do not
A chatbot produces words for a person to consider. An agent is designed to pursue an objective through a sequence of actions. The OECD's 2026 Digital Government Outlook describes the change plainly: agents can plan, decide and act within an assigned action space. It recommends clear authority limits, approval gates, audit trails and ways to pause, reverse and challenge outcomes.
Those safeguards are not administrative decoration. Government decisions carry coercive power. A private recommendation may waste a consumer's time. A public decision can withhold food support, alter a tax liability or place a person under investigation.
The state cannot answer an appeal by saying that the software reached its own conclusion. Nor can an officer sign thousands of machine-generated decisions without meaningful review and call that human oversight. A rubber stamp does not become accountability because it is made of flesh.
India's opportunity is real
India has good reasons to use agents. Public offices manage enormous volumes, many languages and large backlogs. A well-designed agent could gather documents once rather than make a citizen visit three counters. It could tell an officer which rule applies, expose inconsistent treatment and keep a service available outside office hours.
At the India AI Impact Summit, government statements presented agentic systems as a route to more responsive public services. The India AI Governance Guidelines likewise emphasise responsibility, safety and trust alongside adoption. That direction is sensible. The danger begins when speed becomes a reason to obscure who exercised power.
International experience should make India cautious. The OECD found that 35 of 36 countries surveyed used AI in government, but only 11 had binding standards and only six had open algorithm registers. Adoption is outrunning the institutions meant to govern it.
India does not need to repeat that sequence.
The principal must be visible
Every deployed agent should have a short public record naming the department, the responsible officer, the purpose, the data it can reach and the actions it may take. The record should state which actions require prior approval, how a citizen can appeal and how the system is suspended.
The agent itself needs an identity distinct from a human employee. The US National Institute of Standards and Technology has begun examining identity and authority for software agents. The issue is basic: a system must authenticate itself, receive only the permissions it needs and leave evidence of what it did. A shared superuser credential turns one faulty instruction into an institutional breach.
India should require least-privilege access, signed action logs and an expiry date for every permission. Sensitive changes should need a second factor that belongs to a responsible official, not to the agent. Logs should record the evidence available at the moment of action, the model and version used, the rule invoked and any human approval.
That record must be intelligible to an auditor and useful to the citizen affected. A million tokens of internal reasoning are not an explanation of why a widow's pension stopped.
The strongest countercase
Requiring a human superior can become theatre. Officers may approve everything to avoid delay, while agencies produce registers that nobody reads. Excessive approvals can also erase the efficiency that justified the system. If every routine translation or reminder needs a senior signature, government has built an expensive typewriter.
The answer is proportional authority. Low-risk, reversible acts can be automatic: routing a file, translating an already approved notice, sending a reminder or identifying a missing field. High-impact actions should require a human decision: rejecting eligibility, imposing a penalty, changing a legal record, disclosing sensitive data or initiating enforcement.
Between them lies a monitored zone where the agent may act but the decision is rapidly reviewable and automatically sampled for error. The more difficult an action is to reverse, the higher the approval threshold should be.
Rights must travel with the decision
A citizen should be told when an automated system materially shaped an outcome. The notice should identify the responsible office and provide a route to a human review. Appeals must pause irreversible enforcement where delay would not create a serious public risk.
Departments should publish error rates by language, region and relevant demographic group. They should commission red-team tests for prompt injection, data leakage and unauthorised tool use. Procurement contracts must preserve the government's ability to inspect logs, change providers and disclose enough information for judicial review. Commercial secrecy cannot swallow due process.
None of this requires exposing security-sensitive code or inviting manipulation. The United Kingdom's Algorithmic Transparency Recording Standard shows that public bodies can describe purpose, scope, data and oversight without publishing an attack manual.
A test India should insist upon
Before launch, every department should answer one question in a public document: if this agent causes a serious wrongful action tomorrow, who can stop it, who must explain it and who bears professional responsibility?
If the answer is a vendor, a committee or “the system,” deployment is premature.
Agentic government can reduce queues and make the state more attentive. It can also distribute power through software until responsibility disappears. India should choose the first path by keeping the hierarchy unambiguous: an agent may serve the government, but it may not become the government. There must always be a human superior whose name the citizen can find.