Who Authorised the Agent? The Decision-Authority Clause in the WAIC Statement

Who Authorised the Agent? The Decision-Authority Clause in the WAIC Statement

METHODS · WORKING PAPER – Agentic governance. Anchored to the official WAIC Chair’s Statement of 17 July 2026. This paper proposes an operational record; it does not claim that the statement is binding law.

Most global statements on artificial intelligence speak in principles: beneficial, safe, inclusive, human-centred, trustworthy.

The Chair’s Statement of the 2026 World Artificial Intelligence Conference contains one sentence that is unusually operational.

Its ninth point says that AI agents, as a new form of AI product and service, must operate with clearly defined decision-making authority and behavioural boundaries, supported by mechanisms for behaviour tracing and risk alert.

That sentence identifies the exact gap between an agent log and an accountable decision.

Four requirements, not one

The clause contains four distinct requirements.

Defined decision-making authority

The agent must not merely possess a technical permission. Its authority to affect a decision must be defined.

An API key, service account, tool token, or role-based permission can show that software was able to act. It does not show why the action was legitimate, who authorised it, for which purpose, or within which limits.

Authority requires a source: law, regulation, organisational mandate, contract, role assignment, consent, or another recognised basis. It also requires a holder and, where the agent acts by delegation, a traceable chain from that holder to the agent.

Behavioural boundaries

Authority is never simply “the agent may act.” It has scope.

The boundary may limit tools, data, subjects, transaction value, duration, autonomy level, jurisdiction, risk class, or ability to delegate. It should also identify excluded actions and conditions that require pause, escalation, or human approval.

A boundary that exists only in a policy document but is not enforced in the tool and credential layer is aspirational. A technical boundary with no authority basis is permission without legitimacy. Accountable agency requires both.

Behaviour tracing

Tracing records what happened: which model produced an output, which agent called a tool, which record changed, which credential was used, and when.

This evidence is essential. It remains incomplete if it cannot reconstruct who acted on whose behalf.

The Institute’s working paper Who Acted, Under Whose Authority? describes this as the difference between event provenance and authority provenance. A system log may preserve the first while losing the second.

Risk alert

An alert mechanism needs defined triggers, recipients, and consequences.

Which deviation creates an alert? Who receives it? Does the agent stop, narrow its actions, request approval, or continue while logging the event? Who can clear the alert, and what evidence is required before the agent resumes?

An alert without a response authority is notification, not control.

The missing object: a decision-level authority record

The four requirements can be distributed across different systems:

policy and legal repositories hold the authority basis;

identity systems hold credentials;

agent platforms hold tool permissions and autonomy settings;

observability systems hold traces;

risk systems hold alerts;

case-management systems hold the outcome and appeal.

If those records are never linked at the level of a consequential decision, no reviewer can reconstruct the whole episode.

The Decision Authority Record, or DAR, is designed as that linking layer. It does not replace logs, model cards, impact assessments, provenance graphs, or legal files. It references them while recording the authority questions they do not answer alone.

For a specific decision or action, a minimum record should identify:

the decision and its consequence;

the accountable organisation;

the authority basis;

every material human, model, system, and agent;

the delegation chain;

permitted and excluded actions;

the evidence used and excluded;

material decision-shaping steps;

the human-control point;

the executed effect and reversibility;

notice, explanation, challenge, and remedy;

logs, hashes, retention, corrections, and unresolved uncertainty.

A model-access profile

The WAIC statement appears in a global-governance document, not only an enterprise-agent context. The record should therefore cover decisions that determine access to AI capability itself.

A DAR-Model Access profile would apply when an actor grants, limits, suspends, withdraws, exports, or releases:

a model API;

model weights;

fine-tuning access;

cloud or compute capacity;

advanced chips or related equipment;

a dataset or evaluation environment;

trusted-partner or research-only status.

For each event, the record would add:

FieldRequired question
ObjectWhich model, version, weights, endpoint, compute or hardware?
ActionGrant, limit, hold, refuse, release, suspend, or withdraw?
RecipientWhich person, organisation, sector, country, or access class?
CriteriaSecurity, capability, reliability, origin, sanctions, licence, public interest?
ExecutionAccount control, repository release, export licence, cloud policy, procurement gate?
DurationEffective date, expiry, review and sunset?
RemedyExplanation, correction, exception, appeal, re-decision or re-admission?

This profile would let two apparently opposite events be compared through the same method:

the Fable-Mythos episode, in which access was restricted and restored;

the Kimi K3 event, in which hosted access was followed by an announced transfer of model possession through weight release.

Restriction and diffusion are both authority decisions.

Human control cannot remain a slogan

Xi’s WAIC speech called for AI to remain under human control. The Chair’s Statement made the requirement more concrete for agents. But “human control” is still incomplete unless the human can inspect, challenge, and stop the agent in practice.

The Institute’s Assisting or Deciding? test asks whether a human could reconstruct and comprehend the basis, realistically depart from the system’s result, and record genuine engagement.

For an agent, add four questions:

Did the human possess authority over the relevant action, not merely responsibility after it?

Was the intervention point before an irreversible effect?

Could the human technically revoke or narrow the agent’s credentials?

Was exercising refusal institutionally protected and operationally feasible?

Without these conditions, a named human may be present while effective control sits elsewhere.

From shared language to interoperability

The significance of the WAIC clause is not that it validates one Institute instrument. It is that different governance systems are converging on the same operational objects:

agent identity;

defined authority;

bounded delegation;

tracing;

alerts and stop conditions;

meaningful human accountability.

This creates room for interoperability even where political values and legal regimes diverge.

A DAR can map actors, activities, and evidence to W3C provenance structures; link technical traces to observability systems; and reference jurisdiction-specific law rather than impose one legal theory. The common layer is not agreement about every legitimate use of AI. It is agreement that consequential action must carry a reconstructable authority chain.

The test

Before an AI agent is allowed to shape or execute a consequential decision, ask:

Can we identify the source of its authority?

Can we reconstruct every delegation hop?

Are its allowed and excluded actions explicit?

Are those limits technically enforced?

Can we trace material behaviour to a named identity?

Do alerts trigger a defined response?

Can an accountable human stop the action before an irreversible effect?

Can an affected party obtain an explanation and remedy?

If any answer is no, the system may be capable and observable. It does not yet have accountable standing to act.

Sources

Chair’s Statement of the 2026 WAIC and High-Level Meeting on Global AI Governance, points 7-9, 17 July 2026.

Xi Jinping, Joining Hands to Build a Just and Equitable System for Global AI Governance, 17 July 2026.

The White House, National Security Presidential Memorandum/NSPM-11, 5 June 2026.

Synthocracy Institute, Admissibility for AI Agents: A Record-Based Test.

Synthocracy Institute, Who Acted, Under Whose Authority?.

This is Article 6 of Open-Weight Power: Models, Access, and the Emerging AI Order.


Synthocracy Institute — Power & Accountability When AI Co-Decides