Admissibility for AI Agents: A Record-Based Test

Admissibility for AI Agents: A Record-Based Test

Methods / Working Paper · Synthocracy Institute · 5 July 2026

When should an AI agent be allowed to act? Our answer: only when its identity, its autonomy level, its reach, its access class, its delegation authority, its human boundary, and its reversibility all exist as records — produced before the agent runs, not reconstructed after it acts. If any one of these cannot be produced, the agent has no standing to act. This paper sets out that test as a usable method.

This is a companion to our first working paper, Admissibility: The Decision That Comes Before Safety, which established admissibility for AI systems in general: a decision, taken before a system reaches real use, about whether it may cross the threshold into deployment — resolving to one of four documented, reversible outcomes (Admit, Admit-with-Limits, Hold, Refuse) on a single principle, no record, no standing. Here we extend that method to the case that now dominates deployment: not models that answer, but agents that act.

Working definition — admissibility for an AI agent. The pre-runtime, record-based decision about whether an agent may act, at what level of autonomy, through which reach, for and on behalf of whom, with what power to delegate, under which human boundary, and with what ability to reverse. It is distinct from whether the agent is capable (safety) and from whether it meets existing rules (compliance).

Why agents change the admissibility question

A model produces outputs. Between the output and any consequence in the world, a human has typically stood — reading, approving, or ignoring. Admissibility for a model could therefore focus on what the system might say and who could see it.

An agent removes that gap. It plans, calls tools, writes to databases, moves money, edits code, operates interfaces, and — increasingly — hands work off to other agents. As Singapore’s regulator puts it, agentic AI shifts the risk from wrong answers to wrong actions. The output is no longer the event; the action is. So the admissibility record can no longer stop at what the system can produce. It must cover what the agent can do, on whose authority it does it, and to whom it can pass that authority down a chain.

Two industry facts frame the urgency. Gartner projects that at least 80% of governments will deploy AI agents to automate routine decision-making by 2028. And on the technical side, surveys in 2026 found that only about a quarter of organisations have full visibility into how their agents communicate with one another — meaning most cannot answer the basic accountability question of which agent acted under whose authorisation. Adoption is outrunning the records that would make it accountable. Admissibility is the discipline that closes that gap before the agent runs, not after it fails.

The identity corollary: no identity, no admission

An output can be anonymous. An action cannot be accountable if the actor is unnamed.

This is why admissibility for agents begins one step earlier than for models, with identity. An agent must carry a verifiable identity before it is admitted to act — the disclosure Singapore’s IMDA framework calls an Agent Identity Card, specifying the agent’s declared capabilities, its limitations, its authorised action domains, and its escalation protocols. The gap this closes is the one the U.S. NIST agent-standards work names directly: today, agents are too often treated as generic service accounts, with no dedicated identity, authorisation, or accountability controls of their own.

Our addition to the identity requirement is structural. Identity is not a label; it is the anchor to which every later record attaches. Reach, access class, delegation, and boundary are all statements about a named agent operated by a named party. Without identity there is no record; without record there is no standing. No identity, no admission is the agentic form of no record, no standing.

The seven records

An agent is admissible to act only if the following seven records exist and are current before it runs. Each record captures one thing, rests on an external anchor, and prevents one characteristic failure.

1. Identity record — who is acting, and who is answerable. The agent’s verifiable identity, plus the split the IMDA framework draws between the operator (the party that builds the agent platform) and the deployer (the party that puts it to work in a specific context). Prevents: orphaned, unaccountable agents that no one owns.

2. Autonomy-level record — how much rope, on the record. The level at which the agent is admitted, on a graduated scale. IMDA’s five-tier taxonomy runs from Level 0, tool-assisted, to Level 4, fully autonomous, with governance requirements rising at each step. The discipline is that admission is pegged to a level: moving an agent up a level is a new admission event, not a settings change. Prevents: silent capability creep, where an agent quietly graduates from suggesting to acting.

3. Reach record (actuation surface) — what it can actually touch. Everything the agent can trigger or change: tools, APIs, sub-agent hand-offs, memory writes, payments, records, code, external systems. Each is sorted along three lines — reversible or irreversible, visible or hidden, advisory or operational. Prevents: the common error of mistaking the chat window for the system, while the agent acts through routes no one mapped.

4. Access-class record — for whom, and on whose behalf. The class of access under which the agent operates — public, enterprise, critical-infrastructure, government, trusted-partner, research-only, internal-only — and, distinctively for agents, the principal on whose behalf it acts. For each class: purpose, standing, liability, logging, monitoring, and a revocation rule fixed before access begins. Prevents: treating access as a product decision when, for a system that acts, it is a status decision.

5. Delegation record — what it may pass on, and to whom. What the agent is permitted to delegate, to which other agents, and under one load-bearing rule: authority must narrow at each hop of the chain, never widen (what the standards literature calls scope attenuation). The record must make the chain reconstructable — which agent acted under whose authorisation — the very property that today’s protocols cannot yet cryptographically prove at the third or fourth hop. Delegation, properly understood, is not just task hand-off; it is the transfer of authority, responsibility, and accountability together. Prevents: the “hop-three” problem, where an action happens and no one can establish who authorised it.

6. Boundary record — where a human with standing actually sits. The point at which a human can still refuse, and whether that point is real or ceremonial. We tier it by reversibility, following the “governed autonomy” model now emerging in the literature: reversible, low-risk actions may run automatically with sampled review; medium-risk actions use pooled, rotating approval; high-risk or irreversible actions require a named owner to sign. Two safeguards keep this from becoming theatre: override-rate auditing, which flags reviewers who approve everything, and the boundary tests we hold from our first paper —

A click is not oversight. A dashboard is not witness. An approval flow is not accountability. A human is at the boundary only if they have the knowledge, the time, the authority, the protection, and the technical ability to refuse before the act crosses.

The EU AI Act’s Article 14 mandates human oversight for high-risk systems, and it applies to autonomous agents — but the duty falls on the relying party and the Act does not specify how the boundary is built for an agent. The evidence for why this record matters is blunt: in one 2026 study, clinicians given a biased AI aid saw their diagnostic accuracy fall from 73% to 61.7% — they knew the answer and deferred anyway. And the Australian Robodebt and Dutch childcare-benefit scandals both had human oversight that satisfied compliance on paper and still produced mass harm. Prevents: ceremonial oversight, where the power to act has migrated into the agent while authority remains human only in name.

7. Reversibility-and-rollback record — what happens if it is wrong. For each class of action the agent can take: whether it can be undone, contained, or replayed; whether the action is idempotent and the trail reconstructable as a timeline; what condition triggers rollback; and what evidence is required for re-admission. Prevents: irreversible action taken on unproven standing — the failure that no later audit can repair.

The four outcomes, applied to an agent’s right to act

The same four terminal statuses from our first paper apply — now to the question of whether, and how, an agent may act:

OutcomeMeaning for an agent
AdmitActs under defined conditions, at the recorded autonomy level, within its recorded reach.
Admit-with-LimitsActs only through a narrowed route — e.g. capped at Level 1, irreversible actions gated by a named owner, no authority to spawn sub-agents.
HoldDoes not act yet, pending a missing record — e.g. its delegation chain is not yet reconstructable.
RefuseDoes not act under current conditions.

Three rules travel with the outcomes. No silence counts as permission. A configuration default is not an admission. And a level increase, a new tool grant, or a new class of sub-agent is a new admission event — not an operational tweak — because each changes what the agent can do to the world.

Where this meets the live rules

The record-based test is designed to sit inside the 2026 regulatory landscape, not beside it.

The EU AI Act brings Article 14 (human oversight) and Article 15 (accuracy, robustness, cybersecurity) to bear on high-risk agents. But the obligations for stand-alone high-risk systems were deferred by the Digital Omnibus to 2 December 2027 — which means the binding backstop for exactly the domains where agents are entering government and essential services (employment, justice, public administration) arrives later than the agents themselves. The gap between deployment and enforcement is precisely the space admissibility is meant to hold.

Singapore’s IMDA Model AI Governance Framework for Agentic AI, launched at Davos on 22 January 2026 and already updated to Version 1.5 in May, is the first governance template built specifically for agents: Agent Identity Cards, graduated autonomy, an operator–deployer split, and human-accountability checkpoints designed to resist rubber-stamping. Notably, the framework itself flags what it leaves open — dynamic agent identity, delegation chains, and liability in multi-agent systems. The seven-record test is aimed squarely at that open ground.

NIST’s AI Agent Standards Initiative (February 2026) frames the underlying deficiency the same way we do: agents are being run as generic service accounts, without identity, authorisation, or accountability of their own. Standards to fix that are in progress, not yet in production.

Read together, the message is consistent across jurisdictions: the frameworks agree that agents need identity, tiered autonomy, and meaningful human accountability — and they agree that the hardest part, the delegation chain, is still unsolved. A record-based admissibility test does not wait for the protocols to mature. It requires the records to exist before the agent acts, and treats their absence as a reason to Hold or Refuse.

Diagnostic: seven questions before an agent acts

A team can run this in minutes. If any answer is “no,” the outcome is Hold or Refuse, not Admit.

  1. Identity — Can we name this agent, its operator, and its deployer?
  2. Level — Is the autonomy level recorded, and is this run within it?
  3. Reach — Have we listed everything the agent can touch, marked reversible or not?
  4. Access — Is the access class and the principal it acts for on the record, with a revocation rule?
  5. Delegation — Can we reconstruct who authorised what, and does authority narrow at every hop?
  6. Boundary — Is a named human positioned where an irreversible act can still be refused?
  7. Reversibility — For each action class, do we know what can be undone, and what triggers rollback?

Seven “yes” answers is not proof the agent is safe. It is proof the agent has standing to act — that if it acts wrongly, the record exists to see it, stop it, and reverse it. That is the whole of admissibility, and it is the minimum a system that acts on the world should have to satisfy before it does.


FAQ

When should an AI agent be allowed to act? Only when seven records exist before it runs: its identity, its recorded autonomy level, its reach (everything it can touch), its access class and the principal it acts for, its delegation authority, its human boundary, and its reversibility. If any of these cannot be produced, the agent has no standing to act, and the correct outcome is to Hold or Refuse — not to Admit by default.

What is AI agent identity governance? It is the discipline of giving each agent a verifiable identity and tying every action back to it, so that “which agent did this, under whose authority?” always has an answer. Singapore’s IMDA framework operationalises this through Agent Identity Cards; NIST’s 2026 agent-standards work targets the same gap, noting that agents are currently treated as generic service accounts. Identity is the anchor on which all other admissibility records depend.

How is admissibility for agents different from admissibility for models? A model produces outputs, with a human usually standing between output and action; a model’s admissibility can focus on what it may say. An agent acts and delegates, closing that gap. So an agent’s admissibility must additionally record its autonomy level, its actuation surface, its delegation chain, and a boundary that is real rather than ceremonial — because the risk has moved from wrong answers to wrong actions.

Does the EU AI Act cover AI agents? Yes, in part. Article 14 (human oversight) and Article 15 (accuracy, robustness, cybersecurity) apply to autonomous agents used in high-risk domains. But the obligations for stand-alone high-risk systems were deferred to 2 December 2027, the duties fall on the relying party, and the Act does not specify agent identity or delegation-chain governance. A record-based test is designed to hold that space in the interim.

What is an Agent Identity Card? A standardised disclosure introduced by Singapore’s IMDA Model AI Governance Framework for Agentic AI (January 2026) that specifies an agent’s capabilities, limitations, authorised action domains, and escalation protocols. In the admissibility test it is the first of seven records — the identity anchor to which reach, access, delegation, and boundary all attach.


Sources

  • IMDA (Singapore), Model AI Governance Framework for Agentic AI, Version 1.0 (22 January 2026, WEF Davos); Version 1.5 (20 May 2026) — Ministry of Digital Development and Information; Baker McKenzie briefing.
  • NIST Center for AI Standards and Innovation, AI Agent Standards Initiative and NCCoE concept paper on Agent Identity and Authorization (February 2026).
  • EU AI Act (Regulation (EU) 2024/1689), Articles 14 and 15; Digital Omnibus on AI (high-risk deferral to 2 December 2027).
  • “Governed Autonomy: Human Accountability Above the Loop in Agentic AI” (2026) — risk-tiered oversight and override-rate auditing.
  • “Designing meaningful human oversight in AI,” AI and Ethics (2026) — operative vs evaluative agency.
  • “Meaningful Human Oversight of AI: Beyond Rubber-Stamping” (2026) — clinician study; Robodebt and Dutch childcare cases.
  • “Intelligent AI Delegation,” arXiv:2602.11865 (February 2026) — delegation as transfer of authority, responsibility, accountability.
  • Agent-to-agent visibility and scope-attenuation findings, arXiv:2604.23280 (2026).
  • Gartner, Governments and AI agents by 2028 (March 2026).

This working paper is part of the Synthocracy Institute’s governance research strand. It sets out a method, not legal advice, and does not endorse any single regulatory framework as sufficient on its own.



Synthocracy Institute — Power & Accountability When AI Co-Decides