Who Acted, Under Whose Authority? Traceability When Public Decisions Are Delegated Between Agents
METHODS · WORKING PAPER — Governance. The first paper of the Agentic Government programme. Empirical and analytical; anchored to dated, citable law as of July 2026. Where it points forward, it links to the Futures strand rather than forecasting.
When a public agency decides something about a person through a chain of AI agents — one agent triaging the case, another gathering and summarising the record, a third drafting the determination, a fourth executing it — the ordinary system log will faithfully record that these events happened. It will not record the one thing the citizen’s rights depend on: who acted under whose authority. The event chain survives; the authority chain does not. And when the authority chain is lost, the citizen’s ability to trace the decision, and therefore to contest it, is lost with it — not because the decision was hidden, but because it was distributed across actors no one thought to make accountable individually.
This paper sets out why delegation between agents breaks the accountability that public decisions are legally required to carry, why an ordinary log does not fix it, and what an accountable agentic administration would have to preserve instead. It proposes a minimum standard — a delegation record — that keeps a decision traceable from the citizen-facing outcome back to the human who authorised it.
Why is a delegated decision different from an automated one?
A single automated decision, however complex, still has a locus: one system produced an output, and a human deployed or ratified it. The citizen’s legal rights are built on that assumption. The administrative-law duty to give reasons assumes there is a decision whose basis can be stated. The right to an effective remedy assumes there is a decision that can be pointed at and challenged. Data-protection law on automated decisions — the right to obtain human intervention, to express a view, and to contest — assumes a human who can meaningfully intervene in a decision they can reconstruct.
Agentic delegation dissolves that locus. An agent does not merely compute; it plans across steps, calls tools, reads and writes shared memory, and hands sub-tasks to other agents. The determination that reaches the citizen is the product of a chain, and each hand-off is a place where authority is passed but rarely recorded as authority. Ask, after an adverse outcome, “who decided this, and under what authority were they permitted to?” and the honest answer in most agentic deployments is a shrug: a system did it. In a private setting that is a governance failure. In government it is a failure of a different order, because the citizen has rights that presuppose the very traceability the delegation destroyed.
Why doesn’t the log solve this?
Because a log preserves events, and accountability needs authority provenance. A log tells you that Agent B ran at 14:03 and produced output X. It does not tell you that Agent B was authorised to make this class of determination, that it received its task from Agent A under a specific delegated scope, that the scope traced back to a human official’s decision to deploy the chain for this purpose, and that a named person remains accountable for the result. Those are not events; they are relationships — and an ordinary log is not built to hold them.
The gap widens exactly where the stakes rise. As autonomy increases, agents delegate more, and the distance between the final output and the authorising human grows. The output reveals almost nothing about the path that produced it, and the log records the path as a sequence of actions without the authority that made each action legitimate. So the more capable the agentic administration becomes, the less its records can answer the citizen’s basic question — unless the authority chain is captured deliberately, as its own object, alongside the event chain.
What a citizen must be able to trace
To contest a decision, a person does not need the full internal state of every agent. They need to be able to reconstruct a specific, bounded chain of authority. Concretely, an accountable delegated decision should let an outside reviewer establish:
- Which agents acted in the chain that produced this determination — each identifiable, not anonymous.
- What each was authorised to do — the bounded scope of its task, and the limits on it.
- Who delegated to whom — the hand-offs, so the chain can be walked from the output backward.
- Where the authority originated — the point at which a human official decided to deploy this chain for this purpose, so the chain terminates in a person, not in “the system.”
- Who remains accountable — a named human or office answerable for the outcome, regardless of how many agents sat between them and it.
- Where a human could still have refused — the boundary at which the decision could have been stopped before it became consequential, and whether that boundary was real.
These six are the delegation record. They are the record-based admissibility test applied to the specific problem of delegation: not “is the agent safe?” but “can this decision be walked back to an authorising, accountable human, through identifiable actors acting within stated authority?” Where the six can be reconstructed, the citizen’s duty-to-give-reasons and right-to-contest survive the shift to agents. Where they cannot, those rights become formal — present on paper, unusable in fact.
The failure the log hides: the human who signed but did not decide
There is a specific trap for public administration here, and it is worth naming because it will pass most audits. An agency, aware that a person has the right not to be subject to a solely automated decision, places a human signature at the end of the chain. The audit sees a human decision-maker; the record shows a human approval. But if that human received only the final determination, produced by agents whose chain they cannot reconstruct, they did not decide — they ratified. The signature satisfies the letter of the rule and defeats its purpose. This is the ceremonial-human problem arriving in the one place it is most dangerous: a decision that is legally treated as human, and practically made by an untraceable chain of agents. The delegation record is what distinguishes a human who decided from a human who signed: it establishes whether the person at the boundary could actually reconstruct, and therefore actually refuse, what the agents had done.
What live regulation already assumes — and does not yet reach
Existing law points in the right direction and stops short of the delegated case.
The EU AI Act treats AI used in essential public services and the administration of justice as high-risk, and its Article 14 requires meaningful human oversight of such systems — oversight that presupposes a human who can understand and, if needed, override the decision. But Article 14 was written for a system with an overseeable output, not for a chain of agents whose authority provenance is unrecorded; an official cannot meaningfully oversee what the record cannot reconstruct. And under the Digital Omnibus, the high-risk obligations for these Annex III public-sector systems were deferred to December 2027 — so even the oversight requirement that most nearly addresses this problem does not yet bind. Data-protection law grants the right to human intervention and to contest an automated decision, but “intervention” is empty if the intervening human cannot see the chain, and “contest” is empty if the citizen cannot trace it.
The clearest movement is in agent-identity work. Singapore’s agentic-AI framework recommends that each agent carry a traceable identity linked to a human accountable party, with an audit trail of which agent acted under whose authorisation — which is precisely the authority provenance this paper argues for. But it is non-binding guidance, and the baseline it is trying to escape is stark: standards bodies note that agents are still routinely deployed as generic service accounts, with no dedicated identity, no bounded authority, and no accountability control. A public agency that deploys agents as generic service accounts has, by construction, no delegation record — and no way to answer the citizen.
The honest tension
A delegation record is not free, and maximal provenance is not the goal. Capturing the full authority chain across every hand-off carries real cost, can collide with the data-minimisation duties public bodies also owe, and can harden into a bureaucracy that documents everything and clarifies nothing. The standard is therefore not “log the internal state of every agent.” It is narrower and harder: what is the minimum authority provenance that lets a specific decision be walked back to an accountable human, well enough for the citizen to contest it? Nor does this argue against agents in government. Agents can make administration faster and more responsive, and refusing them wholesale would preserve slow and unequal systems, not accountability. The claim is only this: delegation must not be allowed to dissolve accountability. An agentic administration is admissible when its delegated decisions remain traceable to a person; it is not when “a system did it” is a true and complete account of a decision about a citizen.
What this paper does not settle
Three questions remain open and belong to the programme’s next work. First, the standard for how far back the chain must be reconstructable, and in what form it must be disclosed to a citizen versus held for a reviewer, is undefined — and is exactly the kind of thing that should not be left entirely to each agency’s discretion. Second, the boundary between an agent that assists an official and one that has effectively replaced the official’s judgment needs a workable test, because the ceremonial-human failure lives on that line. Third, whether a delegation record can be built that survives across agent versions and vendor systems — so that a decision remains traceable after the agents that made it have been replaced — is an open technical and legal problem. The gap this paper names is clear; the standard that closes it is work still to do.
FAQ
What is the difference between a log and a delegation record?
A log preserves events — which agent ran, and when. A delegation record preserves authority provenance — which agent was authorised to do what, who delegated to whom, and where the authority traces back to an accountable human. Accountability needs the second; a log gives only the first.
Why does this matter more in government than in a company?
Because a citizen has legal rights that presuppose a traceable, reasoned decision: the duty to give reasons, the right to an effective remedy, and the right to contest an automated decision. Delegation across agents breaks the assumption those rights rest on — that there is an identifiable decision-maker and a reconstructable basis.
Doesn’t a human signature at the end solve it?
No. If the signing human received only the final output and cannot reconstruct what the agents did, they ratified rather than decided. The signature can satisfy the letter of the rule while defeating its purpose. A delegation record is what distinguishes deciding from signing.
Does this mean government shouldn’t use AI agents?
No. It means delegation must not dissolve accountability. An agentic administration is admissible when its delegated decisions can still be walked back to an accountable human; the problem is not that agents act, but that “a system did it” becomes a complete account of a decision about a person.
