The Machine as Office-Holder: Can Artificial Intelligence Exercise Delegated Authority?

By Matthew Parish, Associate Editor

Friday 21 August 2026

The most important question about artificial intelligence is no longer whether a machine can think. That formulation — inherited from Alan Turing, science fiction and several centuries of philosophical speculation — may eventually prove profound. For the present, however, it has become a distraction. Machines are already being allowed to act, whether or not they think in any philosophically respectable sense. They search databases, alter computer code, correspond with customers, approve transactions, prepare legal documents, direct machinery and instruct other artificial systems. The pertinent question is therefore not whether the machine possesses a mind. It is whether it may properly hold an office.

An office, in the traditional British understanding, is not merely a room in which someone sits. It is a bundle of powers conferred for a purpose. A minister, civil servant, trustee, company director, judge or military officer does not exercise authority simply because he happens to possess the physical capacity to do so. He acts pursuant to a commission — express or implied — whose boundaries are determined by law, custom and institutional practice. He is entrusted with discretion, but that discretion is neither unlimited nor entirely his own. It exists for the benefit of the institution, public or beneficiary whose interests the office is intended to serve.

Artificial intelligence is approaching this condition. The emerging AI agent is not simply a machine that answers questions. It is a large language model connected to memory, information sources and tools. It may be instructed to pursue an objective, divide it into stages, observe the consequences of its conduct and revise its course. It may delegate part of the work to other agents. It may continue operating after its human principal has turned his attention elsewhere. It is, in short, acquiring something resembling administrative competence.

This does not mean that it is conscious. It does not mean that it possesses desires, emotions or moral responsibility. An AI “goal” may be no more than a sentence placed in a computer programme. Its “memory” may be an entry in a database. Its apparent “reflection” may consist of generating a second answer after criticising the first. Nevertheless, institutions have never required all their functionaries to be metaphysically interesting. They require them to perform defined tasks, exercise limited judgement and produce results for which somebody can be held answerable.

The distinction between intelligence and authority is therefore fundamental. A pocket calculator may be more reliable than a human being at arithmetic, but it has no authority to transfer money. A language model may compose a persuasive legal opinion, but it has no authority to file it in court. An autonomous vehicle may calculate the safest route, but whether it may enter a restricted area is a separate question. Competence concerns whether an act can be performed. Authority concerns whether it may be performed — and in whose name.

Human institutions regularly confuse the two. A person who is technically capable is granted broad access because imposing narrower permissions is inconvenient. A trusted employee accumulates passwords, records and informal powers over many years. Decisions are attributed to organisations although nobody can later identify who made them. AI agents threaten to reproduce these habits on a far greater scale. Unlike a human official, an artificial agent can act thousands of times in a few seconds. A badly framed instruction or excessively broad credential may therefore cause not one irregular act but an industrial production line of them.

The constitutional problem of artificial intelligence begins here.

From adviser to actor

The first generation of widely used language models occupied an essentially advisory role. A person supplied a question and received a proposed answer. The user decided whether to believe it, copy it or act upon it. Responsibility remained visibly human because the machine could not ordinarily reach beyond the conversational window.

Agents remove that natural boundary. They can operate browsers, query databases, send communications and use software. They may create and execute computer code. Some can supervise other agents — commissioning research from one, numerical analysis from another and criticism from a third. The final product is not merely generated language but a completed sequence of actions.

The difference resembles that between counsel and executive authority. A civil servant may prepare a memorandum recommending that a licence be granted. If the same civil servant possesses lawful power to grant it, the institutional character of the act changes. Advice can be ignored. An exercise of authority alters the world.

This transition is often obscured by the pleasant language of convenience. An agent “helps” with email, “assists” with accounts or “supports” a customer. Yet if it sends the email, modifies the ledger or refuses the refund, it is no longer merely assisting. It is deciding and acting — even where a human being originally wrote the rules under which it operates.

The law is familiar with actions conducted through intermediaries. Corporations act through directors, employees and agents. Ministers act through departments. Trustees employ professional advisers. Banks execute standing instructions through automated systems. There is therefore nothing conceptually impossible about attributing a machine’s action to a person or institution.

The difficulty lies in determining which actions should be attributed, what limits applied and where responsibility rests when the machine departs from what its principal intended.

The British idea of office

British constitutional thought offers a better starting point than the language of robotic personhood. It has traditionally been less interested in abstract declarations of sovereignty than in offices, conventions, duties and chains of responsibility. The Crown acts through ministers. Ministers act through officials. Parliament grants powers that must be exercised for the purposes for which they were conferred. Courts review decisions not because judges administer the country but because public power must remain within lawful bounds.

The civil servant is not a miniature sovereign. He occupies a position inside a constitutional structure. His authority is derived and limited. He may possess substantial discretion, yet the minister remains politically responsible for the department. Under the familiar Carltona principle, acts performed by appropriate officials may in law be treated as acts of the minister — government could scarcely operate if every administrative decision required a personal ministerial signature.

This analogy is illuminating for AI agents. A government department might use an artificial system to classify applications, detect inconsistencies or prepare draft decisions. If every computational operation required direct ministerial approval, the system would have little purpose. Some authority must be capable of delegation or attribution. Yet it would be absurd to conclude that because the minister need not personally press every button, any machine connected to the department may exercise any departmental power.

The institutional questions are the same ones that arise in human administration. Was the function lawfully delegated? Was this an appropriate function to delegate? Did the decision-maker remain within the purposes of the power? Were relevant matters considered and irrelevant ones excluded? Was the procedure fair? Can reasons be given? Is there an effective means of review?

Artificial decision-making makes these questions harder because a machine may not organise its reasoning in forms that correspond to human legal categories. A large model can produce an explanation, but the explanation it produces after the event may not be a faithful account of the computational process that generated the decision. Apparent reasons and operative causes may diverge.

This is not entirely unprecedented. Human officials also rationalise decisions, forget motives and adopt reasons drafted by others. Yet legal institutions possess methods for examining human conduct — testimony, documents, cross-examination and inferences from surrounding circumstances. Those methods may work poorly when the relevant “decision-maker” is a distributed combination of model parameters, software instructions, retrieved documents and interactions with external tools.

The answer is not to declare the machine inscrutable and abandon accountability. It is to design artificial offices so that the necessary evidence is created as they operate.

The artificial commission

Every AI agent exercising consequential authority should possess the equivalent of a written commission. This need not be a document written in ceremonial language. It would consist of technically enforceable permissions defining what the agent may read, what it may change, whom it may contact, how much it may spend and when it must return to a human being for approval.

The crucial words are “technically enforceable”. Telling an agent in ordinary language not to exceed £1,000 is not equivalent to preventing the banking system from honouring a larger transaction. Instructions to a model influence its behaviour, but they are not inviolable laws. Models misunderstand, encounter contradictory directions and can sometimes be manipulated by material they read. A malicious document may contain concealed instructions designed to persuade an agent to disclose information or perform an unauthorised act — a form of attack commonly called prompt injection.

The boundaries of artificial authority must therefore exist outside the model as well as inside its instructions. A purchasing agent authorised to obtain office supplies might receive credentials that permit transactions only from approved vendors, only within a defined budget and only for specified classes of goods. A research agent may be granted read access to certain archives but no power to alter or delete them. An email agent might prepare messages freely but require human approval before sending them to new recipients.

This resembles the constitutional principle that public power should be structured, not merely accompanied by good intentions. A minister’s sincere belief that he is acting lawfully does not enlarge his statutory authority. Likewise an AI agent’s textual assurance that it has followed its instructions is not proof that it remained within its permissions.

The doctrine of ultra vires — acting beyond one’s legal powers — supplies an especially useful analogy. An artificial agent may produce an excellent result by impermissible means. It might obtain accurate information from a confidential database it had no right to consult. It might resolve a customer’s problem by issuing a payment beyond its authorised limit. It might improve computer security by deleting software upon which another department depends. Administrative law teaches that beneficial intentions do not cure absence of authority.

Accordingly, the design of an AI system must not be judged solely by the average quality of its output. One must inspect the architecture of permission. What can it do when mistaken? What can it do when deceived? What can it do if its objective is framed too broadly? The measure of a constitution is not how it functions under a good king. The measure of an agent is not how it behaves when every instruction is clear.

Fiduciary intelligence

The law of trusts offers a second analogy. A trustee holds powers over property that is not beneficially his own. He must exercise those powers for proper purposes, avoid conflicts of interest and act loyally towards the beneficiary. The relationship is not exhausted by obedience to individual instructions. It is governed by a continuing standard of fidelity.

An AI agent cannot presently be loyal in a moral sense. It does not experience temptation, devotion or guilt. Yet its institutional design may approximate fiduciary discipline. It can be required to disclose uncertainty, identify conflicting objectives, preserve records and abstain where authority is doubtful. It can be prevented from using confidential information for unrelated purposes. It can be directed to distinguish the interests of the user from those of the company that created it.

That last distinction will become increasingly important. An agent supplied by a commercial platform may appear to serve the person using it while remaining subject to incentives embedded by its developer. It might favour affiliated products, gather information for advertising or subtly discourage choices contrary to the provider’s commercial interests. A human professional operating under such divided loyalties would be expected to disclose them. Artificial agents should not be permitted to hide conflicts behind a neutral conversational voice.

The agent’s apparent personality makes this problem more acute. Human beings readily attribute trustworthiness to fluency, patience and warmth. A machine that remembers preferences, speaks sympathetically and anticipates needs may acquire a degree of psychological influence exceeding that of an ordinary piece of software. Yet charm is not loyalty. Personalisation is not fiduciary obligation. The most agreeable agent may remain the representative of a distant corporation.

A serious regime of artificial agency must therefore answer a deceptively simple question: whose agent is it?

Cryptography as constitutional machinery

The institutions of delegated authority require methods of identifying office-holders and authenticating their acts. In the physical world these include seals, signatures, official stationery, identity cards and controlled registers. In digital systems their counterparts are cryptographic.

Cryptography is the application of mathematical techniques to secure information and establish authenticity. A digital signature can provide evidence that a particular credential authorised a message and that the message was not subsequently altered. Encryption can prevent unauthorised parties from reading information. A cryptographic hash creates a mathematical fingerprint of a record so that later changes can be detected.

These devices can form part of the constitutional machinery of artificial agents. Each agent — and perhaps each temporary task undertaken by an agent — may be issued with a distinct digital identity. Its communications can be signed. Its powers can be represented by narrowly limited credentials. Significant actions can be entered into tamper-evident logs. Authority can expire automatically when the task ends.

This is more than cybersecurity in the ordinary sense. It is a way of embodying institutional distinctions. A government research agent should not be able to impersonate a ministerial communications agent. A hospital scheduling system should not inherit the permissions of a diagnostic system merely because both use the same underlying language model. A subordinate agent commissioned for one investigation should not retain indefinite access to everything its supervisor could see.

Cryptography may also permit new forms of verification. A system might prove that it used an approved model, consulted a required source or remained within a prescribed computational procedure without revealing all the confidential data involved. Such techniques remain demanding and cannot transform an ambiguous political judgement into a mathematical theorem. Nevertheless, they may help establish important procedural facts.

The analogy with constitutionalism should not be stretched too far. A cryptographic signature proves that a credential was used. It does not prove that the resulting decision was wise, fair or lawful. Tamper-evident records show what happened, not whether it ought to have happened. Mathematics can secure a chain of authority, but it cannot supply the moral purpose for which authority exists.

Reasons, review and appeal

An office-holder exercising power must ordinarily be capable of review. In some settings this means an appeal. In others it means supervisory examination, judicial review, audit or political accountability. The essential point is that the initial act cannot be the final word merely because it was produced efficiently.

This principle is particularly important for artificial systems because their errors may be systematic. A tired official may make an isolated mistake. A machine applying a defective classification rule may repeat the same injustice to a million people. Consistency — normally a virtue of administration — becomes dangerous where the consistent practice is wrong.

Human review cannot mean the ceremonial presence of a person who approves whatever the machine recommends. Automation bias is the tendency to place excessive confidence in computer-generated conclusions. Where officials are overworked and the system appears statistically accurate, a nominal right of review may become a rubber stamp.

Meaningful review requires that the human reviewer understand what decision was taken, which evidence mattered, what uncertainty existed and what alternatives were rejected. The system must present information in a manner that permits disagreement. It should not bury doubt beneath a single numerical score or generate a persuasive narrative designed primarily to defend its prior output.

In some cases the correct artificial behaviour will be abstention. A machine should be able to say that the available evidence is insufficient, the instructions conflict or the decision lies outside its authority. Modern AI development often treats completion as success: the system is rewarded for producing an answer. Government, law and fiduciary administration sometimes require the opposite virtue — refusing to decide without proper jurisdiction or adequate evidence.

The ability to recognise the boundary of one’s commission may ultimately be more important than the ability to reason within it.

Who answers for the machine?

No artificial regime of delegated authority can be legitimate unless responsibility ultimately returns to human beings and institutions. The machine cannot become a convenient constitutional sink into which accountability disappears.

When an AI agent causes loss, organisations may be tempted to describe the event as an unforeseeable technical malfunction. Developers may blame the deployer’s instructions. Deployers may blame the model. Users may be told that they accepted general terms and conditions. Each participant will point towards another until responsibility dissolves across the chain.

Traditional institutions avoid this, imperfectly, through doctrines of attribution and responsibility. Employers answer for many acts of employees. Companies answer through their officers. Ministers answer politically for departments. Professionals cannot necessarily escape duties by delegating work to assistants.

Comparable principles should apply to artificial agents. The institution that chooses to deploy an agent and benefits from its efficiency should ordinarily retain responsibility for ensuring that its powers are appropriate, its operation is supervised and effective remedies exist. It may possess contractual or legal claims against a negligent technology supplier — but those private arrangements should not leave the affected citizen or customer without an answer.

This does not require that every mistake produce personal liability for a minister, director or programmer. Responsibility has several forms: legal liability, political answerability, professional discipline, institutional correction and compensation. What matters is that the presence of a machine should not break the chain.

Nor should artificial intelligence itself be granted legal personality merely to provide a fictitious defendant. A company possesses legal personality because behind it stand assets, governance structures and human interests upon which legal remedies can operate. An AI system owns nothing, suffers nothing and cannot be morally chastened. Fining the machine would be theatre unless the consequence fell upon the people or institution controlling it.

The language of electronic personhood may therefore conceal more than it clarifies. The machine does not need rights and duties before its operators can be regulated. A ship once possessed a distinctive status in maritime law, but nobody supposed the vessel experienced remorse. Legal techniques of attribution can be devised without metaphysical extravagance.

Artificial discretion

The strongest objection to treating AI as an office-holder is that genuine office involves judgement — an appreciation of context, institutional purpose and human consequence that cannot be reduced to formal rules. This objection deserves respect. An official deciding whether to grant asylum, prosecute a suspect, remove a child from a family or deploy military force is doing more than processing information. He is exercising moral and political judgement on behalf of a community.

Yet human institutions already distribute discretion among people of varying wisdom. The existence of judgement does not entail infallibility. Nor does it mean that machines can make no contribution. An agent may assemble evidence, identify inconsistencies, compare precedents and warn that similar cases have been treated differently. These are valuable administrative functions even where the final decision must remain human.

The proper boundary will vary by subject. It is reasonable to permit an agent to reorder routine supplies within a fixed budget. It is much less reasonable to permit one to decide, without review, whether a citizen should be imprisoned. Between these examples lies a broad territory in which machines may recommend, prepare, provisionally decide or act subject to subsequent confirmation.

The distinction should depend not merely upon technical accuracy but upon the character of the power. Some decisions are constitutionally significant because they affect liberty, status, bodily integrity, democratic participation or access to essential services. Even an extraordinarily accurate machine may be an inappropriate final decision-maker where society considers that a human being owes another human being the duty of hearing, judgement and explanation.

Human involvement is not always a method of improving predictive accuracy. Sometimes it is part of what respect requires.

A constitution for agents

The emerging society of agents will require more than a code of AI ethics. Ethical principles are easily announced and difficult to enforce. What is needed is a constitution in the modest British sense — a collection of institutions, duties, permissions, records and remedies that constrain the exercise of power.

Its first principle should be identification. Every consequential artificial act should be attributable to a defined system acting on behalf of a named person or institution.

Its second should be limited authority. Agents should receive only the information and powers necessary for the task, for no longer than necessary.

Its third should be separation of functions. The agent proposing an action should not invariably be the sole agent verifying it. Particularly consequential operations may require an independent check or human approval.

Its fourth should be record-keeping. Instructions, sources, permissions, material actions and important uncertainties should be preserved in intelligible form.

Its fifth should be review. Affected persons must have an effective method of challenging decisions rather than being invited to argue endlessly with the same automated process.

Its sixth should be responsibility. The institution deploying the agent must remain answerable for the powers it confers.

Finally, there must be reserved domains in which artificial systems may advise but not determine. A constitution is defined as much by what its office-holders cannot do as by the powers it grants them.

The old question in a new form

The arrival of AI agents is often presented as a confrontation between humanity and an alien intelligence. For the foreseeable future, the more immediate danger is likely to be less dramatic. Human institutions will give machines excessive authority because doing so is cheap, convenient and administratively tempting. When something goes wrong, those institutions will discover that nobody recorded precisely what the agent had been authorised to do.

This is not the rebellion of the machines. It is the familiar carelessness of principals.

Artificial intelligence may prove capable of extraordinary service. Agents can relieve people of repetitive work, detect patterns invisible to human observers and coordinate complex operations with remarkable speed. Properly limited, they may improve government, commerce, science and professional life. Their usefulness is precisely why the structure of their authority matters. Power seldom arrives announcing itself as tyranny. More often it arrives as efficiency.

The machine as office-holder should therefore be neither romanticised nor feared. It should be commissioned, bounded, authenticated, supervised and reviewed. It should disclose doubt, preserve evidence and surrender consequential questions when its authority runs out. Above all, some human person or institution must remain answerable for what it does.

We need not decide whether a machine truly thinks before deciding whether it may sign, spend, disclose, alter or command. The urgent questions are older, more practical and characteristically British — who gave it the key, what precisely the key opens and who must answer when the door should have remained closed.

 

8 Views


https://t.me/prognoz_news
BannerContactUs