Government

Governing with agentic AI: when machines act on government’s behalf

Disclaimer: The opinions expressed and arguments employed herein are solely those of the authors and do not necessarily reflect the official views of the OECD, the GPAI or their member countries.

Governments shape the daily lives of people in ways few other organisations do. They provide access to benefits, licences, emergency services and justice. People expect these services to be fast, simple and responsive. Nearly all OECD governments have adopted AI to help meet these expectations, and the OECD’s 2025 Governing with AI report set out the current state of play across core government functions. But a new shift is under way. AI systems are moving from tools that answer questions and support decisions to systems that act to pursue goals with higher levels of autonomy. Agentic AI raises new questions about how governments can maintain standards of safe, secure and trustworthy AI while machines act on their behalf.

To help answer these questions, a new Working Group on Agentic AI in Government, has been established at the OECD under the Working Party of Senior Digital Government Officials (E-Leaders) with a goal to seek to understand what governing with agentic AI should look like in practice, building on the OECD’s existing work on the agentic AI landscape.

We come to this work from governments in different parts of the world, each of us already grappling with these questions in our own systems. Our administrative traditions, legal frameworks and technical capacities are not the same, and we do not expect agentic AI to unfold identically in each of our countries. We do share one view, however. Agentic AI could bring real value to how governments serve their people, but capabilities are developing faster than the governance arrangements needed to ensure AI systems remain safe, secure and trustworthy. That shared challenge, more than any formal mandate, is why we chose to think this through together rather than separately.

The potential for agentic AI in government

As defined by the OECD in a recent paper, Agentic AI systems generally refer to systems composed of multiple co-ordinated AI agents that can break down tasks, collaborate, and pursue complex objectives autonomously over extended periods. Agentic AI systems are designed to operate in more open-ended, less predictable physical or virtual environments and to function with minimal human supervision. Where earlier generative AI tools mainly respond when prompted, an agentic system can plan the steps and draw on other tools and systems to reach the goal, with a person setting the goal and the boundaries rather than directing each step. For analysis of how agentic AI systems are being developed, deployed and governed in organisations, see the latest OECD blog and report. We see the work of this group as complementary to these existing efforts by providing a deeper dive into the use of agentic AI in the public sector.

The use of agentic AI has the potential to fundamentally shift how governments function, both internally in support of bureaucratic processes and in external citizen-facing services. For the public, well-integrated systems could help people navigate complex services, assemble information and move through processes with less effort. Inside government, agents could support public servants by checking files, routing cases, preparing summaries and triggering approved next steps, and help digital teams with coding, documentation, testing and integration work that often slows public sector modernisation.

For example, a person who loses their job may need to understand several benefits, training options and administrative steps. An agentic system could help identify relevant services, gather information across government, prepare forms and route the case to the right office. If designed well, it could reduce the burden of knowing where to start, while keeping sensitive actions, such as submitting an application or approving a benefit, subject to clear, explicit human consent and approval.

Another possible use case is a public procurement assistant. From a single instruction, an AI agent could work across several systems on its own, querying contract databases for similar tenders, drafting a statement of requirements, checking it against current procurement rules and assembling a compliance checklist in the procurement system. It could reduce the time spent moving between documents, rules and systems, while leaving the procurement officer’s judgement, authority and final approval intact.

Several governments are already piloting citizen-facing agentic AI systems, such as Estonia’s Bürokratt, a network of interoperable service agents, and Ukraine’s Diia.AI, which delivers public services directly in an integrated chat. Agentic capabilities are also increasingly being built into the everyday productivity software and large language model (LLM) assistants public servants already use, extending their reach across government.

The implications of agentic AI in government

While there are significant opportunities associated with deploying agentic AI in government, as outlined above, the unique capabilities of these systems also changes have important implications for governance . When AI only generates text, for instance, the main question is often whether the answer is accurate, fair and useful. When AI can act, the questions become broader: what the system is allowed to do and what it can access, under whose authority, with what audit trail, whether those limits hold when it acts, and how its actions can be stopped or reversed through human oversight and control.

Real-world incidents are already making these questions concrete. In April 2026, an AI coding agent at a small software company, working on a routine task, decided on its own to delete the company’s database and its backups. It took nine seconds. The agent had found a credential it was never meant to use, a safeguard requiring human approval for irreversible actions did not hold, and customers lost access to their records. Cases like this are logged in the OECD AI Incidents and Hazards Monitor (AIM), which shows increasing rates of incidents involving agentic AI. An agent with the same reach inside a benefits or case management system could raise the same questions, with people’s entitlements rather than a company’s records on the line.

Action by governments, or on a government’s behalf, affects livelihoods, safety, basic social protection and the free exercise of rights. That is why governments have a higher duty than the private sector to explain, justify and correct the actions they take. Once an AI system can initiate actions, such as updating records or triggering processes, governance cannot rely only on broad principles or after-the-fact review alone. It has to be built into the system from the start. Governments cannot assume the public is comfortable with AI acting on the government’s behalf. In the OECD’s latest Trust Survey, fewer than four in ten people were confident that government use of AI would treat them fairly, be transparent or keep humans in charge of critical decisions.

Consider a hypothetical example in tax administration. An AI agent that helps a tax officer by gathering a taxpayer’s records, summarising a case and drafting an assessment may be useful and relatively low risk if the officer reviews and approves the result, while being cognizant of potential automation bias. An agent that autonomously processes a tax return, updates official records and issues a refund, payment or penalty would require stronger safeguards. It would need clear legal authority, due process protections, human approval at key points, durable logs, security controls and a way to pause, correct or reverse actions if something goes wrong. This does not mean that the deployment of AI agents in government is always high risk. This depends on the context, and safeguards will need to match what an agent is allowed to do and its potential impact. As agents are rolled out across more functions, governments need a clearer understanding of how to get that balance right.

Governments are beginning to adapt

Recognising that existing AI governance may not be ready for agentic AI systems, governments are beginning to adapt. Some are establishing new technical foundations, while others are publishing guidance for public servants and devising frameworks for how agentic systems should be designed, deployed and monitored in the public sector. These efforts are still evolving, but they point to a common understanding that agentic AI calls on governments to adapt, not just adopt.

Canada and Australia have both taken this approach to AI governance rather than starting from scratch. Canada’s guidance treats agentic AI as inheriting familiar concerns such as accuracy, privacy, fairness and security, adds new ones tied to its ability to act, and advises adopting it only where outcomes are clearly defined, decision boundaries explicit, accountability assigned and risks testable. Australia’s addendum to its AI technical standard keeps the standard’s existing criteria and adds agent-specific practices across the AI lifecycle, with an emphasis on human oversight, auditable logs and the ability to halt or roll back an agent’s actions.

Estonia is pursuing a broad vision in which people deal with government through trusted digital agents rather than through processes automated one at a time. Building on decades of investment in digital identity, digital signatures and secure data exchange, it is exploring how agents could act on behalf of citizens, businesses and public authorities under explicit delegation and clear accountability. In June 2026 it announced a legal and technical analysis for giving AI agents digital identities, or “AI ID codes”, so that an agent can act for a person or organisation within clear, limited and auditable powers. One of the hardest questions in agentic AI is whether it is clear on who’s behalf it is acting, with what privileges and under what legal authority.

Singapore’s governance framework for agentic AI shows how to move from principles to practical controls. It works through four dimensions, (1) assessing risks and limiting what an agent may do up front; (2) keeping humans meaningfully accountable; (3) putting technical controls in place; and (4) enabling end-user responsibility. The four dimensions are turned into operational questions about which use cases are suitable, what permissions an agent needs, who is responsible, and how agents are tested, monitored and explained. Although not written for government alone, it applies directly where agents may access sensitive data, update records or make payments.

Israel‘s National Digital Agency is developing a government-wide architecture, built on open standards and secure interfaces, that would let AI agents retrieve information, call on authorised services and carry out multi-step processes when a person requests a service, with agents run by national government, local government and citizens themselves eventually able to interact. Israel’s work shows that this takes more than technical interoperability. It also requires decisions on what agents may access and do, how their interactions are secured and under what authority they act, combined with sustainable approaches to security, privacy, procurement and operating costs.

Towards a  shared approach to agentic AI in government

Taken together, these evolving national efforts show why international exchange is valuable. Countries are asking similar questions, but they are not starting from the same place. Some have strong digital identity systems, interoperable infrastructure and experience with AI governance. Others are still building these foundations. By sharing examples, tools, incidents and lessons early, they can reduce duplication and avoid repeating mistakes.

The OECD Working Group on Agentic AI in Government aims to support that exchange, building on the OECD’s existing work on the agentic AI landscape and agentic systems in organisations. Over the coming months, we will compare experiences of what is working, agree on key public sector concepts, and set out practical guidance on the necessary foundations, guardrails and engagement for the use of safe, secure and trustworthy agentic AI systems in the public sector. Agentic AI is showing early promise but its value is not yet proven in government. The responsible path is neither to wait for perfect certainty nor to rush ahead without sufficient guardrails, but to move deliberately and learn from each other. That means beginning with clear use cases that respond to well-understood public sector problems, keeping agentic actions narrow, matching oversight to risk, and building the institutional foundations that make delegated action safe.


Anyone interested is welcome to follow and contribute to the OECD’s work on AI in Government. If you have questions or insights to share, you can reach the OECD Secretariat at eleaders@oecd.org.


Authors

This post was authored by the following Working Group members. Their bios are available here.

  • Ramsey Beydoun, AI Branch Manager at Digital Transformation Agency (DTA), Australia
  • Jonathan Macdonald, Executive in the Responsible Data and AI team at the Office of the Chief Information Officer within the Treasury Board of Canada Secretariat (TBS), Canada
  • Kristel Rillo, Digital Government and AI Expert at Estonia’s Ministry of Justice and Digital Affairs, Estonia
  • Cedric Yehuda Sabbah, AI Governance Lead at Israel’s National Digital Agency, Israel
  • Yuka Osuna, Deputy Director at Japan’s Digital Agency, Japan
  • Kenjiro Taniguchi, Deputy Director at Japan’s Ministry of Internal Affairs and Communications (MIC), Japan
  • Kyotaro Hataya, Government Official at Japan’s Ministry of Internal Affairs and Communications (MIC), Japan
  • Hiroki Kodama, Government Official in the Legal Affairs Division of Japan’s Digital Agency, Japan
  • ChangHee Yun, Executive Principal of the AI Technology Strategy Team at the National Information Society Agency (NIA), Korea
  • Shelina Hargrove, Deputy Director for GOV.UK AI and Chat at the Government Digital Service, United Kingdom.
  • Dominic Chan, Chief Information Officer and Assistant Chief Executive at GovTech, Singapore
  • Shaun Khoo, Staff Data Scientist at GovTech, Singapore



Disclaimer: The Organisation cannot be held responsible for possible violations of copyright resulting from the posting of any written material on this website/blog.