Искусственный интеллект · 1 мая 2026 · 5 мин чтения

AI under cover

Initial recommendations for managing the risks of agent AI

Из выпуска мониторинга No. 5 (29), May 2026 · выпуск целиком, PDF · на сайте Института Гайдара

This year marks 70 years since the term "artificial intelligence" was adopted by the scientific community. Interestingly, the author of the term, John McCarthy, died in the same year, 2011, when Apple launched its Siri voice assistant.

In May 2026, countries published the first regulatory measures for agent AI systems. Why and what is it?

Assume that we ask an AI to perform a market analysis. Generative AI without any additional tools will take information from the data it was trained on, compose a text similar to "market analysis," release it, and then "forget" both the task and its answer. Agent AI is a subset of generative AI that can “break down” a request into subtasks, plan what data to take and where to get it from, self-check, and produce a more “meaningful” result. Such AI independently decides which steps to perform within a task, and which data and applications to use.

A question arises: who is responsible for the damage caused by agent AI?

For example, a company's AI agent erroneously orders a shipment of goods. Can the company refuse the order because it was placed without human intervention? Should human approval of orders be mandatory? This is how agent AI differs from traditional AI systems: a human may lose control over the actions and decisions of an agent AI due to its high degree of autonomy, while the agent AI may go beyond its instructions and thereby cause harm.

Thus, in China, the PRC Position of the Cyberspace Administration notes that it is necessary to legally delineate which decisions agent AI can make only with human participation, which ones without it, and which ones cannot be transferred to AI at all.

Similarly, in Singapore, Model Guidelines for Governance of Agent AI recommend that before launching an agent AI, companies should determine what data it has access to, whether it can only read or also modify data, what it can do only with human approval, i.e. provide the minimum necessary access. For example, every time AI is going to use sensitive data, send messages, make payments, etc. It is also recommended to allow it to use only certain APIs , grant access to programs or data only temporarily, and forbid it to transfer its access rights to other AI systems.

56%

1 a software interface that allows different applications to communicate and exchange data with each other

developers using AI agents in 2025, pointed to security risks and data leaks when using them

Another problem with agent AI is how to monitor their progress if they consist of several AI systems (a feature of AI agents is that one AI can delegate tasks to others), use different tools (e.g., email clients, instant messengers), delegate tasks to AI, etc. The chains of their actions are not always visible to the user: an agent AI can display a chain of its own actions, but what other agents or applications in the chain did is not visible. China proposes to develop the work of AI agents using blockchain to ensure that the actions of each agent are as transparent as possible.

Cyber security authorities in Australia, the US, Canada, New Zealand and Great Britain recommend in their Guidelines on agent AI introduction to developers of agent AI to Integrate special logs of interactions between agents into systems: if one agent delegates a task to another, the log should reflect who is the recipient, what actions were performed, what tools were used, etc.

Regulators in the respective countries also point to digital security risks, such as AI deleting data from other apps or overloading them with requests, etc. Thus, for instance: the incident concerning the Replit AI agent, which, during its operation, completely deleted the database of the developer who created the application using this agent. There are recommendations to test how agent AI behaves regarding the access to various external programs, creating AI agents that monitor the main AI to ensure it does no harm, and ensuring that the AI "keeps in mind” the goal, why it is doing this at every step of its work, etc.

In Russia, there are no initiatives yet to develop regulation of agent AI. However, for instance, the draft law on AI submitted by the Ministry of Digital Technology, Communication and Mass Media, could include provisions specifically addressing the risks of agent AI, establishing rules for developers to implement measures to monitor actions of agent AI, etc.

А что дальше

Why is agent AI more dangerous than a simple chatbot? It can use programs you don't control. If it gets an access, the agent AI could accidentally delete your email, leak payment What is information, and even run the risk of common AI “hallucinations”, distortion, and other risks. next? In 2025, companies used about 28.6 mn of AI agents; it is forecasted that by 2030 there will be more than 2.2 bn.

YESTERDAY
February 2026 OECD report on AI agents The OECD identifies factors that increase the risks of agent AI: delegation of tasks, reduction of human oversight and transparency, etc.:
TODAY
May 2026 Recommendations of the PRC, Singapore, Australia, Great Britain, etc. on agent AI Determination of agent AI risks: deleting, changing or transmitting data without permission, delegation of powers to other programs, going beyond the scope of assigned tasks and permitted actions
TOMORROW
Introduction of agent AI security measures: maintain logs of actions of programs assigned to perform tasks; restrict the transfer of access rights to third parties or other programs, etc.

From the monitoring issue No. 5 (29), May 2026. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также

Искусственный интеллект

Trust the system

1 марта 2026