When the System Stops Advising and Starts Acting

Agentic AI in public administration crosses a line that recommendation systems never did, and government is the place where that line matters most
For several years, the debate about artificial intelligence in government has concerned systems that produce information. A model summarises a case file, flags an application for review, predicts which claims are likely to be fraudulent, or drafts a response. In every instance, something is generated and a human being decides what to do about it.
A different category is now arriving. Agentic systems do not merely produce an output. They take actions: opening and closing cases, sending correspondence, updating records, triggering downstream processes, and in some designs deciding when to escalate and when to resolve. The output is not a recommendation. It is a completed act.
This distinction sounds technical. It is not. It is the difference between a system that informs a decision and a system that is the decision, and government is the setting where that difference carries the most weight.
Why Government Is Different
A private company deploying agentic AI risks its own money and reputation. A citizen dissatisfied with a company can, in principle, take their business elsewhere.
Government has no equivalent. A person cannot choose a different tax authority, a different immigration service, a different benefits agency, or a different licensing body. When the state acts, the citizen has no exit, only whatever process of appeal the state itself provides.
Public administration also carries a specific obligation that commerce does not: the duty to give reasons. Administrative law traditions across jurisdictions hold that a person adversely affected by a state decision is entitled to know why. This is not a courtesy. It is what makes the decision reviewable, and what distinguishes administration from arbitrary power.
An agentic system that acts without producing a reason a person can examine has not merely automated a task. It has removed the conditions on which the act was legitimate.
The Real Case in Favour
It would be dishonest to present this only as risk, because the case for automation in public administration is genuinely strong, and it is strongest precisely where citizens suffer most.
Anyone who has dealt with a large bureaucracy knows the experience: months of waiting for a determination that requires ten minutes of actual work, files lost between departments, the same documents supplied four times, decisions delayed until the delay itself becomes the harm. People lose housing, medical treatment, and legal status while waiting for administrative processes that no one is deliberately obstructing.
Automation can genuinely fix parts of this. A system that completes routine steps immediately, that does not go on holiday, that processes the fiftieth application with the same care as the first, addresses a real injustice. And the people who benefit most from faster administration are usually those with the least capacity to absorb delay.
There is also a fairness argument. Human administrators are inconsistent. Studies of discretionary decision-making have repeatedly found variation by time of day, caseload, and the individual assessor. A well-designed system applies the same rule to everyone.
Refusing automation is therefore not a neutral choice. It preserves a status quo that already fails people, and it fails them invisibly because nobody is accountable for the accumulated cost of slowness.
The Line Worth Holding
The question is not whether to automate but what may be automated, and the useful distinction is not between simple and complex tasks. It is between acts that are essentially administrative and acts that determine a person’s standing.
Reasonably automated: retrieving records, checking whether a form is complete, confirming an eligibility threshold that is purely arithmetical, scheduling, routing a case to the correct department, issuing acknowledgements, and completing steps that follow necessarily from a decision already made by a person.
Requiring human judgement: any determination involving discretion, assessment of credibility, weighing of competing considerations, or the exercise of mercy. Any decision that removes a benefit, denies a status, imposes a penalty, or initiates enforcement against a person.
The principle underneath is not that machines are unreliable. It is that some decisions are constitutive of a relationship between a citizen and a state, and that relationship requires an accountable person on the state’s side of it.
There is a further test worth applying: can this action be reversed? A system that schedules an appointment has done something correctable. A system that closes a case, terminates a payment, or refers a family for investigation has set consequences in motion that an apology does not undo. Irreversibility should raise the threshold for automation sharply.
Accountability Cannot Be Automated
The most serious risk of agentic systems is not error. It is the dissolution of responsibility.
When a system acts, the chain of accountability lengthens and thins. The official did not make the decision. The developer implemented a policy specification. The policy team described requirements. The vendor supplied a product. The minister approved a programme. Each account is individually reasonable and collectively adds up to a citizen harmed by nobody.
This is why the Catholic moral tradition’s insistence that conscience is exercised by persons is not a devotional remark but a practical requirement. Responsibility can be delegated to a person. It cannot be delegated to a process. An institution that cannot say who is answerable for a given automated act has not distributed responsibility, it has vacated it.
Practically, this means every agentic system operating in public administration needs a named official who is answerable for its actions, holds authority to suspend it, and would face consequences for its failures. Not a committee, not a function, a person whose name appears in a register the public can consult.
What Citizens Are Owed
Six things, none of which are technically difficult.
Disclosure. Citizens should know when an automated system has materially acted in their case, stated plainly rather than buried in a privacy notice.
Reasons. Not the model architecture, but the actual grounds: which rule was applied, which facts were found, what would have produced a different outcome.
Appeal to a human being. With genuine authority to reverse, not an officer whose role is to confirm what the system did.
Reversal. A defined mechanism for undoing an automated action, tested before deployment rather than improvised afterwards.
Timeliness. Automation that speeds the state’s actions while leaving citizens’ appeals at human pace has made the asymmetry worse.
A route for reporting failure. The people best placed to notice a system malfunctioning are those it is malfunctioning against. If they have no channel, the institution has blinded itself.
Doing This Well
Governments considering agentic AI would do well to begin where the stakes are lowest and the benefit clearest: internal processes, routine correspondence, retrieval, and the completion of steps that follow from decisions humans have already made. Build the accountability structures there, where errors are recoverable, before approaching anything that determines a person’s status.
And consult before deploying, not after. The people who understand where a benefits system fails are claimants and caseworkers, not procurement officers. Subsidiarity is not merely a principle about which level of government should decide. It is a claim that those closest to a reality know things that cannot be learned from a specification document.
Public administration is not a service industry with citizens as customers. It is the concrete form the state’s obligations take toward the people it governs. Speed matters, and slowness is itself a failure. But an efficient state that cannot say who decided, or why, or how to contest it has traded something it will find difficult to recover.

