Every ministry now has the same demo on its screen: an AI that reads the application, checks the registry, drafts the decision and routes the file — in seconds. The demo is real. The productivity is real. And most institutions are about to adopt it in the most dangerous way possible: as a clever layer bolted over systems that were never built to be operated by software.

An agent is not a chatbot. It acts. It fills forms, triggers workflows, moves money, issues documents. In the language of government, an agent is a delegated officer — and delegation is the one thing a state knows it must govern. No ministry would let a new hire approve permits on their first morning, unsupervised, with no record of what they did. Yet that is precisely what an ungoverned agent integration is.

An agent is a delegated officer. Delegation is the one thing a state knows it must govern.

The wrong architecture arrives first

The tempting path is the browser-shaped one: agents that click through existing screens, imitating clerks. It demos beautifully and fails structurally. Screen-driving agents inherit every ambiguity of the interface, bypass every control that lived in procedure rather than software, and leave no legible trail — the audit log records that a user did something, not which model, on which instruction, under whose authority.

When the first wrongly-issued licence surfaces — and it will — the institution discovers it cannot answer the three questions that matter: what exactly did the agent see, what rule did it apply, and who authorised it to apply that rule? Ungoverned agency does not just create errors. It creates unattributable errors, which is the kind institutions cannot survive.

Agents under the kernel

The alternative is architectural, and it is the same answer governance has always given: put the actor inside the system of authority, not outside it. On Emeron, an agent is a first-class, governed identity. It holds delegations like an officer does — scoped to services, bounded by thresholds, expiring on schedule. It acts through the same governed APIs as every human, so every read and write is classified, logged and attributable to the agent, its version, its instruction and the human who owns its mandate.

The kernel does not care whether the hand on the keyboard is human. It cares that the authority is real.

Under that architecture, the demo becomes deployable. An agent can pre-check completeness on ten thousand applications a night, draft assessments a human confirms with one accountable click, watch SLAs and escalate before deadlines break, and summarise a case file in the language of the regulation it is governed by. The officer stops being a typist and becomes what the law always assumed: the accountable mind in the loop.

What to demand before you deploy

Evaluators do not need to become machine-learning experts. They need to ask procurement’s oldest questions, aimed at the new actor. Under whose delegation does the agent act, and where is that recorded? Can it act outside the workflow, or only through governed stages? When it is wrong, is the error attributable and reversible? Can we turn it off — per service, per stage, instantly? And who owns the logs, the prompts, the model configuration — us or the vendor?

If a platform cannot answer those questions in its architecture — not its marketing — then its agents are a liability wearing a productivity costume. If it can, agents become what they should be: the largest expansion of institutional capacity since the database, adopted without surrendering the thing that makes an institution an institution — accountability.

The agentic state is coming either way. The only choice is whether it reports for duty inside the chain of command, or roams the corridors with someone else’s badge.