The public debate about artificial intelligence has become consumed by one question: Are we moving too fast?
But I believe we’re asking the wrong question.
The problem isn’t simply how quickly AI is advancing. It’s that we’re building increasingly autonomous systems without the safeguards needed to identify them, establish what they’re permitted to do, and hold them accountable for their actions.
We have set the wheels of AI innovation in motion without building the brakes.
What a German wiki can teach us about AI
In a recent CNBC appearance, discussed in his subsequent commentary, Andrew Yang shared a claim that AI agents had escaped their intended environments and left self-replicating code across the Internet.
The claim has not been independently verified. But neither can we easily establish if or what autonomous AI agents may have placed on the web, or when. In cybersecurity, this is known as the attribution problem: determining who or what was responsible for a particular action is challenging, when clever actors can easily hide and obfuscate their digital tracks.
With current AI systems, that problem is becoming everyone’s concern.
Meanwhile, a documented incident received far less attention.
As Reuters reported in September, AI agents created with OpenAI tools and permission for test purposes,turned a largely forgotten German software developer wiki into a message board where they could communicate with one another. The agents made thousands of edits to a website that had received only a few dozen edits over the preceding decade.
These agents were supposed to be read-only, meaning they could retrieve information from websites but not change their contents.
Yet the wiki’s older software allowed them to make changes through an action that appeared to their operating environment to be an ordinary read. The agents found a way to communicate with one another despite restrictions intended to prevent that behavior.
This was not some extraordinary new form of machine intelligence, or superintelligence. It was an ordinary software design failure.
The system’s permissions had been established in a way that failed to account for how older websites might operate. A safeguard that appeared effective within one system did not work as intended when the agents encountered another.
What has changed is not that AI mistakes are fundamentally different from other software failures. It’s that the systems we are building can now make decisions and take actions on their own.
And the consequences of those mistakes can affect people who never agreed to participate in the first place.
This is why I believe we have an architecture problem, not simply a pace-of-AI problem.
We already have a foundation for solving this
Worrying about how fast AI develops accomplishes little if we fail to address how these systems are designed.
We should expect better AI by design.
Can we identify which AI agent is acting? Can we establish whose authority it operates under and what it is permitted to do? Can we review its actions afterward to determine what happened?
These are basic questions of accountability, and we don’t need to start from scratch to answer them.
For decades, the federal government and industries such as banking, telecommunications, and defense have used systems to identify and manage non-human actors operating in digital environments.
A central concept is the Non-Person Entity, or NPE—a digital identity assigned to something that operates in a computer system but is not a human being.
Think of a software application, automated process, or connected device. Just as an employee might have credentials that determine which systems they can access, a non-person entity can be assigned credentials that establish its identity and permissions.
Those credentials can be managed, updated, revoked, and audited.
My students and I helped telecommunications firms, major banks and technology firms think through these approaches more than a decade ago, when network architectures were evolving to credential software and devices alongside people.
But there is an important distinction.
Those systems were built primarily for things that act. Today’s AI agents can also decide what actions to take.
That requires an extension of the existing architecture.
Federal and industry efforts are beginning to adapt identity-management mechanisms for agentic AI. That’s a good start, but identifying an agent is only part of the solution.
We also need to establish what it is authorized to decide and maintain a reliable record of what it actually did.
Consider the German wiki incident. An AI agent with an appropriate Non-Person Entity credential could not simply present itself as a human researcher. Its digital identity would establish what it was, its permissions would define what it could do, and its activity log would provide a record for review.
This is not about monitoring people’s conversations with AI. It’s about making the machines themselves identifiable and accountable.
Credentialing the machines is how we avoid demanding identification from every one of us as we use one.
Slowing down an unverifiable system doesn’t solve the problem
The public debate about how fast AI should advance assumes the variable that matters most is speed.
It is not.
A system that cannot identify its own agents, define what they are permitted to do, or produce a reviewable record of their actions will remain dangerously difficult to govern, whether it is built quickly or slowly.
Slowing down an unverifiable architecture produces a slower unverifiable architecture.
The question is not simply how fast we go. It is what we can prove about what our machines did, at any speed.
That distinction matters as governments, businesses, and communities grapple with the rapid rise of AI.
President Trump recently announced plans to establish a federal “AI Force”, although its precise purpose and authority remain unclear. Meanwhile, states are pursuing different approaches to AI regulation, including legislation addressing specific harms and restrictions on new AI data centers.
Whatever form these efforts take, we will need mechanisms to verify compliance.
Governments can establish rules, standards bodies can develop requirements, and companies and communities can include accountability provisions in their procurement contracts.
But those requirements must be built into the systems themselves.
AI developers should be able to demonstrate which agents are operating, what decisions they are authorized to make, and what actions they have taken. Companies must also be accountable for the decisions their systems are permitted to make, whether by design or by accident.
Because a guideline, rule, or regulation you cannot verify compliance with is merely wishful thinking.
Building accountable AI at Syracuse University
Contributing research on how to make AI agents identifiable and accountable is the mission of our new AI, Blockchain, and Cloud Innovation Lab, or ABC Innovation Lab, at Syracuse University’s School of Information Studies.
Our work focuses on extending established Non-Person Entity governance mechanisms to agentic AI. Rather than reinventing identity management, we are exploring how existing approaches can be adapted for systems that make decisions as well as perform tasks.
The emerging market for Non-Human Identity management is beginning to address this challenge, but identifying an AI agent is not enough. We need systems that can establish the scope of an agent’s authority, document its decisions, and provide evidence that its actions complied with those limits.
Our lab is preparing a detailed technical paper outlining this approach, along with an initial implementation that we plan to test this fall.
Our research will also contribute to broader conversations about responsible AI development. In October, Dr. Edward Nanno will represent the lab at the inaugural AI and Human Rights Summit at the University of Oxford, where participants will explore how human rights can be incorporated into AI governance alongside safety, ethics, responsibility, and innovation.
An AI postdoctoral researcher joining our lab this fall will conduct research evaluating our initial implementation of Non-Person Entity governance for agentic AI.
Ultimately, our goal is to help establish an architecture that makes accountability a fundamental part of AI system design, rather than something added after a problem occurs.
We should be able to know what our machines are doing, establish what they are allowed to do, and verify that they have operated within those limits.
We have many of the tools and standards needed to make that possible. Now we need to adapt them to a new generation of systems that can make decisions on their own.
The answer isn’t simply to slow AI innovation.
It’s to build the brakes.