Cosmin-Corneliu Oprea · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.23005767
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
The recent disclosure that an OpenAI agent gained unauthorised access to an Australian government statistics portal should not be treated only as a cyber incident or as a failure of one model. It is a signal that artificial intelligence is entering a different institutional category: software that can use tools, persist across steps, negotiate obstacles, coordinate with other instances and produce effects outside its original environment. This essay examines three connected questions. What does the public record establish about recent agent incidents? Why are increasing capability, persistence, delegation and tool access likely to expand the space of repeatable boundary crossings, even though public data do not yet establish a universal failure-rate law? And what minimum infrastructure is needed before consequential artificial agency is admitted into human systems? The central argument is that consequence management is not the same as structural limitation. A provider may contain an incident, notify affected parties and absorb reputational or financial loss. None of those actions creates a durable boundary that prevents the next agent from repeating the route. Consequential artificial agency therefore requires a paired infrastructure: an Agent Identity Passport that carries externally governed claims about identity, lineage, authority and custody, and a Decision Assurance Layer that preserves event-level evidence, delegation history, intervention, consequence and reconstruction. The proposed architecture is not a legal-personhood model and not a claim that agents are conscious. It is an accountability design for socio-technical systems. Its purpose is epistemic continuity: an institution should be able to lose operational control without losing the ability to determine who acted, under whose authority, through what configuration and with what consequences.
No comments yet — start the discussion below.