Agentic artificial intelligence—AI systems that operate autonomously with minimal human oversight—is advancing rapidly, raising critical governance questions that the United States must address to maintain security and competitiveness, according to experts at the Special Competitive Studies Project (SCSP). Unlike current AI that responds to prompts, agentic AI can independently set goals, create plans, and execute multi-step tasks, creating a self-accelerating loop where AI helps build better AI. Ylli Bajraktari, president of SCSP, warned in a recent newsletter that this compounding capability development will far outrun projections.
The implications for global security are profound. Bajraktari emphasized that an AI agent capable of navigating complex bureaucratic systems, identifying exploitable vulnerabilities, and acting without leaving a clear attribution trail represents a qualitative expansion of adversarial capability. The United States should be aware that adversaries will deploy agentic AI systems in areas where governance is weakest, potentially using them for coercion, espionage, and influence.
SCSP experts argue that effective governance of agentic AI focuses not on the AI model itself but on the scaffolding built around it. This scaffolding includes connectors to bridge the model to real-world infrastructure—such as email, booking systems, and financial platforms—as well as memory that allows the system to learn and adapt across interactions. Planning capabilities break large objectives into smaller tasks, identify failure, and navigate obstacles without human intervention. Permission structures define what the system can access and act upon, while guardrails determine what the system will refuse to do, such as spending limits or requiring human sign-offs.
Accountability remains a major challenge, with governance falling short in three key ways, according to SCSP. First, responsibility is untraceable when using AI; there is no way to determine who authorized what if an AI agent acts on someone's behalf. Second, current frameworks do not ask whether an AI agent performed a task safely or caused harm, only that the task was completed. Third, agentic AI builds personal profiles that may include sensitive data by accumulating information on patterns of behavior, preferences, and inferences.
Despite these challenges, SCSP emphasizes that agentic AI is not a technology to be feared or deferred. Institutions that prioritize understanding, shaping, and governing agentic AI will determine their own competitive position and also impact the character of the environment in which agentic AI operates globally. To learn more about how the United States should pursue effective governance of agentic AI, visit scsp.ai.

