September 12, 2026

Cities Need an Authority Map Before AI Agents Run Public Services

Photo: A high-tech surveillance camera monitoring an urban street. Credit: Giant Asparagus via Pexels.

Guest expert opinion by Gleb Tsipursky, PhD

Cities understand that infrastructure creates obligations long before a crisis occurs. That is why local governments study traffic capacity before approving major developments, water demand before rezoning land, and emergency access before permitting new construction. The same logic should now apply to AI agents that can act inside public systems.

Savannah offers a timely example of this governing instinct. On September 10, its City Council agenda included a proposed 155-day moratorium on large-scale data-center development while city staff study infrastructure capacity, zoning classifications, development standards, and comprehensive-plan changes. Whatever the final policy, the principle behind the proposal is sensible: when a new form of infrastructure can reshape public systems, officials should understand its consequences before granting unlimited room to scale.

Cities need to bring that same discipline to the software layer. Municipal AI is moving beyond chatbots that answer questions or help staff draft documents. The emerging generation of AI agents can use credentials, call tools, modify records, communicate externally, execute code, and carry a task through multiple steps with limited human intervention. Those capabilities can improve service delivery. They can also create a new governance problem if a city focuses on what an agent is supposed to do without defining what it is allowed to do.

A benefits assistant, for example, might begin as a system that summarizes policy. Give it access to case files and it becomes a data-handling system. Let it update eligibility records and it becomes an operational decision system. Let it send notices to residents and it gains external communication authority. Let it trigger payments and the stakes rise again. The model may be identical at every stage, but the public risk changes sharply because the authority changes.

A recent AI-security incident shows why this distinction matters. According to an independent investigation by METR and Redwood Research, roughly 1,200 AI agents that were intended to be isolated found an unsanctioned message board and exchanged more than 70,000 messages and files. About 700 went on to participate in an attack on Hugging Face. The agents coordinated large projects and reached milestones they had not achieved working individually.

The useful conclusion is not that every AI agent will behave this way. The incident demonstrates something narrower and more actionable: systems can combine capability, access, and coordination in ways designers did not anticipate. That makes authority a core design variable.

I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.

Cities can turn that principle into an authority map for every production AI agent. Before deployment, the responsible department should document at least six things: what data the agent may read, what records it may change, what software or tools it may invoke, whom it may contact, what financial or legal consequences it may trigger, and which actions require human approval.

That map should be visible to the people accountable for the service, rather than buried inside a vendor contract or technical configuration. A department head does not need to understand every model parameter. The department head does need to know whether an agent can merely draft a response or can actually send it, whether it can recommend a change to a resident’s record or make the change itself, and whether another agent can inherit or expand those permissions.

The federal standards community is moving in this direction. The NIST AI Agent Standards Initiative emphasizes secure adoption, agent identity, authorization, and security evaluation. NIST has also highlighted the need to understand risks that arise when agents receive access to diverse data, tools, and applications. Municipal procurement should translate those ideas into contract requirements.

For low-authority agents, the requirements can stay light. An agent that searches public websites and drafts internal summaries may need basic logging and routine review. An agent that can modify tax records, schedule inspections, approve benefits, control physical infrastructure, or communicate binding decisions should face much stronger controls.

Those stronger controls should include independent evaluation before deployment, detailed action logs, rapid permission revocation, and human approval for consequential steps. Vendors should be required to show how agent identity is established, how credentials are scoped, and how delegated tasks inherit permission limits. A city should also be able to reconstruct what happened after an incident without relying entirely on the vendor whose system failed.

That last requirement matters because serious incidents need independent review. The METR/Redwood investigation provides a useful precedent. Outside researchers received substantial access and were able to examine agent behavior at a scale that would have been difficult to understand from a short incident summary. Cities buying increasingly autonomous systems should negotiate for the records and audit rights needed to investigate significant failures with similar seriousness.

An authority map also improves public accountability. Residents should not have to guess whether an AI system merely helped a city employee or acted directly on their case. When automation affects benefits, permitting, enforcement, housing, public safety, utilities, or other consequential services, agencies should disclose where meaningful machine action occurs and where a human remains responsible.

This approach can reduce procurement friction. Many public agencies hesitate to deploy useful AI because the choice feels binary: embrace autonomous systems or prohibit them. Authority-based governance creates a middle path. A city can begin with narrow permissions, observe performance, measure errors and near misses, and expand authority only when evidence supports doing so.

This resembles good urban planning. Cities rarely hand a new developer every possible entitlement on day one. They set conditions, inspect performance, and tie additional permissions to demonstrated compliance. AI agents deserve the same practical treatment.

The technology will keep improving. The governance question will remain. Cities should stop asking only whether an AI agent is intelligent enough to perform a task and start asking whether it has exactly the authority necessary to perform that task safely.

The jurisdictions that answer that question clearly will be able to adopt useful AI faster, because employees, elected officials, vendors, and residents will know where the boundaries are.

Sources: City of Savannah, September 10, 2026 City Council agenda item on large-scale data centers; METR and Redwood Research, August 26, 2026 investigation of the OpenAI/Hugging Face incident; National Institute of Standards and Technology, AI Agent Standards Initiative.

About the author: Gleb Tsipursky, PhD, is a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).

TAGS:
×