0 cumulative citations
View corpus contextA new corporate resilience metric repurposes national-level indicators to judge how companies shape society’s capacity to absorb and adapt to harms from agentic AI; an illustrative audit of Microsoft’s public materials shows how the approach can be operationalized but stops short of validating real-world effects.
Citation observations
Cumulative provider counts captured on specific dates; providers are never combined.
Companies that deploy AI agents and make them available to others are creating the sociotechnical circumstances under which this technology integrates into existing social and economic structures. AI-deploying companies are institutional actors that actively shape society's capacity to withstand and govern the consequences of agentic AI. In view of these societal impacts, companies can build societal resilience by designing and promoting safer implementations of AI agents. To operationalize this goal, this paper adapts the indicator-based Societal Capacity Assessment Framework (SCAF) to measure how a company's deployment decisions contribute to societal resilience, inverting its original measurement of societal resilience as a backdrop for deployment decisions (Gandhi et al., 2025). Our procedure has two steps: a conceptual step in which we design a suite of indicators that define what SCAF's vulnerability, coping, and adaptive capacities mean when assessing a company's agentic AI deployment decisions; and a measurement step in which we apply this framework in a structured assessment of public-facing Microsoft documents.
Summary
Main Finding
The paper adapts the Societal Capacity Assessment Framework (SCAF) to evaluate how companies’ deployment decisions for agentic AI (systems that plan, reason, and act on behalf of users) contribute to societal resilience. It proposes indicator sets mapping company actions to vulnerability, coping, and adaptive (including transformative) capacities, and demonstrates the approach via a structured assessment of Microsoft’s public-facing documents. The core claim is that downstream deployers—not only frontier model developers—meaningfully shape societal exposure to agentic-AI risks and can (or should) build resilience through deployment design choices.
Key Points
-
Motivation
- Societal resilience (ability to absorb, cope, adapt, transform after shocks) is a useful complement to upstream AI risk prevention.
- Companies that deploy agentic AI are key governance actors: their choices about use-cases, autonomy defaults, safeguards, and support shape downstream exposure and norms.
- Decentralized deployment actors can build resilience even absent centralized constraints on frontier model training.
-
Conceptual contribution
- Inverts the original SCAF (which measured societal resilience as a backdrop) to measure company contributions to societal resilience.
- Translates SCAF’s three capacities to company-relevant contributions:
- Vulnerability: product diffusion and integrations that increase society’s susceptibility (e.g., embedding agentic AI in critical infrastructure).
- Coping capacity: features and services that help users detect/respond/recover from failures (monitoring, incident support).
- Adaptive (and transformative) capacity: features, policies, and transparency that reduce future risk likelihood and reshape systems (acceptable-use policies, human-in-the-loop norms, red-teaming, reporting, defensive tools).
-
Agentic-AI threat model (illustrative, near–to–medium term)
- Removal of human labor bottlenecks can accelerate and scale harmful projects (loss of human friction, “agentic groupthink”).
- Expanded cybersecurity surface: multi-agent interactions, tool-use, and prompt-injection vectors create new attack opportunities.
- Unknown emergent threats from post-deployment interactions among agents even when single-agent capabilities are understood.
-
Indicator design and scope
- Indicators were chosen to be actionable and measurable in company-facing artefacts; selection grounded in the 2026 CLTC Agentic AI Risk Management Profile (high-priority, practitioner-focused mitigations).
- Emphasis on public-facing company documents in the illustrative application (what companies say and publish about product design, policies, and tooling).
-
Case study
- The authors applied the company-level SCAF indicators to Microsoft’s public documents as an illustrative test of the method (details of results are in the paper; the main goal is to demonstrate feasibility and construct validity).
-
Caveats
- Focus is on contributions to resilience (what firms enable externally), not on firms’ internal risk exposure.
- The case study is illustrative and limited to public-facing materials; deeper assessments would require internal data and comparative analyses.
Data & Methods
- Two-step empirical approach:
- Conceptual design: adapt SCAF capacity definitions to company-level contributions for agentic AI; construct indicators that map to vulnerability, coping, and adaptive/transformative capacities.
-
Measurement/application: perform a structured assessment of public-facing company documents using those indicators; Microsoft chosen as an illustrative deployer case study.
-
Indicator selection principles:
- Grounded in high-priority mitigations from the 2026 CLTC Agentic AI Risk Management Profile, which synthesizes practitioner and standards-based recommendations (NIST AI RMF alignment).
- Focus on mitigations that are both within deployer control and plausibly linked to societal resilience outcomes (e.g., deploy-time default autonomy, monitoring/incident tooling, reporting/transparency, use restrictions).
-
Data sources:
- Publicly available corporate materials (product docs, policies, blog posts, help/support materials) for the illustrative Microsoft assessment.
- The paper follows SCAF’s indicator-based, evidence-seeking approach rather than relying on a single metric.
-
Methodological limits:
- Public-docs-only assessments are partial: they capture stated design choices and public commitments but may miss internal practices, enforcement fidelity, or real-world behavior.
- The paper is a prototype: indicators and operationalizations are intended for refinement, comparative applications, and possible quantification.
Implications for AI Economics
-
Externalities and market failure
- Company deployment choices create externalities: diffusion and integration choices increase societal vulnerability while benefits accrue privately. This can produce underinvestment in resilience—classic public-good/free-rider problems.
- Measurable indicators of resilience contributions can make these externalities visible to policymakers, investors, and insurers, enabling targeted corrective mechanisms (regulation, subsidies, procurement preferences, or liability structures).
-
Incentives and corporate strategy
- Firms face trade-offs between competitive pressure to diffuse capabilities and the social value of restraint. Without alignment, competition can favor rapid diffusion that increases systemic vulnerability.
- Firms that invest in coping/adaptive features (monitoring, incident support, transparency, human-in-the-loop defaults) may internalize some mitigation costs but also reduce third-party risks that can create aggregate market instability (e.g., cybersecurity cascades, regulatory backlash).
-
Valuation, risk pricing, and insurance
- A standardized SCAF-for-companies approach could feed into ESG-like assessments for AI governance, affecting firm valuation and access to capital.
- Insurers could use resilience indicators to price cyber/AI-liability insurance more accurately; conversely, lack of resilience could increase expected systemic losses.
-
Labor, productivity, and diffusion economics
- Agentic AI that removes human bottlenecks alters labor supply and organizational scale economies; resilience-focused deployment (e.g., preserving human oversight) can moderate disruptive short-term labor impacts while maintaining productivity gains longer-term.
- Decisions about default autonomy levels affect adoption speed and the economic distribution of benefits and harms across sectors and regions.
-
Policy design and regulatory implications
- Indicators make actionable targets for policy: regulators can incentivize resilience-building (tax credits, standards, procurement preferences) or require disclosure/assurance about coping and adaptive features.
- Decentralized governance can be effective if combined with incentives that align firm-level decisions with societal resilience (e.g., liability rules, transparency mandates).
-
Research and market monitoring
- The framework enables comparative empirical work across firms and sectors to study how deployment strategies affect macro-level outcomes (systemic risk, adoption patterns, labor-market effects).
- Better measurement supports evidence-based policy and economic modeling of AI diffusion under different governance regimes.
Overall, the paper argues that measuring and incentivizing company contributions to societal resilience is both feasible and important for addressing the socio-economic externalities of agentic-AI diffusion. It provides a prototype measurement approach that can be refined and used to inform economic policy, corporate governance, valuation, and insurance markets.
Assessment
Claims (14)
| Claim | Direction | Outcome | Confidence & Evidence | Details |
|---|---|---|---|---|
| Companies that deploy agentic AI and make it available to others shape the sociotechnical conditions under which the technology integrates into social and economic structures. Governance And Regulation | positive | Influence of AI-deploying companies on societal conditions and governance |
Reading fidelity
high
Study strength
low
|
not reported
|
| Companies can contribute to societal resilience by designing and promoting safer implementations of AI agents. Ai Safety And Ethics | positive | Company contribution to societal resilience |
Reading fidelity
high
Study strength
low
|
not reported
|
| The paper extends the indicator-based Societal Capacity Assessment Framework from assessing societal resilience as a backdrop for deployment decisions to assessing company contributions to societal resilience. Governance And Regulation | positive | Applicability of a societal-resilience assessment framework to companies |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Companies that deploy agentic AI make decisions about which use cases to encourage, the default level of AI autonomy, and which safeguards to include. Task Allocation | positive | Company control over agentic-AI deployment and task allocation |
Reading fidelity
high
Study strength
low
|
not reported
|
| Deployment decisions have downstream effects on third-party risk exposure, cultural norms, and institutional functioning. Ai Safety And Ethics | negative | Third-party exposure to AI risks and institutional functioning |
Reading fidelity
high
Study strength
low
|
not reported
|
| Companies that deploy AI agents increase societal vulnerability to agentic-AI risks, while the same companies can also build societal resilience through design decisions that improve responses to failure. Ai Safety And Ethics | mixed | Societal vulnerability and resilience to agentic-AI risks |
Reading fidelity
high
Study strength
low
|
not reported
|
| The authors' core research question is how to assess company contributions to societal resilience, and they address it by prototyping resilience indicators and applying them to Microsoft's public documents. Governance And Regulation | positive | Assessment of company contributions to societal resilience |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The company-level version of SCAF conceptualizes vulnerability as exposure created by product deployment reach, coping as features that help users respond to and recover from failures, and adaptive capacity as features and practices that reduce future failures and improve learning. Governance And Regulation | mixed | Company contributions to vulnerability, coping, and adaptive resilience capacities |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Agentic AI risks are considered suitable for company-level SCAF assessment because their management falls directly within the purview of large companies and existing work provides operational definitions of agency and autonomy for mitigation recommendations. Governance And Regulation | positive | Feasibility of company-level agentic-AI risk governance |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The paper selects high-priority agentic-AI risk mitigations from the 2026 CLTC Agentic AI Risk Management Profile as empirical proxies for vulnerability, coping-capacity, and adaptive-capacity constructs. Governance And Regulation | positive | Quality and standardization of agentic-AI resilience indicators |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Removing human labor bottlenecks through agentic-AI-enabled automation may increase the ability of malicious or unintentionally harmful projects to scale. Automation Exposure | negative | Ability of harmful projects to scale after removal of human labor constraints |
Reading fidelity
high
Study strength
speculative
|
not reported
|
| Without design decisions that prioritize human agency, agentic-AI groupthink may undermine institutional interrelationships and enable harmful projects to reach completion. Decision Quality | negative | Institutional accountability and quality of collective decision-making |
Reading fidelity
high
Study strength
speculative
|
not reported
|
| Multi-agent interactions can introduce unpredictability that undermines governance based on evaluating individual agents before deployment. Ai Safety And Ethics | negative | Reliability of evaluation-based governance for multi-agent systems |
Reading fidelity
high
Study strength
speculative
|
not reported
|
| Prompt injection is an architectural security problem for LLM agents because malicious instructions embedded in processed data may be followed when agents fail to distinguish user requests from external content. Ai Safety And Ethics | negative | Agent security and susceptibility to malicious instructions |
Reading fidelity
high
Study strength
medium
|
not reported
|