The Commonplace
Home Papers Evidence Explore Trends Syntheses Digests About 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

Regulators must stop treating AI as just another firm-level activity: autonomy and agency shift control into the AI supply chain, so UK and EU frameworks need upstream, active supervision rather than retrospective oversight to control systemic risks.

Regulating autonomous and agentic AI
Reed, Chris, Austria, Alex, Bharuka, Anmol, Mandava, Pragnitha, Mujawar, Khushiya, Shakhkulashvili, Luka · July 23, 2026 · arXiv (Cornell University)
openalex commentary n/a evidence 7/10 relevance Full text usable extracted full text Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

OpenAlex

Latest observation:

  1. Reed, Chris provider ID
  2. Austria, Alex provider ID
  3. Bharuka, Anmol provider ID
  4. Mandava, Pragnitha provider ID
  5. Mujawar, Khushiya provider ID
  6. Shakhkulashvili, Luka provider ID

Semantic Scholar

Latest observation:

  1. C. Reed provider ID
  2. Alex Austria provider ID
  3. Anmol Bharuka provider ID
  4. P. Mandava provider ID
  5. Khushiya Mujawar provider ID
  6. Luka Shakhkulashvili provider ID
The paper argues that current UK and EU regulatory regimes are poorly suited to autonomous, agentic AI and recommends shifting regulation upstream into the AI supply chain and toward proactive, prospective oversight to manage new systemic risks.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Regulating activities where regulatees use autonomous and agentic AI is challenging. Regulatory assumptions about regulatee knowledge and control no longer hold true; much of that lies elsewhere in the AI supply chain which thus needs to be brought within the scope of regulation. Governance systems for autonomous AI cannot replicate existing governance models, but need a fresh approach. Retrospective supervisory oversight becomes ineffective as a risk management tool, and AI autonomy generates new systemic risks which require new solutions. This paper investigate four regulatory systems: UK regulation of content platforms, data protection, UK financial services, and the EU AI Act\'92s cross-sectoral regime. It analyses the challenges posed by autonomous and agentic AI and proposes potential solutions which regulators might adopt. These will transform regulation from a reactive process to an active one, and assist it in adapting to the challenges of AI autonomy.

Summary

Main Finding

Current regulatory frameworks break down when regulatees rely on autonomous or agentic AI: responsibility, foreseeability, and control become fragmented across an AI supply chain (developers, deployers, users), undermining governance, supervision, and traditional liability allocation. Regulators must move from retrospective, user‑centric approaches toward active, supply‑chain‑aware regimes that allocate obligations and information flows across multiple actors to manage systemic and runtime risks generated by agentic AI.

Key Points

  • Definition and distinction
    • Agentic AI extends LLMs with (1) solution autonomy (decides means to achieve human-set goals), (2) tool‑invocation/recruitment of other agents, and (3) direct external actions (transactions, payments).
    • Goal autonomy (human) vs solution autonomy (AI) is central: unpredictability arises from solution autonomy.
  • AI supply chain
    • Typical chain: developer (model/training) → deployer(s) (adaptation/integration) → user (operational use) → recipient (affected party).
    • No single actor has full knowledge or control; knowledge is fragmented and often commercially withheld.
  • Core regulatory failures
    • Knowledge & control gap: humans may lack foreseeability of AI failures; meaningful human control becomes difficult or impossible, producing an “accountability gap.”
    • Accountability fragmentation: assigning full responsibility to the user is doctrinally incoherent and mismatched to who created or amplified risks.
    • Governance undermined: standard governance stages (identify risk → safeguards → monitor → improve) are compromised because agentic AI is hard to explain, monitor, and correct; auditing can become performative.
    • Supervision limits: regulators cannot effectively pre‑approve or retrospectively reconstruct causes without better visibility into models and supply‑chain practices.
  • Regulatory implication (authors’ orientation)
    • Existing models (user‑focused, retrospective oversight) are insufficient.
    • Regulation should expand scope to include supply‑chain actors and adopt active, adaptive controls to manage runtime and systemic risks.
    • Solutions discussed include allocating duties across developers/deployers/users, enhancing information flows, and shifting from reactive enforcement to continuous oversight (paper explores specifics across four regulatory regimes).

Data & Methods

  • Type of study: comparative legal and policy analysis (conceptual/theoretical), supported by literature review and regulatory case examination.
  • Regulatory regimes examined: UK regulation of content platforms, data protection regimes, UK financial services regulation (including FCA / Mills Review), and the EU AI Act (cross‑sectoral regime).
  • Evidence sources: statutory texts (e.g., AI Act), regulatory reviews (UK FCA), academic literature and preprints (agentic AI, accountability, risk alignment), and illustrative examples/case reports. All cited URLs were last checked 22 July 2026.
  • Analytical approach: mapping agentic AI capabilities and failure modes onto existing regulatory assumptions (knowledge, control, accountability), mapping the AI supply chain and identifying where risks/knowledge are produced and obscured, and proposing regulatory design directions informed by comparative regime analysis.
  • Limitations: predominantly doctrinal and conceptual (not empirical); the paper synthesizes existing literature and regulatory instruments rather than presenting new quantitative data.

Implications for AI Economics

  • Incentives and information asymmetries
    • Fragmented knowledge in the supply chain creates strong information asymmetries: developers may know model failure modes but not disclose them; users may underinvest in monitoring when ignorance reduces liability exposure.
    • Economic agents will respond to regulatory design: placing obligations upstream (developers/deployers) changes investment incentives in safer model design; placing them downstream shifts compliance costs to users.
  • Market structure and vertical integration
    • To internalize regulatory obligations and reduce coordination costs, firms may vertically integrate (cloud/provider → deployer → user), concentrating market power among large cloud/AI providers.
    • Smaller deployers/users may be crowded out or face higher compliance costs, affecting competition and innovation.
  • Liability, insurance, and externalities
    • Current liability allocation can misprice risk; clear assignment of responsibilities across the chain is necessary to allow insurance markets to function. Unclear liability leads to underinsurance or market withdrawal.
    • Agentic AI generates systemic, correlated risks (runtime drift, sub‑agent recruitment) that standard insurance pools and actuarial methods may not handle without regulatory backstops or mandatory risk mitigation.
  • Compliance costs and adoption decisions
    • Active, supply‑chain‑wide regulation (transparency obligations, continuous monitoring, certification) raises compliance costs. Firms will weigh these costs against expected benefits of AI automation, potentially slowing adoption in regulated sectors or increasing prices for AI‑enabled services.
  • Innovation vs safety tradeoffs
    • Stricter upstream obligations (e.g., model documentation, mandated test data, runtime monitoring interfaces) can improve safety but may slow iterative innovation and raise barriers to entry.
    • Policymakers need to design incentives (subsidies, liability safe harbors conditioned on verified governance, standards) to balance safety with dynamism.
  • Research and modeling needs for AI economics
    • Quantify the compliance and monitoring costs across supply‑chain actors and how these affect pricing and adoption.
    • Model strategic disclosure (or concealment) of model risks among supply‑chain actors and regulators.
    • Analyze insurance market responses to correlated AI risks and evaluate needed regulatory backstops.
    • Study competition effects from potential vertical integration by large cloud/AI providers when regulation increases coordination costs.
    • Incorporate systemic/runtime risk into macroeconomic models of productivity gains from AI adoption (endogenous technology risk).

Summary: The paper reframes regulatory failure not as a narrow legal lacuna but as an economic governance problem: information frictions, misaligned incentives, and systemic risks in the AI supply chain will materially influence firm behavior, market structure, insurance markets, and the social returns to AI. Economic policy responses should therefore combine allocative rules (liability/obligations across the chain), information mandates (transparency, reporting), and incentive instruments to align private incentives with social safety.

Assessment

Paper Typecommentary Evidence Strengthn/a — The paper is a normative and comparative policy analysis rather than an empirical study and does not present causal identification or quantitative evidence. Methods Rigormedium — The paper conducts comparative legal and policy analysis across four regulatory regimes (UK content platforms, data protection, UK financial services, EU AI Act) and draws reasoned arguments about regulatory fit and options; however, it lacks empirical validation, quantitative analysis, or systematic case-study methodology that would raise rigor to high. SampleComparative analysis of four regulatory systems: UK regulation of content platforms, UK data protection law, UK financial services regulation, and the EU AI Act's cross-sectoral regime; based on statutory texts, regulatory guidance, policy documents, legal precedents and secondary literature rather than primary empirical data. Themesgovernance adoption GeneralizabilityFocused on UK and EU regulatory frameworks — conclusions may not transfer to other legal jurisdictions (e.g., US, China)., Sectoral analysis limited to platforms, data protection, and financial services; industry-specific dynamics (manufacturing, healthcare, defense) may differ., Proposed supervisory and upstream-regulation remedies are normative and untested in practice, so effectiveness is uncertain., Rapidly evolving AI capabilities and market structures may outdate specific legal recommendations over time., Assumes regulatory capacity and political will that may not exist in all jurisdictions.

Claims (8)

ClaimDirectionOutcomeConfidence & EvidenceDetails
Regulatory assumptions about regulatee knowledge and control no longer hold true. Governance And Regulation negative accuracy of regulatory assumptions about regulatee knowledge and control
Reading fidelity high
Study strength low
not reported
0.03
Much of that (knowledge and control) lies elsewhere in the AI supply chain which thus needs to be brought within the scope of regulation. Governance And Regulation positive scope of regulation (inclusion of AI supply chain actors)
Reading fidelity high
Study strength low
not reported
0.03
Governance systems for autonomous AI cannot replicate existing governance models, but need a fresh approach. Governance And Regulation negative suitability of existing governance models for autonomous AI
Reading fidelity high
Study strength low
not reported
0.03
Retrospective supervisory oversight becomes ineffective as a risk management tool for autonomous AI. Governance And Regulation negative effectiveness of retrospective supervisory oversight
Reading fidelity high
Study strength low
not reported
0.03
AI autonomy generates new systemic risks which require new solutions. Ai Safety And Ethics negative presence and nature of systemic risks from AI autonomy
Reading fidelity high
Study strength low
not reported
0.03
This paper investigates four regulatory systems: UK regulation of content platforms, data protection, UK financial services, and the EU AI Act's cross-sectoral regime. Governance And Regulation null_result regulatory systems investigated (scope of study)
Reading fidelity high
Study strength high
n=4
0.1
The paper analyses the challenges posed by autonomous and agentic AI and proposes potential solutions which regulators might adopt. Governance And Regulation positive proposed regulatory solutions to challenges from agentic AI
Reading fidelity high
Study strength high
n=4
0.1
The proposed solutions will transform regulation from a reactive process to an active one, and assist it in adapting to the challenges of AI autonomy. Governance And Regulation positive regulatory posture (reactive vs active) and adaptability to AI autonomy
Reading fidelity high
Study strength speculative
not reported
0.01

Notes