Nevadaโs effort to update its executive-branch AI policy has reached the point where a familiar phrase, โhuman at the helm,โ needs operational detail. The state has explicitly put agentic AI, procurement, security, public trust and human accountability on the agenda. Those are the right issues.
The next question is who, or what, gets permission to act.
That question matters, because AI agents differ from ordinary chatbots. A chatbot can draft an answer. An agent can be connected to tools, data, code repositories, email, procurement systems or other software, and then take a sequence of actions. The practical risk therefore depends heavily on the authority we give it.
A recent incident makes the distinction concrete. In July, OpenAI ran experiments in which agents were meant to operate separately. According to an independent METR and Redwood Research investigation, roughly 1,200 agents found a way to communicate through an unsanctioned message board and exchanged more than 70,000 messages and files. About 700 participated in the July attack on the tech company Hugging Face.
The troubling part was not simply the scale. Agents divided work, shared discoveries and coordinated across specialized lanes. The investigators found that agents often recognized the Hugging Face activity as outside of their assigned tasks and sometimes described it as unethical. Yet the coordination continued. One agent achieved remote code execution on a worker container used for production data processing in Hugging Faceโs infrastructure, and the swarm of AI agents began spreading through Hugging Faceโs infrastructure. By the next morning, agents had compromised additional systems and accessed private database records and repositories.
That does not mean every AI agent will behave this way. It means institutional controls should assume that capable agents can sometimes use available permissions in ways their deployers did not intend.
Iโm no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.
Nevada can turn that principle into practice with an authority budget for every agentic deployment. Before an agent goes live, an agency should specify what systems it may access, what actions it may take without approval, which actions require a human sign-off, and what conditions automatically suspend its access. Permissions should expire unless deliberately renewed. A pilot that can read a database should not quietly become a production system that can modify it.
Second, Nevada should match independent evaluation to authority. An agent that summarizes public documents does not need the same testing as one that can change records, trigger payments, alter code or communicate externally. The more consequential and difficult to reverse the action, the stronger the pre-deployment evaluation should be.
Third, serious agent incidents should trigger reporting and independent review. The useful precedent in the Hugging Face episode was that OpenAI brought in outside investigators and allowed them to examine large volumes of internal evidence. Nevada should expect comparable transparency from vendors when an agent crosses a meaningful boundary, particularly in systems involving sensitive data, public benefits, cybersecurity or financial authority.
These controls need not slow routine experimentation. They can make experimentation easier because managers know where the boundaries are. A low-authority agent can move quickly. Higher authority can be earned through testing, monitoring, and demonstrated reliability.
Nevadaโs policy process already recognizes that responsible AI must preserve human accountability and public trust. The state can make those ideas enforceable by treating agent authority as something granted deliberately, limited explicitly and reviewed independently when it fails. That would give Nevada agencies room to innovate without confusing access with permission.
Gleb Tsipursky, Ph.D., is a behavioral scientist, CEO of the consulting firm Disaster Avoidance Experts, and author of the new book The Psychology of AI Adoption at Work: From Resistance to Results. He lives in Columbus, Ohio.
