Who governs 900 billion AI agents?

Huawei’s forecasts of an agentic future expose a question deeper than computing capacity: how can institutions ensure that autonomous systems retain legitimate authority as they learn, coordinate and act, asks Vendan Ananda Kumararajah

Huawei’s 2025 Intelligent World 2035 report projected that nine billion people could be connected to 900 billion AI agents by 2035. A 2026 follow-up projected that traffic generated by agents could account for more than 90 per cent of global token traffic by then. These are corporate forecasts, not a census of the future. But they make one present governance question difficult to avoid: if autonomous systems become this numerous and interconnected, who remains accountable for the authority through which they act?

Huawei characterises agents as systems that perceive their surroundings, reason, make decisions, invoke tools and interact with people in real time. Its reports call for greater computing capacity, connectivity, memory and operating systems designed for agents, while identifying security and privacy as essential. Yet while infrastructure can scale an agent’s capacity to act, it cannot by itself determine when that action is legitimate.

The familiar answer is human oversight. Yet no human can personally approve every decision in a network of agents acting continuously, at machine speed and across organisational boundaries. Nor does a nominal supervisor provide meaningful accountability when the volume and velocity of decisions leave them unable to understand, intervene in or alter the system. Oversight must therefore be designed into the conditions under which an agent acquires, exercises and retains authority.

Consider an agent authorised to manage a manufacturer’s supply chain. It can gather information, place orders and negotiate with other systems. A shortage prompts it to identify a new supplier. The supplier appears credible, the price is competitive and the order is urgent. But what does the agent actually know about the supplier’s identity, the reliability of its data, the labour conditions behind the offer or the consequences of bypassing an established approval process?

If several agents rely on one another’s confident but unverified assessments, a local uncertainty can become a systemic decision. Each step may appear useful in isolation while the network drifts beyond its legitimate mandate. A technically competent system can act on weak, stale or selectively presented information, and can do so through chains of delegation that obscure where judgement, responsibility and authority actually reside.

This is a problem of emergence as well as control: agents interacting with one another can collectively behave in ways that were not apparent from the rules governing each individual system. As agents acquire information, build memories, invoke tools and coordinate with other agents, their combined behaviour cannot always be inferred from the permissions granted to each one at deployment. Circumstances can change faster than a fixed rule can be rewritten. Information may be incomplete, distorted by incentives or repeated until a recommendation is mistaken for verified knowledge. A system can execute its immediate task effectively while losing sight of the purpose that made that task permissible.

The transition from acquiring information to acting independently therefore deserves more scrutiny. What provenance – or evidence of the origin and reliability of information – does an agent have for what it claims to know? Which uncertainties remain unresolved? Has a recommendation become ‘knowledge’ merely because several agents repeat it? At what point is the agent entitled to spend money, alter a service, affect a person or commit an organisation to a course of action? The governance of intelligence must continue through the passage from knowledge to action – and through the consequences of that action.

At machine scale, human oversight alone cannot provide meaningful accountability. Governance must be built into the system, continuously testing whether AI agents still have sufficient grounds and legitimate authority to act. Credit: panumas nikhomkhai / Pexels


My A3 Model, developed as a framework for governing adaptive systems, treats this as a shift in the basic object of governance – in other words, what governance must concern itself with as systems learn and change. Its three elements operate simultaneously: Aram, or ethical coherence; Aanavam, endogenous systemic distortion, meaning distortion that develops within the system itself; and Adhikaram, legitimate agency that must be earned, remains conditional and can be withdrawn. Rather than operating as a conventional checklist, they condition one another as a system learns, acts and changes.

Ethical purpose must be tested against what a system can genuinely know and against the ways in which that knowledge may be distorted. The authority to act must be reassessed as those conditions change. In this sense, governance is not simply a set of constraints imposed before deployment or an investigation conducted after a failure but an ongoing judgement about whether the system still has sufficient grounds to act.

Aanavam matters especially at scale. Distortion can develop inside a successful system without a malicious prompt or external attack. A performance target can begin to substitute for the reason the system was deployed. One agent’s output can become another’s unquestioned premise. A monitoring dashboard can reward apparent completion while suppressing evidence of harm. As the number of agents and their connections increase, these effects can compound without any single agent visibly ‘going rogue’.

Adhikaram introduces a different question from whether an agent has technical permission to act: is its exercise of authority still justified here, given what it knows, the risks involved, the people affected and the purposes it is meant to serve? An agent may have the technical ability to place an order but lack adequate grounds to use that power when a supplier’s identity is uncertain. Its permitted scope may need to narrow. Its action may require independent corroboration. Or the matter may need to be escalated for a human decision.

Legitimate agency can expand when the evidence, conditions and mandate justify it. It can also contract or be withdrawn when the conditions that justified it no longer hold. That is different from a static access-control model. It treats authority not as a permission granted once but as a continuing institutional judgement.

At machine scale, this requires continuous monitoring and legitimacy gates within the operating architecture: checks that determine whether an agent still has sufficient grounds to exercise a particular authority. Institutions need evidence of what agents know, what remains uncertain, which tools and decisions they can reach, how their actions affect other agents and whether the grounds for their authority remain valid.

In practical terms, this means tying authority to evidence and consequence: verifying supplier identity before procurement authority is exercised; requiring independent corroboration before high-value or irreversible commitments; and automatically narrowing or suspending permissions when provenance weakens, conflicts emerge or an action could affect rights, safety or essential services. Higher-consequence actions should face stronger checks and clear escalation routes.

But an automated gate is only as legitimate as the knowledge and governing authority behind it. The institution must remain answerable for how it grants mandates, defines evidence thresholds, assigns accountability and decides when authority should be suspended. Governance cannot be outsourced to an automated control merely because the underlying system is automated.

The response to failure must also change the future system. Blocking one transaction or patching one route may contain an incident. Closure requires learning why that route became available, which assumptions failed, whose knowledge was missing and whether the institution’s own rules or authority structures need to change. That learning must be absorbed into future permissions, monitoring and governance. Otherwise, the network returns to service with the same deeper weakness intact.

Huawei’s forecasts may prove too high or too low. Their importance lies in the scale of the question they make visible. We are building systems able to communicate, remember, coordinate and act at unprecedented speed. We must build governance able to determine, before and during consequential action, whether an agent knows enough, remains ethically coherent and still possesses authority it has earned – and to reassess that judgement after its effects become known.

Vendan Ananda Kumararajah is an internationally recognised transformation architect and systems thinker. The originator of the A3 Model—a new-order cybernetic framework uniting ethics, distortion awareness, and agency in AI and governance—he bridges ancient Tamil philosophy with contemporary systems science. A Member of the Chartered Management Institute and author of Navigating Complexity and System Challenges: Foundations for the A3 Model (2025), Vendan is redefining how intelligence, governance, and ethics interconnect in an age of autonomous technologies.




READ MORE: Who let the bots out? The disturbing truth behind rogue AI. Recent reports of AI going rogue are alarming but, according to Vendan Ananda Kumararajah, they put a misleading focus on the machines rather than the institutions granting them authority. As autonomous systems gain more freedom to act, the solution to rogue AI lies in deciding where that authority begins, where it ends and when it should be withdrawn.

Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.

Main Image: Pixabay / Pexels

TOP STORIES

Who governs 900 billion AI agents?

TOP STORIES