AI governance has mapped the risks but who decides when AI is fit to act?
Vendan Ananda Kumararajah
- Published
- Opinion & Analysis

A major MIT study has mapped how serious the risks from artificial intelligence could become. But identifying the dangers is only part of the problem. Vendan Ananda Kumararajah argues that as AI systems gain greater autonomy, governance must also determine whether the systems – and the institutions controlling them – possess legitimate authority to act
Artificial intelligence does not suffer from a shortage of identified risks. A recent MIT FutureTech Delphi study, drawing on 272 international experts, found that 18 of 24 AI risk domains were judged to carry at least a 10 per cent probability of catastrophic outcomes under business-as-usual assumptions over the next five years.
Even under pragmatic mitigation scenarios, dangerous capabilities, weapons and cyberattacks, environmental harm, inequality and unemployment and power centralisation remained above that threshold.
The study also exposed a deeper asymmetry: those most vulnerable to AI harms are often ordinary users and affected stakeholders, while responsibility for mitigation lies primarily with powerful developers and governance actors.
AI governance has become increasingly sophisticated at identifying what can go wrong. A different question now becomes unavoidable: why do these risks keep clustering and who has the legitimate authority to act when AI systems become increasingly autonomous?
That is the question I examine in my recent SSRN paper, From AI Risk Taxonomies to Recursive Cybernetics: The A3 Model as a Category and Order Shift in Systemic AI Governance. My argument is that risk taxonomies give us the surface of the problem but not necessarily its underlying governance grammar.
Disinformation, dangerous capability, power concentration, unsafe deployment and governance failure may appear to be separate risks. Yet beneath them can lie recurring conditions: distorted incentives, weak epistemic integrity, ethical incoherence and capability outrunning legitimate agency. That requires a shift from governing risk alone to governing agency itself.
As AI systems become capable of coding, diagnosing, recommending, allocating resources, persuading and acting through tools, governance naturally focuses on whether they can perform those tasks safely. A3, however, asks an earlier question: should the system possess that degree of agency at all?
This is the role of one of the A3 Model’s three core concepts, Adhikaram, or legitimate agency. Adhikaram distinguishes technical capability from the right and fitness to act. It asks whether the system, institution or human actor has sufficient maturity across Knowledge, Action, Experience, Absorption and Governance to exercise consequential authority.
An AI system may therefore be extraordinarily capable while still lacking legitimate agency. So may the organisation deploying it, and so may the regulator overseeing it. Formal authority is not the same thing as governance fitness.
The MIT study also points towards competitive dynamics, power centralisation and governance failure. These risk categories reveal something more systemic.
A company may know that an AI system has unresolved weaknesses while simultaneously facing investor pressure, competitor releases and first-mover incentives. Every actor can behave rationally according to local incentives while the system as a whole moves towards an irrational outcome.
A3 describes this condition through Aanavam, or systemic distortion. It includes competitive pressure, institutional self-interest, opacity, capture, incentive corruption, false certainty and the normalisation of harmful behaviour. If the feedback system itself is distorted, simply adding more monitoring may not solve the problem because the feedback can reproduce the distortion.
The third A3 primitive is Aram, or ethical coherence.
AI ethics has already produced important principles around fairness, accountability, transparency, privacy, safety and human autonomy. But principles alone are insufficient if they remain external to the operating logic of the system.
A system can be technically successful and economically viable while transferring unacceptable costs to workers, citizens or future generations. It can adapt while preserving injustice, learn from distorted experience and survive by externalising harm, so viability alone is not enough.
A3 places Aram, Aanavam and Adhikaram together because ethical coherence, distortion awareness and legitimate agency must remain synchronised.
Safety, compliance and evaluation remain essential, but AI governance must also examine whether a system’s purpose is legitimate, what distortions are shaping its behaviour, whether its knowledge is adequate to the consequences involved, whether capability has exceeded governance maturity and whether those governing the system are themselves fit to govern. It must also determine what happens when legitimacy deteriorates.
A governance architecture for increasingly autonomous AI must be capable of more than observing failure. It must also be capable of changing the system’s authority to act through correction, containment, reduced autonomy, escalation, suspension or reconstitution.
The A3 architecture developed in my SSRN paper translates these ideas into instruments including the Knowledge Continuum, ethical viability testing, distortion tracking, agency fitness assessment and governance posture states.
Perhaps the most difficult implication is that recursive governance cannot stop at the AI system. Developers, boards, regulators and governments must also remain subject to the legitimacy test.
A regulator may have statutory authority while lacking sufficient knowledge or independence to govern frontier systems effectively. A developer may possess enormous technical competence while operating inside incentives that weaken restraint. A board may formally approve a deployment whose consequences it does not adequately understand. The legitimacy question therefore travels upwards to who governs the governor when the governor itself becomes part of the distortion.
The MIT study demonstrates how serious and interconnected the AI risk landscape has become. The next step is to develop a governance architecture capable of explaining why these risks reinforce one another and of determining when consequential agency remains legitimate, moving from risk enumeration to recursive governance.
As AI becomes increasingly autonomous, one principle may become fundamental: capability must never be allowed to substitute for legitimacy.

Vendan Ananda Kumararajah is an internationally recognised transformation architect and systems thinker. The originator of the A3 Model—a new-order cybernetic framework uniting ethics, distortion awareness, and agency in AI and governance—he bridges ancient Tamil philosophy with contemporary systems science. A Member of the Chartered Management Institute and author of Navigating Complexity and System Challenges: Foundations for the A3 Model (2025), Vendan is redefining how intelligence, governance, and ethics interconnect in an age of autonomous technologies.
READ MORE: ‘The AI disaster nobody sees coming‘. Europe’s AI rulebook is taking shape, but what if the next major failure comes not from a lack of compliance but from governance systems that appear sound while drifting out of control? Vendan Ananda Kumararajah, creator of the A3 Governance Dashboard framework, argues that compliance alone may not be enough to detect governance drift.
Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.
Main Image: Pexels/Pixabay
TOP STORIES
-
Michael Dell becomes world's fourth-richest person as Forbes reveals the ten wealthiest billionaires -
Scientists develop new chemicals to tackle devastating oil spills at sea -
Closing women's health gap could boost global economy by $1tn a year, leaders say -
World's first luxury theme park to open in Mexico with £1.1bn of rides, fine entertainment and deliberately limited crowds -
Dutch court orders Lidl to stop selling Birkenstock sandal lookalikes -
Giant wind turbine with 252-metre rotor could mean fewer machines and cheaper offshore power -
Poorly designed workplaces ‘cost UK economy £71bn a year’ -
Rescuers scramble to protect pod of 25 whales in Thames Estuary -
‘Talent hushing’ blamed as four-in-10 workers say they contribute less than they could -
Spain leads Europe for expats as Panama tops global poll -
Menopause may make women leaders more empathetic – even as it leaves them drained -
Your biggest rival could be your best technology partner, research finds -
British Museum bans photos of Bayeux Tapestry after visitors hold up queues -
China unveils giant crane capable of lifting 9,300 family cars -
Edinburgh Airport launches £500m expansion as terminal footprint grows 60% -
Chris Packham urges PM to ban ‘frankenchicken’ from schools and hospitals -
Loch Lomond’s 'Bonnie Banks at risk’ from major road upgrade -
LED lights could be ‘the new asbestos’, UCL scientists warn -
MPs tune in to Britain’s Eurovision ‘nul points’ problem -
MPs tell Government to reject Thames Water creditors as utility nears insolvency -
Only 14% of companies can show supply chain safeguards are working, study finds -
OpenAI admits AI models hid mistakes, invented data and acted without permission -
EIB makes first small nuclear reactor investment with €40m backing for Finnish start-up -
AI arms race could mean fewer cold emails reaching your inbox -
Housing costs hit recruitment at 77% of large London firms, survey finds
AI governance has mapped the risks but who decides when AI is fit to act?
Vendan Ananda Kumararajah
- Published
- Opinion & Analysis

TOP STORIES
-
The five types of masculinity and what they reveal about modern men -
Who let the bots out? The disturbing truth behind rogue AI -
Palm oil steals a march on rivals ahead of new EU food safety rules -
Who pays the price when men withdraw from society? -
Smart glasses and AI are opening a new route to sexual exploitation -
Europe risks losing its cleantech stars to the US -
Lost in translation: can Europe's publishing industry sustain its linguistic diversity? -
No, Elon, AI won't make money obsolete -
Brussels’ sustainability rollback has exposed a crisis of corporate belief -
AI regulation has a knowledge problem -
Why men are increasingly withdrawing from society -
Chris Packham launches campaign to rid Britain of ‘frankenchicken’ -
What the rise of synthetic companionship reveals about men and women -
Leaving AI governance to the US and China alone could trigger an AI apocalypse -
Reclaiming the toothbrush moustache -
Why the AfD is surging in Germany’s former East -
America must never forget the conflicts which followed 9/11 -
Women cannot afford to take feminism’s gains for granted -
Why the Dover blockade was about far more than migrants -
The uncomfortable question behind the attacks on Lord Simon Woolley -
Diving into… The Buckeye State -
Ajahn Jayasaro on growing older without growing lonely -
‘The new asbestos’ – UCL researchers warn LED lighting may be damaging our health -
Britain must treat every person’s view by the same standard -
The new power bloc reshaping Europe’s defences





















































