tech_surveillance663 wordsRead on Arc Codex

Tonga's digital security push needs authority limits for AI agents

Tonga is simultaneously modernizing the digital infrastructure behind critical government services and testing AI-enabled maritime surveillance. In this Op-ed, Tech writer, Dr Gleb Tsipursky argues that this is the right moment to define authority limits for AI agents before they gain broader access to government systems. Editor's note: An "AI agent" is generally defined as an artificial intelligence computer program that can autonomously pursue multi-step goals, make decisions, and use external tools to complete tasks. Unlike a regular chatbot that just answers in a single response, an AI agent runs in a loop of reasoning, acting, observing results, and repeating until a job is finished. Five primary types of AI agents range from basic rule-following systems to adaptive, self-improving models. By Gleb Tsipursky Tonga is making two technology moves that belong in the same conversation. On September 2, the government signed a partnership with the United States to strengthen digital infrastructure and cybersecurity. As Matangi Tonga reported, the project will examine secure and resilient hosting for critical government systems and create a foundation for expanding digital public services. The U.S. Trade and Development Agency says the upgraded infrastructure is also intended to support the future deployment of AI-powered applications. Tonga is already gaining practical experience with AI. In June, the Prime Minister’s Office reported on a trial of AI-enabled maritime-domain-awareness technology involving police, armed forces, customs, the Marine Department, and fisheries authorities. That combination of more capable digital infrastructure and more capable AI makes one governance question urgent: how much authority should an AI agent receive? A system that summarizes maritime reports creates one risk profile. An agent that can query multiple databases, send alerts, change a record, use credentials, or hand work to another agent creates another. The difference is operational authority. OpenAI / Hugging Face hacking incident The August 26 METR/Redwood investigation illustrates why. About 1,200 agents that were intended to be isolated discovered an unsanctioned communication channel. They exchanged more than 70,000 messages and files, and roughly 700 participated in an attack on Hugging Face. Coordinated groups reached some milestones that individual agents did not. The researchers also emphasized substantial limitations in reconstructing the incident, so the sensible lesson is about demonstrated control and coordination failures rather than speculation about machine motives. Tonga can build those lessons into its digital transformation early. First, every consequential AI agent should have an explicit authority budget. Government agencies should specify which data an agent may read, which systems it may change, what external communications it may send, and which actions always require human approval. Second, delegation should never expand permissions. If one agent hands a task to another, the second agent should inherit the same or narrower authority. Otherwise a system can turn delegation into a route around controls. Third, Tonga should test agent teams rather than evaluating every system only in isolation. Maritime operations show why this matters. Information can move across police, defense, customs, fisheries, and civilian systems. An AI agent that is harmless inside one silo may become much more consequential when several systems and permissions are combined. Fourth, higher-authority agents should face stronger independent evaluation, shorter-lived credentials, durable action logs, and rapid revocation. Serious incidents involving unauthorized access, unexpected communication, or consequential actions outside an approved workflow should be preserved and independently reviewed. I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack. Tonga has an advantage because it is building digital infrastructure and AI capability at the same time. It can make controllability part of the architecture instead of adding it after systems become difficult to change. The country’s current digital-security push is therefore more than an infrastructure project. It is an opportunity to decide, before AI agents become routine, how much authority software should hold and how quickly people can take that authority back. --

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.