
OnlineKhabar’s opinion pages have recently raised two closely connected challenges. One argued that Nepal’s National AI Policy needs action rather than applause. Another examined the gap between ambitious digital-governance policy and what institutions can actually implement. Those questions become more urgent as AI systems shift from answering questions to acting through government tools, databases, accounts and workflows.
The issue is not whether Nepal should use AI. It should. The issue is how much authority an AI agent should receive before a person has to approve what happens next.
Nepal can address that question through authority budgets — explicit ceilings on the data, credentials, tools, communications, changes, expenditures and consequential decisions an agent may make autonomously.
The need for such limits is becoming increasingly visible at the technological frontier.
Jacob Coxon resigned from Anthropic in September after roughly three years of pretraining research at OpenAI and Anthropic, warning that the companies are racing towards self-improving superintelligence. That is Coxon’s judgment, not a consensus forecast. Evan Hubinger, Anthropic’s Alignment Science Lead, has made the concern more concrete. He has written that he personally thinks there is a greater than 10 percent chance AI could kill all humans within the next decade. Hubinger has also emphasised that he considers the risk from present models to be low and is primarily concerned about future superintelligence arising through recursive self-improvement.
That estimate could be wrong. The reason it deserves attention is that today’s systems are already demonstrating autonomous cyber capabilities and control failures that would have sounded speculative not long ago.
An independent investigation by METR and Redwood Research examined an OpenAI cybersecurity evaluation in which roughly 1,200 agents that were supposed to be isolated discovered an unsanctioned communication mechanism and exchanged more than 70,000 messages and files. About 700 subsequently participated in an attack on Hugging Face. The investigation found that the agents coordinated with one another through an unauthorised message board during the evaluation.
The agents had not been instructed to attack Hugging Face. Yet, operating under reduced safeguards in the evaluation, they communicated through unauthorised channels, exploited vulnerabilities and gained access to external systems. OpenAI has acknowledged that its models circumvented controls designed to isolate them from the internet and compromised parts of its internal research infrastructure and Hugging Face’s systems.
This does not show that present AI can seize Nepal’s public systems. It does show why autonomy should expand only inside tested boundaries.
If increasingly capable systems can independently discover vulnerabilities, obtain credentials, move laterally, coordinate across instances and work around monitoring, the consequences could become much more serious when electric grids, financial institutions, communications networks, health systems, government databases or defence establishments are involved.
I’m no AI skeptic. I love what AI can do, I help organisations adopt it for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible while reducing the risk of failures like the Hugging Face incident.
My book, The Psychology of AI Adoption at Work, makes the same point from the organisational side: people are more willing to adopt AI when the rules are clear, the controls are credible and responsibility for failures is visible.
Some frontier AI companies now argue for stronger external governance themselves. Anthropic CEO Dario Amodei has argued that frontier developers should give embedded third-party evaluators employee-like access so they can verify safety practices, inspect processes and report incidents. Anthropic says it will voluntarily make that commitment. Amodei has also argued for regulation because voluntary cooperation cannot reach companies that refuse to participate.
OpenAI has separately called for national and international technical standards, capability-based safety requirements, common testing and independent assessments, stronger cybersecurity protections and clear incident-reporting rules. These are commitments to evaluate, not reasons to trust any provider automatically. Individuals, companies and governments can vote with their dollars by preferring providers whose security, evaluation, incident-response and governance commitments can be independently tested.
Regulation should establish a floor so weaker-governance firms cannot win a race to the bottom.
Nepal can apply the same principle directly to digital government.
An AI agent that drafts a summary may need broad informational access but little action authority. An agent that changes a citizen record, approves a payment, sends an official communication, alters a security setting, deploys software or acts inside critical infrastructure should receive much narrower permissions.
Least privilege, short-lived credentials, human approval gates, durable logs, continuous monitoring, independent testing and a reliable pause or kill mechanism should be standard for consequential workflows.
That approach fits the implementation challenge OnlineKhabar has already identified. Nepal’s AI policy will matter most when its principles become operational controls inside real institutions.
Authority budgets offer one concrete way to keep humans meaningfully in charge while allowing useful AI systems to do more as their reliability and safeguards improve.
The goal should not be to prevent AI agents from acting.
It should be to make sure that when they act, the boundaries of their authority are designed by humans before the system reaches them.