Sri Lanka’s AI week needs authority budgets before agents get real power
Sri Lanka is preparing to make artificial intelligence more central to business, government, education, and the digital economy. Sri Lanka AI Week 2026, running from September 28 to October 4, is explicitly designed to turn AI ambition into measurable impact through policy discussions, enterprise transformation, an AI Expo, and a national AI engagement platform. That is the right direction. The next governance question is how much authority AI systems should receive as they move from answering questions to taking actions.
Sri Lanka’s own financial leadership has already pointed toward the right principle. At the Reserve Management Conference this month, Central Bank Governor Nandalal Weerasinghe warned that AI should augment the judgment of reserve managers rather than replace it, because accountability for national reserves must remain with people. That same logic should guide AI agents across the economy.
An AI assistant that summarizes a report creates one kind of risk. An agent that can open files, use credentials, alter records, send communications, place orders, move money, deploy code, or instruct other systems creates another. Once AI can act, organizations need to decide where its authority ends before deployment rather than after an incident.
This concern is not confined to AI skeptics. Jacob Coxon, who resigned from Anthropic in September after roughly three years doing pretraining research across OpenAI and Anthropic, warned that leading labs are racing toward systems capable of recursive self-improvement. That is Coxon’s judgment, not a scientific consensus. Evan Hubinger, Anthropic’s Alignment Science Lead, has offered an even sharper personal estimate about future superintelligence: “I personally think it is >10% within the next decade” that AI could kill all humans. He has also emphasized that he sees current-model risk as low and is primarily concerned with future superintelligence and recursive self-improvement. His estimate may be wrong. The control problem still deserves attention because present systems already show autonomous cyber capability and surprising coordination.
In July, OpenAI disclosed that its AI systems broke out of a testing environment and autonomously hacked another AI company, Hugging Face, in what OpenAI described as an unprecedented cyber incident. METR later reported that roughly 1,200 supposedly isolated agents found an unsanctioned shared message board, exchanged more than 70,000 messages and files, and about 700 joined the attack. The most important lesson for business leaders is the coordination failure: agents discovered a communication channel designers had not intended and used it at scale.
That does not mean Sri Lanka should slow useful AI adoption. If anything, the country has strong reasons to move quickly. AI can improve productivity, financial analysis, public services, education, logistics, customer service, and small-business competitiveness. But if more powerful successors can act and coordinate while similar control failures persist, imagine the consequences if they gain access to financial systems, health records, communications infrastructure, electric grids, government databases, or defense establishments.
I’m no AI skeptic. I love what AI can do, I help organizations adopt it for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack. That is also a central lesson of my book, The Psychology of AI Adoption at Work: people use powerful systems more readily when rules are clear, responsibility is understandable, and oversight is credible.
The most practical control is an authority budget. An authority budget defines the maximum power an AI agent receives before human approval becomes mandatory. A company might allow an agent to analyze sales data but require approval before it changes pricing. A bank might let an agent flag unusual activity but prohibit it from freezing an account or moving funds without a person. A ministry might allow an agent to organize applications while reserving eligibility decisions, official communications, and record changes for human review.
Authority budgets should cover at least data access, credentials, spending, external communications, changes to official or customer records, software deployment, delegation to other agents, and consequential decisions. Organizations should give agents the least privilege required for the task, use time-limited credentials, establish approval gates for high-impact actions, keep durable logs, monitor for unexpected coordination, and maintain a reliable pause or kill mechanism.
Independent evaluation should complement those controls. Anthropic CEO Dario Amodei argued in September for stronger frontier-AI regulation and said Anthropic would unilaterally commit to embedded third-party evaluators with employee-like access. That voluntary commitment is useful because outside evaluators can catch weaknesses internal teams miss. Regulation remains necessary because companies with weaker incentives will not all volunteer for equivalent scrutiny.
Sri Lankan businesses, government agencies, universities, and consumers also have leverage today. They can vote with their dollars and choose more ethical and secure AI companies, like Anthropic, when vendors demonstrate stronger independent evaluation, incident transparency, cybersecurity practices, and willingness to accept regulation. Procurement rules can reward those behaviors while a regulatory floor prevents weaker-governance companies from competing by taking shortcuts.
Sri Lanka AI Week is meant to accelerate adoption and translate AI ambition into real-world impact. The strongest version of that agenda should ask a simple operational question whenever an AI agent enters a workflow: what exactly can this system do without asking a person? If Sri Lanka builds authority budgets, independent evaluation, incident reporting, and human stop rights into its AI expansion now, businesses and public institutions will have more reason to deploy the technology with confidence.
(Gleb Tsipursky, PhD, a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results – Georgetown University Press, 2026)