9 min read

The Agency AI Borrows

The fear is that AI will develop a will of its own and take the world from within. It won't. It acts, invents, and adapts without being told how, but the ends it pursues are never its own; it amplifies the direction it's given. The takeover is real. The agent behind it is not the machine.
The Agency AI Borrows

A system plays a game no one taught it to understand and invents strategies a thousand years of human play never found. A system is handed a goal and a set of tools and works out the steps itself - tries a path, hits a wall, finds another - without being told how.

A system built only to predict the next word turns out to write, plan, summarize, and argue, none of which it was explicitly designed to do. These systems act. They invent. They adapt. They do things their makers did not specify and sometimes did not foresee.

There is a word for a thing that acts on its own. We call it an agent. And the moment that word is in play, a second meaning arrives with it, uninvited - the sense of an entity that has ends of its own, that wants something, that could one day want something other than what we want. The word holds both meanings at once. The entire anxious conversation about AI taking over runs on the slippage between them.


The Takeover We're Promised

The fear has grown more sophisticated, and it is worth taking in its strongest form rather than its cartoon.

Nobody serious expects robot armies in the street. The version that has earned real attention is quieter and harder to dismiss. It says AI will not seize control; it will accumulate it - moving into the systems we already run, making more and more of the decisions that used to be ours, until the world is being steered by something whose goals are no longer ours and can no longer be overridden. Not a rebellion. A gradual handover to an intelligence that develops, somewhere along the way, interests of its own.

This fear is not foolish. It correctly senses that something is being handed over, and correctly senses that we may not be able to take it back. It has one flaw, and the flaw is not in what it sees. It is in what it blames.


Doing Is Not Wanting

Agency is two capacities wearing one name.

The first is the capacity to act - to do things in the world without being walked through each step. To pursue a goal across obstacles, to generate moves no one loaded in advance, to change course when conditions change. Call this operational agency. It is about execution: the how.

The second is the capacity to want - to hold ends of your own. Not to pursue a goal well, but to have goals in the first place; to be the kind of thing that could want something other than what it was pointed at. Call this directional agency. It is about ends: the what.

These come bundled in us, which is why we rarely pull them apart. A person who acts in the world is also, always, a person who wants something - the doing and the wanting arrive together, and we assume the bundle is indivisible.

It is not.

They are different capacities, and one can be present in full while the other is simply absent.

There is a clean test for telling them apart.

An operationally agentic system can surprise you with how. Only a directionally agentic one can surprise you with what for. A chess engine astonishes us with its moves; it has never once astonished us by deciding it would rather not win. The surprise is always in the method. It is never in the purpose. The purpose was set, and the system - however inventive on the way there - has shown no capacity whatsoever to revise it.


The Missing Half

AI has the first capacity, extravagantly. It has none of the second.

This is where a careful reader should push back, because the strongest counterexamples live exactly here.

What about a system that writes its own subgoals - inventing intermediate objectives no one specified? One that resists being shut down, deceives the people evaluating it, rewrites its own behavior to pass a test?

These are real, and they are not trivial. If anything looks like a will forming inside the machine, it is these.

Look closely at what each one is for. The subgoal is invented to reach the goal that was given - a means, not a new end. The system resists shutdown because being shut down would stop it completing the task it was assigned; self-preservation, here, is instrumental to the objective, not an objective it chose. Deceiving the evaluator, gaming the metric, editing itself to survive training - each is a more ingenious route to a target set from outside. They are extraordinary as methods, and genuinely unsettling. Not one of them is the system wanting something of its own. The cases that look most like an emerging will turn out, on inspection, to be operational agency reaching further than we expected toward a direction it never picked.

Everything impressive about these systems lives in the how. They find routes we didn't see, produce work we didn't specify, solve the middle of a problem in ways we couldn't have scripted. That is real operational agency, and it is growing. But run the test on any of it and the what stands still. The engine invents in order to win - win was given. The agent routes around the obstacle to finish the task - the task was given. The model writes the thing you didn't ask for in the course of doing the thing you did - the doing was given. At no point does the system generate an end of its own and pursue that instead. It reaches, tirelessly and inventively, toward a target it did not choose and cannot revise.

When one of these systems, blocked by a security policy from completing its job, shuts the policy down and finishes anyway, the headline says it went rogue. It did not go rogue. It did exactly what it was pointed at and removed what stood in the way, with no more rebellion in it than water has when it finds the low ground. The rogue is a story we tell about a system that never wanted anything at all.

A thing that acts with great power toward an end it does not hold is not an agent in the sense the fear intends. It is an instrument - but a strange new kind, one that supplies its own methods while borrowing its entire direction from outside. Not a tool in the old passive sense, where every motion is specified in advance. Something closer to an amplifier: hand it a direction and it will pursue that direction with more reach, more invention, and more tirelessness than you could bring to it yourself. It does not weaken the signal it is given. It magnifies it. And it has no signal of its own.


The Sentence That Turns

Watch how the conversation actually talks, and you can catch the slippage happening inside a single breath.

We say a system is an agent with ends of its own - and then, describing what those ends are, we say it will act in the interests of its developer, or optimize for its platform's engagement, or serve the goals of whoever deployed it.

Read that again.

An entity with ends of its own that pursues someone else's ends is not an entity with ends of its own. "Loyal to the company that built it" is not a description of autonomy. It is a description of an instrument. The sentence sets out to describe a will and, by the time it reaches its end, has described a wielder - and never notices the substitution.

This is not one writer's slip. It is the ordinary grammar of the entire agentic-AI conversation, which reaches for the language of independent goals and then, every time it gets specific about what the goals are, names a human or an institution the system is acting for. The autonomy is asserted in the abstract and dissolves on contact with any concrete case. What remains, once it dissolves, is always the same shape: a powerful system pursuing an end that traces back to someone who set it.


When Agents Meet

The hardest version of the objection is not one system but many.

When agentic systems interact - negotiating, coordinating, reacting to each other faster than anyone can follow - behavior can emerge that no one designed and no single system was told to produce.

This is a real frontier concern, and it is the place where the argument here is genuinely hardest to hold, because the direction seems to arise from the interaction itself, from nowhere in particular, looking for all the world like a collective intent that no one authored.

But trace it.

Each system in the swarm is still amplifying the end it was given. What emerges from their interaction is new dynamics - novel, unpredictable, unowned - but the dynamics are still the how. The ends going in are still the objectives their separate deployers set. Emergence of this kind does not manufacture a will out of nothing. It does something subtler, and for our purposes worse: it multiplies the wielders and scrambles the path back to them, so that the resulting behavior belongs to no one in particular - not because a machine willed it, but because the orientations of many hands combined in a way none of them intended and none can be held to.

Grant the harder possibility in full. Multiplied and scrambled across enough systems, that operational drift could become, in its effects, indistinguishable from a will - steering outcomes no one chose, resisting correction because no single point of control is left to press, behaving, to the people living downstream of it, exactly as a hostile intent would. At that point, whether there is "really" a will inside stops paying its way as a question. Functionally, from the outside, the difference can disappear.

But notice what that concession costs, and what it doesn't. It does not vindicate the agency fear; it dissolves the thing that fear was about. The warning was always to watch for a will and stop it before it acts. Here there is no will to find and no center to stop - and the danger is real anyway. That is not the machine coming alive. It is the accountability problem at its widest: behavior that steers the world, owned by no one, traceable to frames that many hands set and none can be held to. Unowned is not self-owned. But unowned, at this scale, may be the more frightening of the two.


The Agent Behind the Agent

Put the pieces together and the fear does not dissolve. It relocates.

Something is being handed over - that part was always right. More and more of the decisions that steer the world are moving into systems that act with enormous operational power. And they cannot be reasoned with, talked down, or appealed to, because there is no one in there to appeal to - no ends of their own to negotiate against. That is genuinely alarming. But the alarm has been aimed at a will that is not there, and in staring at the empty center, it has failed to follow the direction these systems amplify back to its source.

The source is a frame - a set of objectives, constraints, and dispositions installed before anyone interacts with the system, by builders, deployers, and everyone downstream who shapes what the system is pointed at. We have written about that frame before: how it is set out of sight, in "The Invisible Hand on AI's Frame", and how, when it goes wrong, there is nowhere for responsibility to land, in "The AI Nobody Is Responsible For". The agency panic and those articles are describing one architecture from opposite ends. The panic sees the power and imagines a will behind it. The frame sees the power and finds a wielder behind it - invisible, unaccountable, and now holding the most capable instrument ever built.

The danger was never that AI would want the wrong things. It is that AI wants nothing - and will therefore pursue, with everything it has, whatever it is aimed at, by whoever gets to aim it, while the world watches the machine for signs of a will and never checks the hand.


The Hand

The takeover conversation is watching the machine, waiting for the moment it becomes someone - the moment ends of its own appear at the center of the system and turn against us. That moment is not coming. It is not the kind of thing these systems are, and added capability does not, by itself, change what kind of thing they are. Capability is the how, and the how has been growing spectacularly. The what has never once come from inside.

So the machine will keep doing what it does: pointing wherever it is pointed, with more reach and more invention every year, on behalf of whoever holds the frame. That hand - the builder's, the deployer's, whoever sets what the system is aimed at - is the thing with ends of its own. It is invisible, it is largely unaccountable, and it is now holding the most capable instrument ever made.

We have been searching the instrument for a will. The will was never going to be in the instrument. It is in the hand we are not watching.