Original Work · Strategic Essay
Capability Without Surrender
Human-Centred Digital Governance and the Next Phase of Digital Transformation
August 2026 · Website Edition v1.1
Capability Without Surrender is an original strategic essay by Towseef Ahmed, exploring Human-Centred Digital Governance and the relationship between technological capability, human agency, legitimate authority and accountability.
The ambition should not be smaller AI. It should be greater capability without surrender.
For most of the digital age, progress has been measured by capability: faster computers, better networks, more data, more automation and more things that software can do for us. Artificial intelligence is accelerating that story.
Systems that recently produced mainly predictions, classifications or generated content can increasingly select tools, assemble plans, interpret context and act across digital environments. That is an extraordinary opportunity, and we should use it. A technology that can expand scientific discovery, improve public services, increase productivity, strengthen accessibility and reduce large amounts of routine work deserves serious adoption.
But as these systems become more capable, a quieter question becomes harder to avoid: who still gets to decide?
I have arrived at this question from several directions. Infrastructure and cloud made me think about dependence and resilience; security and identity about who is allowed to do what; programme governance about authority and accountability; digital sovereignty about whether formal choice remains meaningful under dependence. AI now brings these questions together. The technologies changed, but the underlying concern kept returning: capability can expand faster than the arrangements that determine who may act, who may decide and who remains answerable.
The right response to increasingly capable AI is not to retreat from technological progress. It is to ask what must grow alongside that capability. Every major technological transition creates both opportunity and governance problems. The internet expanded connectivity. Cloud computing expanded scale. Digital platforms expanded reach. As those technologies became important, societies developed stronger disciplines around security, privacy, resilience, identity and regulation.
Cybersecurity offers one useful analogy. It did not become important because societies decided to stop digitising. It matured because digital infrastructure had become too valuable to leave unmanaged. NIST’s Cybersecurity Framework is one example of how a technical discipline developed into a broader organisational risk and governance capability.[1]
The analogy has limits. Cybersecurity often begins with relatively stable goals: protect systems, data and services from threats. AI governance also asks more contested questions about who should possess power, which decisions may legitimately be delegated, whose rights constrain optimisation, when efficiency should yield to due process, and how institutions remain answerable for actions carried out through increasingly autonomous systems. Those are not only security questions. They are governance questions.
This essay begins from a simple proposition: AI capability should continue to advance, and human governance should advance with it. That is a normative proposition and a research agenda, not an empirical law. We should not assume that governance will automatically keep pace. The challenge is to design institutions in which greater technological capability does not progressively detach consequential action from meaningful human agency, legitimate authority and accountability.
I use Human-Centred Digital Governance as an integrative lens for that problem. The phrase itself is not new, and neither are the traditions beneath it. Human-Centred AI, Meaningful Human Control, Digital Humanism, Digital Constitutionalism, Digital Sovereignty, responsible AI, and established work on organisational decision rights, delegation and accountability already address important parts of this territory. The United Nations now uses closely related “human-centric digital governance” language.[2] The aim here is synthesis and translation, not invention.
Three questions organise the argument. Agency asks whether the relevant person or institution can meaningfully understand, choose, challenge, intervene or change course. Authority asks who legitimately possesses the right to decide or delegate. Accountability asks who must answer for the exercise of that power, to whom, on what evidence and with what consequences. Power complicates all three. It is not a fourth pillar of the argument, but a contextual condition that can strengthen or undermine whether agency and authority are exercisable in practice.
Three questions that organise the argument
- Agency
- Can the relevant person or institution meaningfully act?
- Authority
- Who legitimately has the right to decide or delegate?
- Accountability
- Who must answer for what happens, to whom, on what evidence and with what consequences?
These distinctions matter because they can separate. A person can have the practical ability to click “approve” without possessing the decision right behind that approval. A senior executive can hold formal authority while lacking the information or practical capacity needed to exercise it meaningfully. A technical system can have permission to execute an action even when that permission no longer matches the institution’s valid mandate. And an organisation can name an accountable owner on paper while lacking the evidence and review mechanisms needed to explain what actually happened.
The most plausible governance failure is therefore not necessarily a dramatic moment in which humans “hand authority” to machines. It may be a gradual accumulation of delegation: each step individually reasonable, yet together making it harder to say who decided what, under whose mandate, and who remains able to intervene.
These are not arguments against AI. They are arguments for becoming good enough at governance to use much more of it.
The ambition should not be smaller AI. It should be greater capability without surrender.
1. When Capability Outruns Governance
A familiar pattern appears whenever a useful technology arrives. A capability works, employees begin using it, customers ask for it, competitors move and leadership sees an opportunity. Deployment begins; governance catches up later.
Sometimes that is rational. Institutions cannot fully govern a technology they do not yet understand. The Collingridge dilemma has long described a related problem: early in a technology’s development, intervention is easier but consequences are uncertain; later, when consequences are clearer, the technology may already be entrenched and harder to change.[3]
AI brings this problem into unusually fast-moving organisational settings. The OECD’s 2026 Digital Government Outlook illustrates the unevenness. AI was already in use in at least one government function in 35 of 36 surveyed OECD countries. Yet only 14 of 36 required pre-deployment risk assessments, 12 had internal review committees and 11 conducted post-deployment audits.[4]
OECD Digital Government Outlook 2026
35 of 36surveyed OECD countries had AI in use in at least one government function.
- 14 of 36 required pre-deployment risk assessments
- 12 had internal review committees
- 11 conducted post-deployment audits
Those figures do not prove a universal “governance lag.” They show something more modest and more useful: adoption and governance capability do not automatically mature together.
A simple mental model is to imagine two curves. One represents capability; the other represents governance capacity. There is no reason they must rise at exactly the same speed. Governance often needs evidence, experimentation and institutional learning. But if the distance between them becomes too large, organisations may delegate consequential work faster than they can explain, constrain or reverse it.
The practical questions then become unavoidable. Who may delegate a task? What may a system decide or execute on its own? Which law, policy or organisational mandate supports that delegation? What happens when the context changes, or when the model changes? Who can intervene, what can be reversed, and who remains answerable afterward?
These questions are often treated as friction around innovation. A better possibility is to treat them as infrastructure for scale. An organisation that can define delegation, escalation, evidence, recovery and revocation clearly may be able to give AI more autonomy with greater confidence than one that cannot.
That proposition should be tested rather than assumed. But it points toward a different role for governance: not merely limiting capability, but making greater capability governable.
The shift matters because the technology itself is changing. Software has not suddenly started acting; automated systems have executed consequential actions for decades. What is changing is the flexibility and generality with which AI can move from producing outputs to taking action.
2. From Outputs to Action
Industrial control systems regulate machines. Trading systems place orders. Fraud systems block transactions. Enterprise applications trigger workflows. So the emergence of agentic AI should not be described as the moment software became an “actor.”
The more precise shift is from relatively predefined automation toward systems that can interpret goals, select tools, generate intermediate steps, react to results and continue pursuing a task across multiple systems. The OECD now treats agentic AI as a distinct policy and research topic, while current engineering practice distinguishes fixed workflows from systems that dynamically direct their own processes and tool use.[5]
The governance significance lies in the shrinking distance between recommendation and execution.
Consider a financial assistant that drafts an analysis. If the system makes a mistake, a human may detect it before anything happens. Now imagine the same system can determine which workflow applies, retrieve records, invoke an internal service, change an account field and send the resulting communication. The system has moved from producing information into participating in institutional action.
That changes the governance problem. When software produces an answer, quality and reliability dominate. When software can initiate or complete consequential actions, institutions also need to ask whether those actions remain inside a valid mandate. A system identity is no longer merely an IT account if it can commit a consequential action. An API permission is no longer merely a configuration detail if it enables financial, employment or public-service consequences. Even a prompt or policy file can become part of the architecture through which authority is translated into action.
None of this means a human should approve every tool call. That would often destroy the value of autonomy. The challenge is to decide, before execution, what may be delegated, how much discretion the system has, which exceptions require escalation, what evidence must survive, and how delegated authority can be suspended or revoked.
That is where the familiar phrase “human in the loop” becomes insufficient. A human somewhere in the workflow may be useful, and sometimes legally or operationally necessary. But human presence alone tells us very little about whether meaningful control exists.
3. Human Presence Is Not Human Control
Imagine a loan officer reviewing an AI recommendation. The system has collected the information, scored the application, highlighted risk factors and produced a recommendation. The interface presents two buttons: approve or reject. A human is clearly in the loop.
But is the human meaningfully in control?
Suppose the officer has little time, limited ability to interrogate the reasoning, organisational pressure to follow the recommendation and an escalation path that makes disagreement costly. The acceptance rate alone would prove nothing; the system might simply be performing well. The real question is whether the officer can exercise informed judgment when disagreement is warranted.
Human presence is not evidence of human control.
This distinction is well established. European trustworthy-AI guidance separates human agency from oversight and discusses human-in-the-loop, human-on-the-loop and human-in-command arrangements.[6] Meaningful Human Control scholarship goes further. Santoni de Sio and van den Hoven argue that control should not be reduced to constant intervention: system behaviour should appropriately track relevant human reasons, while responsibility must remain traceable to humans capable of understanding their role and recognising responsibility.[7]
The implication is simple: human presence is not evidence of human control.
A person can appear in an approval log while lacking meaningful influence. A manager can receive an alert while lacking time or information to act. A committee can review a dashboard while having no practical route to stop the system. Meaningful involvement requires more than a human-shaped checkpoint. It requires enough information, practical capacity and institutional support for intervention to matter.
It also requires authority. Agency asks whether a person or institution can meaningfully act; authority asks whether they are legitimately entitled to decide. Aghion and Tirole’s classic distinction between formal authority — the right to decide — and real authority — effective control over decisions — is particularly relevant here.[8] Their work shows that formal decision rights and actual control can separate because of information, overload, urgency and organisational structure. AI can intensify that separation: a senior executive may formally own a decision domain while an opaque or rapidly operating system acquires much of the practical influence over what happens, while an employee may have the technical ability to intervene without the authority to make the decision.
This is also why more automation does not necessarily mean less human control. Shneiderman’s Human-Centered AI work explicitly rejects a simple one-dimensional trade-off between automation and human control.[9] A procurement agent, for example, could compare approved suppliers, request quotations and execute routine orders within an authorised threshold while being unable to add a supplier, exceed a limit, bypass a conflict rule or alter procurement policy. Unusual cases can escalate, actions can remain reviewable, and delegated authority can be revoked.
In that arrangement, the system may be highly autonomous inside its domain while the institution retains strong control over the domain itself. Human control at scale often moves upstream into purpose, mandate, boundaries, delegation, monitoring, escalation, revocation and review.
The goal is not maximum human contact. It is meaningful human governance.
And that leads to the central distinction in this essay: capability is not authority.
4. Capability Is Not Authority
Imagine an AI agent inside a large organisation. It has an identity and credentials. It can read customer records, call an internal API, create a refund, send an email and change a case status. Technically, it is capable. Administratively, it may be permitted.
But who gave it the legitimate right to decide that this particular action should happen?
Capability describes what a system can do. Permission describes what the technical environment currently allows. Authority concerns the recognised basis from which a decision right or mandate is derived.
These categories often align. A system administrator may grant access because an authorised business owner requested it. A policy engine may permit an action because an approved rule allows it. Technical permission can therefore be a valid expression of institutional authority. The governance problem appears when the two stop matching.
Suppose a manager may approve refunds up to a defined amount and delegates routine cases to an AI agent. The API available to that agent technically supports larger refunds because several teams use the same service. The system now possesses more executable permission than the manager had authority to delegate. Nothing may go wrong for months. Then a model update changes classification behaviour, a new workflow expands the use case, or temporary permissions remain after an incident. The technical ability to act has changed; the mandate may not have.
I use permission–authority gap as shorthand for that possible mismatch between executable technical permission and valid institutional mandate in context. The phrase is not intended as a new theory. It connects mature traditions that become increasingly important when machine execution is flexible and fast.
From mandate to execution
- 01Legitimate Mandate
- 02Delegation
- 03Technical Permissioninstitutional mandate ends · technical capability begins
- 04AI Execution
- 05Review / Accountability
Weill and Ross describe IT governance in terms of deliberately designed decision rights and accountability.[10] Fama and Jensen separate decision initiation, ratification, implementation and monitoring, showing that complex organisations have long distinguished different functions inside the decision process.[11] Principal-agent and delegation theories likewise examine what happens when one actor acts on behalf of another. AI does not erase this history. It makes the connection between institutional authority and technical execution easier to lose.
That is why legitimacy matters. Human origin alone does not make authority legitimate. A human decision can be biased, corrupt, unlawful, arbitrary or outside the person’s mandate. Authority may derive, depending on context, from law, democratic institutions, organisational governance, fiduciary duty, professional responsibility, contract, informed consent or other recognised sources — and those sources may themselves be constrained by rights, procedure and review.
The relevant question is therefore not “was there a human?” It is “what made this exercise of power legitimate, and does the machine’s execution still fall within it?”
This is especially important in government. A public agency may use AI to support or automate statutory functions, but automation does not answer how far public authority may be delegated, what discretion must remain reviewable, what reasons must be available, or how an affected person can challenge the result. Public-law scholarship is already examining exactly this boundary.[12]
The stronger governance requirement is therefore provenance of authority: the ability to show where a decision right came from, who or what institution possessed it, what was delegated, for which purpose and duration, under which law, policy or role, how much discretion was included, and how that delegation can expire or be revoked when the model, policy or context changes.
The relevant question is not “was there a human?” It is “what made this exercise of power legitimate, and does the machine’s execution still fall within it?”
If institutions are going to delegate more action to machines, they need to preserve the connection between execution and the authority under which it occurs.
But valid authority does not complete the governance problem. The exercise of power must still be answerable.
5. Accountability Must Be Exercisable
Consider a consequential AI-enabled outcome. A person starts the process, a model interprets the request, a retrieval system supplies context, another model recommends an action, an agent chooses a tool, an API changes a record and a downstream workflow applies the consequence. The result reaches a customer, employee, patient, citizen or supplier.
Then something goes wrong. Who is accountable?
Naming the organisation may be legally correct, but practical accountability requires more than assigning an owner on paper. Mark Bovens describes accountability as a relationship between an actor and a forum: the actor must explain and justify conduct, the forum can question and judge it, and consequences may follow.[13] Busuioc applies this institutional problem directly to AI in public administration.[14]
That broader account matters because evidence alone is not accountability. An organisation can log everything and still fail to provide meaningful explanation, contestation or remedy. At the same time, accountability becomes difficult to exercise when evidence of the relevant process has disappeared.
This is where reviewability becomes important. Cobbe, Lee and Singh treat automated decision-making as a socio-technical process and argue for contextually appropriate records that allow the process as a whole to be reviewed.[15]
Two practical conditions therefore need to coexist. Accountability must be assigned: someone or some institution is answerable. And enough reconstructable evidence must survive for that accountability to be exercised. The second condition does not create accountability by itself; it supports it.
A meaningful accountability architecture therefore connects a responsible actor to a competent forum and preserves enough evidence for questioning, explanation, contestation, judgment and, where appropriate, correction, consequence or remedy. The relevant record is not every possible log. It is the evidence necessary to understand what governed the action, which material information shaped it, what authority supported execution, what the system actually did, who owned the outcome, and whether the affected person can challenge or reverse it.
There is a risk on the other side. More monitoring and more logs can become tools of worker surveillance or internal blame shifting rather than accountability to affected people. Human-centred governance therefore has to ask who controls the record, who may inspect it, what is proportionate to retain and whether the evidence serves meaningful review rather than merely institutional self-protection.
Governance cannot be reduced to technical architecture because power over the evidence is itself power.
And even an accountable institution can lose practical control if dependency removes its ability to change course.
6. Choice Without Exit
Digital systems often provide formal choice. Contracts can be terminated, providers can be changed, data can be exported, platforms can be left and models can be replaced — at least in principle.
Practical reality may look different.
Suppose an organisation builds its core AI operations around one provider. Its data pipelines, APIs, governance controls, staff skills, evaluation methods and historical context all become tightly coupled to that platform. The organisation still has a formal right to move. But if migration would take eighteen months, disrupt critical services and require expensive re-engineering, how much practical freedom does that right provide?
This problem has deep intellectual roots. Hirschman’s Exit, Voice, and Loyalty distinguishes leaving an organisation or product from trying to change it from within.[16] Switching-cost and lock-in economics similarly show how incompatibility, network effects and switching costs can bind customers to vendors even when alternatives formally exist.[17]
That lineage helps refine the argument. Exit matters, but it is not always the right governance mechanism. A citizen should not need to leave a welfare system to obtain justice. An employee may not realistically be able to leave an employer. A patient cannot always shop for another public health system. In those settings, voice, contestability, rights, collective representation, regulation and remedy may matter more than exit.
The common principle is not that everyone must be able to leave everything. It is that formal choice becomes weak when the practical capacity to act has disappeared.
At an individual level, that may mean the ability to contest, refuse or move data. At an organisational level, it may mean portability, interoperability, substitutability and recoverability. At state level, it may involve strategic dependencies across compute, cloud, semiconductors, data, model ecosystems and critical infrastructure. These are not the same problem at different sizes; they are different forms of dependency that can constrain the practical exercise of agency or authority.
The EU Data Act’s cloud-switching provisions address one concrete part of this landscape by reducing barriers to switching data-processing services.[18] But portability alone does not create sovereignty, and multi-cloud architecture does not automatically create strategic autonomy.
The more useful question is narrower: does the relevant actor retain enough practical capacity to change course?
That question connects dependency to governance without turning sovereignty into self-sufficiency. It also exposes a larger point. “Human-centred” cannot refer to one undifferentiated human. Different people and institutions possess different rights, powers and interests, and those interests frequently conflict.
7. Human-Centred Governance Across Levels
When someone says technology should remain human-centred, the obvious question is: which human? The user, employee, customer, executive, citizen, regulator and wider public do not always want the same thing.
A useful map is to examine connected levels: the person, the organisation and the wider public order, within which society and the state need to be distinguished. The levels themselves are not new. Multi-level scholarship already analyses AI governance across individual, organisational and societal levels.[19] The useful work lies in the relationships and conflicts between them.
Connected levels
- Person
- AgencyRightsVoiceRemedy
- Organisation
- AuthorityDelegationAccountability
- Society / State
- LegitimacyPublic powerRightsSovereignty
The Person
At the personal level, agency, rights, voice and remedy are often central. A meaningful human-centred test asks whether a person can understand enough to make a meaningful choice, contest a consequential decision, refuse or correct something where appropriate, and obtain remedy when exit is unrealistic.
The Organisation
At the organisational level, authority, delegation and accountability become especially visible. The relevant questions concern who may decide and delegate, what discretion may be automated, who may change the rules or accept risk, who can suspend the system, and which evidence must survive so the organisation can later explain what happened.
Society and the State
The wider public order contains at least two different dimensions. Society raises questions about platform power, inequality, collective interests, democratic norms and the distribution of benefits and harms. The state raises questions about constitutional authority, statutory delegation, administrative law, public accountability, coercive power and strategic dependency. Those categories should not be collapsed.
What connects these levels is not a single universal form of control. A more defensible common denominator is the practical capacity of a legitimately empowered actor to make, challenge or implement consequential choices under conditions shaped by digital systems and dependencies.
That still leaves conflict. Employee agency can conflict with enterprise security; corporate autonomy can conflict with consumer rights; state technological autonomy can conflict with interoperability or individual liberty. Human-centred governance does not make those conflicts disappear. It should make them visible and force institutions to confront how they are being resolved.
That is also why the essay cannot ignore power. Authority and power are not identical. A platform can acquire enormous practical power without public authority. A government agency can possess legal authority while lacking technical capacity. A worker can have formal rights while lacking practical bargaining power. A company can retain contractual freedom while dependency leaves it with little room to act. Power is therefore not a fourth element beside Agency, Authority and Accountability; it is part of the context that determines whether those ideas are real in practice.
Human-Centred Digital Governance must also govern the governors. Governance itself allocates power: it determines who may deploy, who may override, whose evidence counts, who can challenge a boundary and whose definition of acceptable risk becomes authoritative. Public law, digital constitutionalism, institutional governance and democratic accountability therefore remain essential companions to technical AI governance.
Consider a public agency using an AI system to administer routine benefit renewals. At the personal level, the citizen needs understandable notice, contestability and remedy. At the organisational level, the agency needs a lawful mandate, bounded delegation, escalation rules, reviewable evidence and a responsible owner. At the state level, procurement choices may create dependency on infrastructure or models outside the agency’s control, while public law determines which decisions may be automated and which rights constrain the process.
One system can therefore connect all three levels. That is the kind of relationship Human-Centred Digital Governance should make easier to see.
8. Guardians of Human Authority
The next generation of digital-transformation leaders will not be judged only by how much they automate. They may also be judged by whether their institutions can explain what a system is allowed to do, under whose authority, within what limits and who remains answerable afterward.
By “Guardians of Human Authority,” I do not mean defending decisions simply because humans made them. Human origin does not create legitimacy. I mean preserving the conditions under which legitimate human and institutional authority remains meaningful, bounded, exercisable and accountable as more execution is delegated to machines.
This is not the responsibility of one profession. Engineers, lawyers, risk and security teams, boards, policymakers, workers and affected communities all see different parts of the problem. The aim is not to create a new caste of AI governors, but to recognise stewardship of legitimate authority as an institutional responsibility.
A guardian of human authority does not own the authority they help preserve. The role is stewardship: keeping legitimate authority connected to mandate, boundaries, intervention and accountability as execution becomes increasingly automated.
The goal is not maximum human contact. It is meaningful human governance.
That distinction is especially important in government. Public institutions administer benefits, issue licences, collect taxes, inspect businesses, allocate services and enforce regulations. AI may improve many of those functions, but efficiency does not create legitimacy. An automated system can be accurate while being used under the wrong mandate; it can be efficient while providing poor contestability; it can save money while making responsibility harder to exercise.
The EU AI Act provides one concrete example of the direction of travel. Article 14 requires high-risk AI systems to support effective human oversight, including the ability, as appropriate, to understand relevant capabilities and limitations, monitor operation, recognise automation bias, interpret outputs, disregard or override them, and intervene or stop the system. Article 26(2) places a corresponding obligation on deployers of high-risk AI systems: human oversight must be assigned to natural persons with the necessary competence, training and authority, as well as the necessary support. For the narrower Annex III point 1(a) biometric-identification context, Article 14(5) adds a separate two-person verification requirement, subject to the stated exception.[20]
This is more precise than saying “keep a human in the loop.” It recognises that oversight must have operational substance.
Stewardship also requires humility about governance itself. Because governance allocates power, governance needs its own checks. And the ability to build those checks is not evenly distributed. A global company may be able to fund internal assurance teams, portability engineering and sophisticated monitoring; a small public agency, an SME or a lower-capacity state may not.
If strong governance becomes a prerequisite for safely using advanced AI, unequal governance capacity could widen the gap between institutions that can exploit AI confidently and those that cannot. Shared standards, public-sector capability building, reusable assurance infrastructure, pooled expertise and proportionate governance therefore matter.
The goal is not merely to demand better governance. It is to make good governance achievable.
9. Preparation Before Dependence
Nobody knows exactly how capable AI will become over the next decade. Technical bottlenecks may slow progress. Economic constraints may reshape deployment. Regulation may change incentives. New architectures may develop differently from today’s expectations.
That uncertainty should remain explicit. But uncertainty is not the same as ignorance.
We already know that institutions take time to change, professional capabilities take time to develop and architectures become harder to alter after dependencies deepen. The Collingridge dilemma captures the tension: early action is difficult because knowledge is limited; later action is difficult because systems may already be entrenched.[3]
AI adds another complication because model and product cycles can move on timescales very different from institutional and regulatory change. Governance may not simply “catch up” through good intentions. Coordination, standards, shared infrastructure, regulation and professional capability all matter, and some questions will remain unresolved even as deployment continues.
The Stanford Digital Economy Lab’s 2026 We Must Act Now statement is one example of a preparedness argument: at its July launch, sixteen Nobel laureates and more than 200 economists and AI researchers backed a call to build research, policies and institutions before potentially larger economic effects become fully visible.[21] That statement does not prove what the next decade will bring, and neither does any industry leader’s forecast.
The stronger case for preparation is simpler. Clear decision rights, reviewable systems, contestability, portability, recovery and institutional competence are useful now. They become more valuable if AI advances rapidly, but they are not wasted if progress is slower.
Preparation is therefore not prediction. It is preserving options before dependence makes them expensive.
Capability and Control Can Rise Together
The optimistic future is not one in which humans perform every consequential action. Nor is it one in which machines are allowed to act without a valid mandate simply because they are capable.
A better future is one in which institutions become good enough at delegation that machines can do much more.
Imagine a public-service agent handling routine benefit renewals. It processes most cases automatically under a clearly defined statutory and organisational mandate. Routine actions happen without case-by-case human approval, while unusual cases escalate. People affected by consequential decisions receive understandable notice and can challenge the outcome. The agency can reconstruct the relevant decision path, a responsible forum can review it, the system’s permissions can be suspended, its delegated mandate can expire, and the service can continue if a provider or model changes.
That is not humans manually controlling AI. It is governed autonomy: the machine has room to act because the institution has become clearer about purpose, mandate, boundaries, evidence, accountability and recovery.
This is the sense in which capability and control can rise together — not as a law of technological progress, but as a design ambition, an institutional test and a research programme.
I do not see this essay as a finished model. I see it as a statement of direction. Some of the questions here may develop into formal research; others may become governance models, architectures, policy approaches or products; some may need to change as evidence and practice evolve. What I want to keep testing is the proposition underneath them: can technological capability keep expanding without weakening the human and institutional capacity to govern what that capability is allowed to do?
Digital transformation has spent decades expanding what technology can do. The next phase may be defined by whether people and institutions can expand the quality of governance alongside it.
The future worth building is not one with less machine capability. It is one in which greater capability remains connected to meaningful agency, legitimate authority and accountability.
Capability without surrender.
Endnotes
- Cherilyn Pascoe, Stephen Quinn and Karen Scarfone, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (National Institute of Standards and Technology, 26 February 2024), https://doi.org/10.6028/NIST.CSWP.29. ↩
- United Nations, “UN Appoints Joseph Gordon-Levitt as First Global Advocate for Human-centric Digital Governance,” 17 March 2026, https://www.un.org/sustainabledevelopment/blog/2026/03/press-release-un-appoints-joseph-gordon-levitt-as-first-global-advocate-for-human-centric-digital-governance/. ↩
- Audley Genus and Andy Stirling, “Collingridge and the Dilemma of Control: Towards Responsible and Accountable Innovation,” Research Policy 47, no. 1 (2018): 61–69, https://doi.org/10.1016/j.respol.2017.09.012. ↩↩
- OECD, Digital Government Outlook 2026: From Foundations to Transformational Impact (Paris: OECD Publishing, 2026), chap. 4, “Adopting and Governing AI in Government,” https://doi.org/10.1787/0496b2bc-en. ↩
- OECD, The Agentic AI Landscape and Its Conceptual Foundations, OECD Artificial Intelligence Papers no. 56 (13 February 2026), https://doi.org/10.1787/396cf758-en; Anthropic, “Building Effective Agents,” 19 December 2024, https://www.anthropic.com/engineering/building-effective-agents. ↩
- European Commission High-Level Expert Group on Artificial Intelligence, Ethics Guidelines for Trustworthy AI (2019), https://doi.org/10.2759/346720. ↩
- Filippo Santoni de Sio and Jeroen van den Hoven, “Meaningful Human Control over Autonomous Systems: A Philosophical Account,” Frontiers in Robotics and AI 5 (2018): 15, https://doi.org/10.3389/frobt.2018.00015. ↩
- Philippe Aghion and Jean Tirole, “Formal and Real Authority in Organizations,” Journal of Political Economy 105, no. 1 (1997): 1–29, https://doi.org/10.1086/262063. ↩
- Ben Shneiderman, “Human-Centered Artificial Intelligence: Reliable, Safe & Trustworthy,” International Journal of Human–Computer Interaction 36, no. 6 (2020): 495–504, https://doi.org/10.1080/10447318.2020.1741118. ↩
- Peter Weill and Jeanne W. Ross, IT Governance on One Page, MIT Sloan Center for Information Systems Research Working Paper no. 349 (30 November 2004), https://cisr.mit.edu/publication/MIT_CISRwp349_ITGovOnOnePage. ↩
- Eugene F. Fama and Michael C. Jensen, “Separation of Ownership and Control,” Journal of Law and Economics 26, no. 2 (1983): 301–325, https://doi.org/10.1086/467037. ↩
- Oliver Butler, “Algorithmic Decision-Making, Delegation and the Modern Machinery of Government,” Oxford Journal of Legal Studies 45, no. 3 (2025): 727–752, https://doi.org/10.1093/ojls/gqaf018. ↩
- Mark Bovens, “Analysing and Assessing Accountability: A Conceptual Framework,” European Law Journal 13, no. 4 (2007): 447–468, https://doi.org/10.1111/j.1468-0386.2007.00378.x. ↩
- Madalina Busuioc, “Accountable Artificial Intelligence: Holding Algorithms to Account,” Public Administration Review 81, no. 5 (2021): 825–836, https://doi.org/10.1111/puar.13293. ↩
- Jennifer Cobbe, Michelle Seng Ah Lee and Jatinder Singh, “Reviewable Automated Decision-Making: A Framework for Accountable Algorithmic Systems,” in Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency (FAccT ’21), 2021, https://doi.org/10.1145/3442188.3445921. ↩
- Albert O. Hirschman, Exit, Voice, and Loyalty: Responses to Decline in Firms, Organizations, and States (Cambridge, MA: Harvard University Press, 1970). ↩
- Joseph Farrell and Paul Klemperer, “Coordination and Lock-In: Competition with Switching Costs and Network Effects,” in Handbook of Industrial Organization, vol. 3 (2007), 1967–2072, https://doi.org/10.1016/S1573-448X(06)03031-7. ↩
- European Commission, “Data Act Explained,” including Chapter VI on switching between data-processing services, https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained. ↩
- Simon Sturm, Florian Krause and Benjamin van Giffen, “Beyond Control? Governing AI in Organizations for Responsible Use,” European Management Journal, published online 26 June 2026, https://doi.org/10.1016/j.emj.2026.06.003. ↩
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), arts. 14 and 26(2), consolidated text 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng. Article 14 sets human-oversight design and intervention requirements for high-risk AI systems; Article 26(2) requires deployers to assign oversight to natural persons with the necessary competence, training and authority, as well as the necessary support. ↩
- Stanford Digital Economy Lab, “‘We Must Act Now’: Sixteen Nobel Laureates Join Leading Economists and AI Researchers in Call to Prepare for AI’s Economic Transformation,” 13 July 2026, https://digitaleconomy.stanford.edu/news/wemustactnow/. ↩
Suggested Citation
Ahmed, Towseef. 2026. Capability Without Surrender: Human-Centred Digital Governance and the Next Phase of Digital Transformation. Strategic Essay, Version 1.0, August 2026.
