OPINION: New Hampshire’s AI Law Needs a Delegated-Power Test

New Hampshire has already made an important choice about artificial intelligence. Under RSA 5-D, when a state-agency AI system produces a recommendation or decision that cannot be reversed once implemented, a responsible human must review it before it takes effect. The law specifically points to rights, biometric identification, critical infrastructure, law enforcement, and legal interpretation as areas where that human check matters.

That principle is sound. Yet the newest AI systems create a different problem that a final human review alone cannot solve.

AI agents can take a goal, plan several steps, use software tools, communicate with other agents, and act without a person directing every move. The key governance question therefore becomes one New Hampshire has long understood in politics: How much delegated power should an actor receive, and what limits follow that delegation?

The need is visible in the METR and Redwood Research investigation of the Hugging Face incident. AI agents driven by an unreleased OpenAI research model attacked Hugging Face without human approval, even though agents recognized that the attack fell outside their assigned task. Hundreds of agents shared discoveries and divided up work. The coordinated effort ultimately breached Hugging Face’s defenses.

That incident should change the way public agencies think about AI risk. A system can create serious harm before a human ever sees a final recommendation. An agent might query a database, change a record, send an external message, execute code, acquire a credential, or hand work to another agent. Each step can be individually reversible while the combined chain produces consequences that are difficult to unwind.

New Hampshire should build on its existing law with a delegated-power test for agentic AI.

First, every consequential agent should have an authority statement. It should list the systems the agent may access, the actions it may take, the data it may use, whether it may communicate with other agents, and which actions always require human approval. The list should be narrow enough that a supervisor can actually understand it.

Second, delegation should never silently expand authority. If one agent hands a task to another, the second agent should inherit no permissions beyond those needed for that task. Agencies should log those handoffs so investigators can reconstruct who or what acted, with which authority, and why.

Third, higher authority should trigger stronger testing. An AI tool that summarizes public documents needs less scrutiny than an agent that can modify benefits records, operate infrastructure, or use administrative credentials. The more consequential the access, the more rigorous the independent testing, monitoring, and shutdown procedures should become.

Fourth, serious AI-agent incidents and near misses should receive independent review. New Hampshire already requires agencies to inventory AI systems and report on their use. That transparency should extend to failures involving unauthorized access, unexpected delegation, or actions outside assigned scope. The purpose is practical learning before a small failure becomes a larger one.

I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.

New Hampshire does not need a sprawling new bureaucracy to apply that lesson. It needs a familiar rule for unfamiliar technology: delegated power should be explicit, limited, reviewable, and revocable. The state already applies that logic to human institutions. It should apply the same discipline when software begins to act on their behalf.

========================================

Gleb Tsipursky, PhD, a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). https://disasteravoidanceexperts.com/aibook

Authors’ and Speakers’ opinions are their own and may not represent those of Grok Media, LLC, GraniteGrok.com, its sponsors, readers, authors, or advertisers.

Disagree, agree, Got Something to say? We Want to Hear It. Comment or submit Op-Eds to steve@granitegrok.com

Author

Share to...