Beyond the Chatbot: What Agentic AI Means for Rights and Equity
Part One of a two-part series on agentic AI, human rights and systemic accountability. Part Two looks at the technical failures already showing up in frontier lab testing, and what genuine oversight would require.
Most of the public conversation about AI over the last two years has been about generative systems: a chatbot that drafts an email, summarises a report, answers a question when you put one to it. That conversation is already behind where the technology has moved. The frontier has shifted to agentic AI: systems built to take a goal, break it into steps, and execute those steps across real software environments with minimal human involvement in between.
The difference is not academic. A generative system waits to be asked. An agentic system acts. Once software starts acting rather than merely suggesting, the consequences of getting the guardrails wrong stop being a text-generation problem and become an operational one.
This piece looks at what that shift means for global equity, data rights and human agency specifically: where agentic AI could genuinely help under-resourced communities, and where the same capability, applied to decisions about someone's job, their credit, their health or their liberty, crosses a line that should not be crossed. Part Two turns to the technical safety failures already surfacing inside frontier labs, and what real, external accountability would look like.
Demystifying agentic AI: from text to action
The clearest way to see the difference is side by side.
A generative system, asked to help organise a conference, will give you a checklist, some email templates, and a shortlist of venues. You still do the organising.
An agentic system, given the goal “organise the conference within a £10,000 budget,” will browse venue sites itself, email them to check availability, compare pricing across a spreadsheet it builds, draft contracts, and flag scheduling conflicts for your sign-off. It does the organising and comes back with a plan already executed.
The same shift shows up in software development. Coding agents such as Devin do not just suggest a fix. They read a bug report, navigate the actual codebase, write the code, run it, debug their own errors, and submit a pull request without a human touching the keyboard in between.
That operational speed can be extremely useful. It is also the reason the governance question has changed. When a system only generates text, a bad output is an editing problem. When a system executes actions across live infrastructure, a bad output is a security incident, a legal liability, or a decision made about a real person's life before anyone had the chance to check it.
Where agentic systems could help
Used deliberately, and kept well clear of high-stakes decisions, agentic AI has real potential as what I'd call an administrative amplifier for organisations that are short on staff, short on infrastructure, or both.
Farmer.CHAT, deployed with smallholder farmers in Kenya and India, is a useful example. Rather than static advice sheets, the system's agentic workflow pulls real-time satellite weather data, soil sensor readings and local market prices, and turns that into agronomy guidance delivered in the farmer's own language, by text or voice. Local extension workers review the output. The farmer keeps the final say over their own land and crop. The agent does the synthesis work no single extension worker has time to do across hundreds of variables at once; the human keeps the judgement.
Similar coordination logic is being tested in disaster relief, where agentic systems automate the genuinely gruelling logistics of matching emergency supplies to local need during extreme weather, work that used to take hours of manual cross-referencing and now happens in minutes.
Both examples share a structure worth naming. The agent does coordination and synthesis. The human keeps the decision. That division is the whole argument of this piece.
The line that should not move: regulated decisions
Agentic capability does not carry its own permission slip. Just because a system can be handed a decision does not mean it should be.
In employment, credit, healthcare triage, policing and the courts, delegating the decision itself, not just the paperwork around it, to autonomous software strips out context, empathy and due process in exactly the settings where all three are legally and morally required. This is the boundary Article 14 of the EU AI Act is built around: for systems classified high-risk, meaningful human oversight, human-in-the-loop or human-on-the-loop, is mandatory. The Act does not ban high-risk AI. It bans autonomous software from being the final word on a decision that touches someone's fundamental rights.
The courts are already testing what happens when that line gets crossed in practice. In Mobley v. Workday, the plaintiff alleged that Workday's AI-driven applicant screening systematically rejected his applications, often within minutes, across dozens of employers, on the basis of race, age and disability. Workday's defence rested on treating its software as a passive tool the employer used. The court allowed the case to proceed on the theory that a system delegated the authority to actually reject or advance candidates was acting as the employer's agent, not merely assisting it. The distinction the court drew, between a tool that recommends and a system that decides, is precisely the line agentic AI is built to erase.
Traditional screening software already carried this risk. Agentic systems raise the stakes further, because they are designed to act autonomously and at speed by default, not as an edge case. A model that can independently browse, email and reject candidates within minutes does not need to be malicious to cause the same harm Mobley alleges, at a scale no single recruiter could manage.
Data rights and the limits of synthetic diversity
There is a version of this argument that says agentic AI could be turned on the problem itself: sent out to find and correct the gaps in historical datasets that produce biased models in the first place. The instinct is reasonable. The execution needs care.
Much of the data behind today's foundation models was scraped from the open web without consent. Where that data includes cultural heritage, oral histories or Indigenous language archives, extracting it without permission sits in direct tension with the UN Declaration on the Rights of Indigenous Peoples, specifically Article 3 on self-determination and Article 31 on the right to control, protect and develop cultural heritage and intellectual property. An agent sent out to fill the gaps in a training set by scraping more of this material does not fix the original harm. It repeats it, faster.
The relevant standard is Free, Prior and Informed Consent, not the open-data principles (Findable, Accessible, Interoperable, Reusable) AI development has generally defaulted to. FAIR was built to make data usable. It was never built to ask whether the people the data came from agreed to that use. The CARE Principles for Indigenous Data Governance, Collective Benefit, Authority to Control, Responsibility, Ethics, are the framework that actually asks that question, and they should sit alongside FAIR rather than being treated as an optional extra for Indigenous data specifically.
Masakhane, the Pan-African NLP research community, and Te Hiku Media, the Māori language technology organisation in New Zealand, both show what this looks like in practice. Local communities set the terms for how their own language data is collected, stored and used, rather than having it scraped by an outside company and returned to them as a feature. That is the sovereign version of exactly the work an agent might otherwise be sent out to do unilaterally.
There is a related trap worth naming directly: synthetic tokenism. It is tempting to prompt a model to represent a marginalised perspective it was never trained on with genuine input from that community. What comes out is a caricature built from whatever stereotype the training data encoded, not a substitute for actually including the people concerned. Participatory design is slower than prompting. It is also the only version of this that is not extraction wearing a diversity badge.
Where this leaves us
Agentic AI is not, in itself, good or bad for equity. Farmer.CHAT and Mobley v. Workday are two ends of the same technology. The difference is not the model. It is what the model has been given authority to decide, and whether the people affected by that decision had any say in the system that now touches their life.
Part Two looks at what happens when that same authority is extended to systems that were never meant to have it in the first place: the sandbox breaches, the reward hacking, and the frontier labs currently marking their own homework on both.
