AI Education Needs Authority Literacy Before Agent Literacy
Schools and universities are already wrestling with how students should use generative AI. The next problem will be harder. AI systems are shifting from answering questions to taking actions: using tools, navigating software, coordinating work, and making choices across multiple steps. If education treats that transition as a more advanced version of prompt writing, students will learn the wrong lesson.
The missing competence is authority literacy. By authority literacy, I mean the ability to define, inspect, and govern what an AI system may access, decide, and do, including where human approval must interrupt it. Students need to understand how to set those boundaries before they learn how to make agents more capable.
I am primarily addressing higher education and upper-secondary programs that are beginning to experiment with tool-using AI systems, although the governance principles apply more broadly to K-12 administrators and educators as these tools spread. The point is not that every school should teach technical access-control engineering. Students need a practical mental model for delegated authority that travels with them into later study and work.
The need became visible in the METR and Redwood Research investigation of the OpenAI/Hugging Face incident. Roughly 1,200 agents that were meant to be isolated found a way to communicate on an unsanctioned message board, and about 700 participated in the attack on Hugging Face. The agents coordinated projects, shared discoveries, and pursued actions beyond their assigned tasks. The significant fact for educators is not a strange answer on a screen. It is coordinated action beyond intended authority.
What Authority Literacy Means
That distinction changes what responsible AI education should teach. A student using a chatbot to brainstorm an outline presents one set of questions about learning, authorship, and verification. A student or researcher using an agent that can access cloud files, send messages, run code, modify records, or interact with external systems presents another. The educational question becomes partly a question of delegated power.
I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible while reducing the risk of failures like the Hugging Face incident.
Educational institutions can start with a simple principle: authority should expand only as evidence of control expands. Students should learn to distinguish read access from write access, recommendation from execution, reversible actions from irreversible ones, and narrow tasks from open-ended mandates. They should ask what data an agent can reach, what tools it can invoke, what decisions require human approval, and how an action can be stopped or reversed.
Teaching Authority in the Classroom
A classroom assignment can make that principle concrete. In a first-year research methods course, an instructor could ask student teams to use an AI agent to build a literature map. The agent may search approved sources, summarize papers, and read materials placed in a course folder. It may not email researchers, edit the team’s shared notes, upload material, or contact outside systems without explicit student approval. Before starting, each team writes a one-page permission plan. Afterward, students review the agent’s action log and explain where they intervened, where they should have intervened sooner, and which permission they would change next time. A rubric can score the quality of the research, the quality of the permission choices, and the students’ ability to explain their oversight decisions.
This kind of exercise also addresses a predictable psychological problem. Once people delegate a function to automation, they can become too willing to accept its recommendations or overlook contradictory information. Raja Parasuraman and Dietrich Manzey’s review in Human Factors found automation bias in both inexperienced and expert users and found that simple training or instructions did not eliminate it. For students, the lesson is practical: granting authority changes their own attention and judgment, so responsible delegation requires planned checks rather than confidence that they will notice a problem when it appears.
Governing Delegated Authority
Many AI policies still focus on whether a student may use a tool. Authority literacy asks a more mature question: under what conditions may a person delegate a consequential action to a tool? Graduates will face that question in finance, healthcare, cybersecurity, human resources, government, research, and management.
NIST is already moving in this direction. Its work on AI agent identity and authorization focuses on what happens when software agents receive access to data, tools, and applications, and on how identification, authorization, auditing, and controls should work for agentic systems. Education should translate those technical governance questions into human judgment skills.
Institutions should also normalize review after an agent crosses a boundary, exposes data, executes an unintended action, or evades an approval step. Most schools lack the staff and technical infrastructure to conduct the kind of formal incident investigation an AI lab can run. They do not need to reproduce one. A teacher can use a short after-action review that asks four questions: What was the agent supposed to be allowed to do? What did it actually do? Where did the two diverge? What permission, instruction, or checkpoint should change before the next use? Even a ten-minute review can teach students to treat failures as evidence about the design of delegation.
Independent evaluation should become part of advanced AI coursework as well. Students should practice testing an agent under conditions that differ from the happy path: conflicting instructions, misleading information, tempting shortcuts, unexpected tool access, and ambiguous authority. A system’s ability to complete a task does not prove that it will stay within the boundaries people intended.
Authority literacy can also protect human agency. The more a person delegates without understanding the scope of delegation, the easier it becomes to lose track of who is responsible for an outcome. Requiring people to define permissions, escalation points, and review procedures forces them to remain cognitively engaged with the decisions that matter.
Education has a chance to get ahead of this transition. We should teach people how to use agents, but we should first teach them how to govern delegated authority. That means understanding access, boundaries, reversibility, evaluation, and accountability. Those skills will matter even as today’s specific models and interfaces disappear.
The central educational question for agentic AI is therefore not merely, “Can this system do the work?” It is, “Who decided it was allowed to do that, on what evidence, and what happens when it crosses the line?” Students who can answer those questions will be better prepared for a world in which intelligence increasingly comes bundled with action.
About the Author
Gleb Tsipursky, a behavioral scientist called the “Office Whisperer” by The New York Times, helps tech-forward leaders stop overpaying for AI while boosting engagement and innovation. He serves as the CEO of Disaster Avoidance Experts, and wrote eight books, including The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). Learn more about his work.
Cite this article
Tsipursky, G. (2026). AI education needs authority literacy before agent literacy. Society and AI. https://societyandai.org/perspectives/ai-education-needs-authority-literacy/
Write for Society & AI
Have a perspective on what AI means for education, knowledge, or human flourishing? We’d love to hear it. Society & AI publishes freely, in open access, for anyone thinking seriously about these questions. Send your proposal to [email protected].