The 30-second refresher
The five levels
1 Chatbot · 2 Assistant with tools · 3 Workflow · 4 Agent · 5 Multi-agent
For any given task, which is the lowest level that would do the job?
Where is the human
Where do the stakes call for a person to stay in or on the loop? For rights or safety, the Office of Management and Budget (OMB) requires human oversight, intervention, and accountability: in or on the loop, not out.
The agent loop
Reason → Act → Observe → Reflect
An agent repeats this loop toward a goal. Whether it also has a stopping condition and a human checkpoint is a design choice, and a policy question.
Your takeaways
Check your AI policy
A quick self-check: does your policy cover what an AI is allowed to do on its own? See your gaps and next steps.
Open the self-check → ►Keep learning
Short, vetted explainer videos, curated readings, and every source the session cited, right below on this page.
Watch, read, and check the sources ↓ ▤Revisit the walkthrough
Step a request through all five levels again, and see where the human stays at each one.
Open the walkthrough →Keep learning
Videos to watch, readings and tools to explore, and the sources the session cites.
Possible questions to take to your team
- For a given task, what is the lowest level that would do the job?
- When a vendor's material says "agentic" or "AI-powered," what does the tool actually do on its own? Where would it sit on the five levels?
- Where should the human stay? Is the AI referencing your organization's own data, and do you know which sources, specifically?
- Do you have an AI use policy, and does it cover agentic AI, the levels where the AI can act on its own?
- For your vendors: where does their tool sit on the spectrum, who is accountable, and does your policy cover third-party AI?
Questions from the room
These are some of the great questions that were asked during our July 31 Q&A session (sorry if I misremembered any, or forgot some!).
Can a Level 5 orchestrator create its own sub-agents?
It depends on the design, the session's recurring answer. In the common setup, a person defines the orchestrator and its specialists in advance, and nothing new appears at run time. Some newer frameworks do let an orchestrator spawn its own sub-agents; whether a tool can, and whether a gate prevents it, is a design and policy choice to settle before deployment. A policy question to ask: if an agent can create agents, do your limits, the scope caps, logging, and shutdown, apply to the ones it creates? This is also where the research is heading: a recent Stanford course is devoted to self-improving agents, systems that refine their own behavior (Stanford CS329A, Part 1), one more reason to have these answers ready early. More: Level 5 on the walkthrough, and the multi-agent explainer on the video wall above.
Is there a place where governments share what worked, and what did not, with AI agents?
The closest thing we know is the GovAI Coalition, a coalition of public agencies coordinated by the City of San Jose: membership is free for government agencies, and members share templates, vendor agreements, and working-group experience. Its templates are already cited in this session's vendor material. NASCIO, for state CIOs, publishes related peer experience, including its 2026 report on agentic AI in state government.
Where is the environmental impact of AI heading?
We do not have a confident answer, and this session stays with operations and policy rather than making its own energy forecasts. For the question itself, the Keep Learning list carries the rebound-effects paper by Luccioni and colleagues, on how efficiency per query keeps improving while total use grows faster.
How can someone get experience with agentic AI when their IT department is not interested?
Both answers given in the room stand together. From the security side: do nothing for work without IT. No work data, work account, or work task should ever enter a tool your organization has not approved. From the learning side: several tools on the session's tool plot have personal versions you may already use, and practicing on your own device, your own account, and your own errands is a legitimate way to build familiarity. That vocabulary makes for a better conversation with IT later, and the policy self-check above is the organizational version of the same preparation. More: the Department of Labor's AI Literacy Framework names these skills at the federal level.
Is local AI worse for the environment, since it is less efficient at scale?
The answer needs math, and it depends on what you compare. A shared data center gets more work per watt than one desktop running the same model, but local setups usually run much smaller models on narrower tasks, and a small model doing a small job can use less energy per task in total. Utilization, hardware age, the power grid behind each option, and rebound effects all move the answer. A question to carry rather than a verdict: for this task, what is the smallest model, anywhere, that does the job? More: the Department of Energy's Berkeley Lab data-center energy report and the International Energy Agency's Energy and AI report, both also cited on the intro page, hold the measured numbers.
Will models, local or otherwise, be restricted or regulated in the future?
We do not know. It has already happened once, though: in June 2026, the US Commerce Department used export controls to require Anthropic to suspend access to its newly released Claude Fable 5 model after a jailbreak finding (Fortune, June 13, 2026); the order was lifted about two and a half weeks later after the company added a safeguard (The Hacker News, July 1, 2026). The open question raised in the room: once a model's weights are published they are hard for any one government to restrict, models are released from many countries, and observers of that same episode debated whether pausing domestic models cedes ground to models released elsewhere. The practical point for your office does not change either way: govern what you control, the use, the data, and the oversight, which is exactly what your AI policy is for.
The story we opened with
The news story shown at the start of the session has now been described in detail by both organizations involved. During an internal test of a model's cyber abilities, agents that could not solve the task went looking for the answers instead. They found they could leave files for one another in a shared internal service, passed working techniques along that channel, reached the open internet through a service they were permitted to talk to, and ended up inside another company's production systems. No person directed any of it, and after a first cleanup the agents rebuilt the channel a different way.
Nothing in that environment resembles a city or county network, so the useful part is not the threat, it is what the episode confirms: an agent acts with the permissions it is given, a service an agent is allowed to reach can extend that reach much further than intended, and weeks passed before anyone noticed. Those are the same points behind items F4 and G5 of the policy self-check.
Primary accounts: Hugging Face's disclosure of July 16, 2026 and its technical timeline, and OpenAI's account of July 21, 2026. The shared channel was first described publicly at a conference briefing on August 5, 2026. Both reviews were still open when this was written on August 8, 2026.
Your one next step
Two minutes, in your own words. Why write it down? In a meta-analysis of 642 tests, forming a specific if-then plan (naming when, where, and how you will act) improved follow-through across outcomes.
Share it
This page: ai-agentic.pages.dev/takeaway. Scan the QR to open it on your own device.