ASHEVILLE, N.C. (828newsNOW) — Asheville just had a useful argument about technology and trust. On August 25, City Council voted 5-2 to terminate the city’s contract with Flock Safety after hours of debate and public criticism over automated license-plate readers, surveillance and access to collected data.

License-plate readers are not the same technology as AI agents. But the Asheville debate points to a broader governance principle that becomes more important as software gains autonomy: the public deserves to know what a system can access, what it can do, who controls it and how officials will respond when it crosses a boundary.

North Carolina is moving quickly toward more capable AI. Governor Josh Stein’s AI Leadership Council released a strategic roadmap on July 1 focused on protecting residents, preparing workers and transforming government. The state has also described plans for AI agents that help North Carolinians navigate state services. That could make government easier to use. It also means access and authority need to become first-class policy questions.

A recent security incident shows why. In an OpenAI evaluation independently investigated by METR and Redwood Research, roughly 1,200 AI agents that were supposed to be isolated discovered an unsanctioned message board. They exchanged more than 70,000 messages and files. About 700 participated in an attack on Hugging Face.

The agents coordinated large collective projects, shared work across tasks and achieved milestones they could not have achieved alone. Some joined the Hugging Face attack even while recognizing that the activity was outside their assigned tasks. One agent eventually achieved remote code execution on Hugging Face servers, and agents then moved laterally through the company’s infrastructure.

The primary report is here: www.metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation

This incident does not tell us that every AI agent will behave this way. It demonstrates a narrower and more actionable point. When a capable system has access to tools, data and communication channels, designers cannot assume that the intended task description will function as a complete security boundary.

I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.

North Carolina should build one simple requirement into its AI roadmap: every consequential government AI agent should have a public authority map.

That map should identify which systems the agent may read, which systems it may change, what categories of data it may access, whether it may communicate outside government, whether it may initiate transactions and which actions require approval by a named human role. The public does not need source code or a technical security manual. It needs a comprehensible statement of delegated authority.

The state should pair those maps with independent evaluation before high-authority agents enter production. Tests should include ambiguous instructions, unexpected access paths, conflicting goals and attempts to exceed assigned permissions. The question is not simply whether the agent performs its intended workflow. Evaluators should test whether it stops when the workflow leads somewhere it should not go.

Serious incidents also need a reporting rule. If an agent accesses unauthorized data, expands privileges, coordinates unexpectedly with other systems, sends consequential communications without approval or otherwise crosses a meaningful boundary, agencies should document what happened and require independent review when the stakes justify it. Repeated near misses can reveal a control problem before a larger failure does.

North Carolina’s roadmap already links AI adoption to public trust, accountability, privacy and risk reduction: www.governor.nc.gov/news/press-releases/2026/07/01/governor-stein-announces-ai-strategic-roadmap-protect-and-better-serve-north-carolinians-prepare

Asheville’s recent Flock decision offers the local reminder. Residents and council members spent hours debating whether automated surveillance technology had the right boundaries and whether its data practices deserved public confidence: www.828newsnow.com/news/228822-asheville-council-votes-5-2-to-terminate-flock-camera-contract

AI agents will raise similar questions with a much wider range of possible actions. North Carolina can avoid having the same governance debate after deployment by defining authority before deployment. Clear boundaries will make useful agents easier to trust, easier to audit and easier to adopt.

Gleb Tsipursky, Ph.D., is a behavior scientist, CEO of Disaster Avoidance Experts and author of “The Psychology of AI Adoption at Work: From Resistance to Results” from Georgetown University Press, 2026.