Taxonomy Confusion Is Leaving Agentic AI Governance Without a Foundation
What happened
The Center for Strategic and International Studies (CSIS) released Lost in Definition: How Confusion over Agentic AI Risks Undermines U.S. Governance Frameworks in January 2026. The paper identifies a foundational problem: agencies, vendors, and oversight bodies are using the word "agentic" to describe systems with very different levels of autonomy, authority, and risk. Without a shared vocabulary, procurement teams cannot compare what they are buying, red-teamers cannot scope what they are testing, and accountability cannot be assigned when something goes wrong. CSIS proposes a relational taxonomy that classifies AI agents by three attributes: where they sit in a workflow, how much authority they have been delegated, and who is accountable for their actions. The paper connects this framework directly to defense procurement, pre-deployment evaluation, and oversight controls for systems that plan, act, or use external tools. The argument tracks closely with concerns raised in 50,000 Agents in Two Weeks: GenAI.mil Exposes Scale vs. Governance Gap, where rapid government agent deployment outpaced any shared classification baseline.
Why it matters
- ·Without a shared definition of what makes an AI system "agentic," procurement contracts cannot specify what controls a vendor must maintain. Compliance teams may be acquiring systems with broad autonomous authority under terms written for narrower tools, creating unmanaged accountability gaps.
- ·Red-teaming and pre-deployment evaluation programs are scoped against what a system is expected to do. Taxonomy confusion means evaluators and vendors may be testing different threat models, leaving real risks unexamined before deployment in sensitive environments.
- ·Regulatory exposure compounds when definitions diverge across jurisdictions. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services and the Implementation Opinions on the Administration of Intelligent Agents each treat agentic systems differently. Firms operating across borders need an internal taxonomy that maps to both, or they risk compliance gaps they cannot even see.
Governance controls affected
What to do now
- ☐Audit every internal policy, contract, and system intake form that uses the word 'agentic' or 'autonomous' and confirm it defines what level of delegated authority and independent action it covers.
- ☐Ask your procurement team to add three classification questions to AI vendor intake: where in the workflow does the system operate, what actions can it take without human approval, and who is named as accountable when it causes harm.
- ☐Review your current red-teaming scope with your security team and confirm it reflects the actual authority level of each agent, not just its stated purpose.
- ☐Map your internal AI agent inventory against the three CSIS attributes (workflow position, delegated authority, accountability) and flag any system where accountability is unassigned or ambiguous.
- ☐Where your organization operates in defense, critical infrastructure, or regulated sectors, confirm that your agent classification language aligns with the definitions used by the agencies or regulators that will review your systems.
What to watch next
CSIS is likely to follow this paper with sector-specific guidance as agentic AI deployment in defense and critical infrastructure accelerates. Compliance teams should watch for any adoption of the CSIS taxonomy in federal procurement standards or Five Eyes Guidance on the Careful Adoption of Agentic AI Services updates. The US AI AGENT Act discussion draft is a parallel legislative signal worth tracking, as it may codify definitional requirements that resolve the ambiguity CSIS identifies. If either instrument adopts formal definitions, organizations without an internal taxonomy will need to retrofit classification across their entire agent inventory.
Stay ahead of stories like this
Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.
