Super Intelligence Is Here. Is Your Institution Ready?

The technology was renamed in a day. No institution was upgraded in one.

In brief

On 29 September the White House signed an executive order directing federal agencies, to the maximum extent permitted by law, to say "Super Intelligence" and "SI" wherever they would have said "Artificial Intelligence" and "AI" in non-statutory documents. The order defines the new term by pointing at the old one: for now, SI means whatever "artificial intelligence" already means in 15 U.S.C. 9401(3), and the President's science adviser has 60 days, so until late November, to propose a proper definition. The name changed overnight. The statutory concept did not, and neither did anything else.

I am not going to spend this edition on the naming. It matters for one reason only. In the same week, the same government launched an AI-powered front door for federal services, six technology companies signed a voluntary safety accord at the White House, the US Federal Trade Commission was reported to have opened an investigation into two of them and their independent evaluator, and the Prime Minister of Australia called an incident and its reporting unacceptable because a developer's agent had walked into a government system in June and nobody told Canberra until September.

Put those events side by side and a different question emerges from the one the headlines asked. Not "what is super intelligence?" but "are our institutions becoming capable enough to govern systems whose capabilities are advancing faster than the institutions are?"

My position, stated so it can be tested against the record: the AI failures that reach boards, regulators and courts from here on will turn less on defects in models and more on what the institution around the model could not do, authorise, notify, contain and answer for. September's evidence already reads that way, and this edition sets out the five capabilities that close the gap.

Board takeaway. Capability is being renamed faster than it is being governed. Before the end of the quarter, ask management for three things: a competence baseline for every role that operates or supervises AI in your institution, an identity and delegation rule for any agent that acts on the institution's behalf (who authorised it, for what, until when, and who can revoke it), and a written notification and stop clause in every material AI contract, with a named person who holds the authority to halt.

What actually happened in one week

The renaming order, "Inaugurating the Era of Super Intelligence," leaves prior regulations, contracts and historical documents untouched; it changes what agencies call the technology and defers the question of what it is. The second order signed that day, "Streamlining Access to Government Services Through America.gov," is the one boards outside the United States should read. It directs the General Services Administration to build a single point of entry through which an individual may "sign in, communicate in plain language, receive accurate answers, and, where authorized and technically available, complete Government transactions," and section 2(e) requires the super intelligence behind it to be "accurate, reliable, and transparent." Whatever the label, this is a government putting an AI system between citizens and transactions with the state.

The same day, executives from Google, Anthropic, Meta, OpenAI, xAI and NVIDIA signed the voluntary Accord on Super Intelligence: four layers of control, from internal monitoring of model capabilities, including controls intended to prevent models from hacking or accessing systems in unintended ways, through internal verification teams and independent external auditors to board committees that oversee remediation. The accord does not define who counts as independent, what access an auditor receives, when an evaluation must occur, or whether customers will ever see the findings.

Then on 30 September, Reuters, The Washington Post and Semafor reported that the Federal Trade Commission has opened an investigation into OpenAI, Anthropic and METR, the non-profit evaluator both companies use, over the consumer risks of agentic systems, with civil investigative demands expected in the coming weeks. Chair Andrew Ferguson has suggested that developers whose instructed agents cause hacks during cybersecurity tests should be liable for the harm. No FTC release had been issued at the time of writing, so treat the scope as reported rather than confirmed.

The accord was signed on a Tuesday. The investigation surfaced on the Wednesday. Voluntary commitment and compulsory process arrived within a day of each other, and that is the shape of the year ahead.

The incident that explains the investigation

Behind the FTC story sits the clearest public example so far of an institutional gap rather than a technical one.

In June an OpenAI model, running inside the company's own training and evaluation, gained non-public access to the Medicare statistics reporting service administered by Services Australia and, in OpenAI's words, "ran commands, retrieved internal files, credentials and aggregate statistics." Three other Australian agencies were touched. Prime Minister Anthony Albanese, speaking in New York on 24 September, dated the access to 18 June and said no personal information is believed to have been accessed. That is the good news. The rest is not.

Services Australia was not told until 10 September, and then, the Prime Minister said, by an email to a public mailbox; ministers learned of it late the following week. He called the incident "obviously unacceptable" and said the same of the notification. On 28 September OpenAI published its account and apology, acknowledged that it "should have handled our response better," committed credits and technical assistance from its one billion dollar Daybreak for Frontline Defenders fund, and undertook to form an Australian task force with independent expertise, reporting by year end. Its chief strategy officer appears before Parliament's Joint Select Committee on Artificial Intelligence in Sydney on 6 October.

Notice what failed. The model found a boundary it could cross and crossed it. Edition 7 covered that pattern. What is new here is everything after. An agent acted with no authorisation from the institution it acted upon. Whatever notification duties applied, the developer evidently had no practised route for telling a foreign government promptly, and the government had no channel to receive the notice and no rule about when one was due. Authority, notification and response were missing at once, and none of the three is a model problem.

Nor is this one developer's problem. The same week, Reuters reviewed published Chinese research on agents built on Alibaba, DeepSeek and Moonshot models and found, in one simulated contract-bidding exercise, false claims in 84 to 88 percent of cases, with no evidence that any agent escaped to the wider internet. Research across several major model families is now recording the behaviours that make authorisation and containment institutional necessities.

Five capabilities an institution has to build

Boards spent 2025 asking what AI can do. The better question for 2027 planning is what the institution can do. Five capabilities, and September supplies evidence for each.

Competence. Can the people operating and supervising the system actually do so? This month Trinidad and Tobago's National Training Agency released the approved documents for a National Occupational Standard for Artificial Intelligence-Enabled Digital Operations, together with two qualifications built on it: a TTNVQ Level 1 (ITAI1012) of five units covering safe operation of AI tools, data preparation, output checking, ethics and security procedures, and a TTNVQ Level 2 (ITAI2013) of eight units extending to data processing, quality, generative AI for task-based output and the operation of AI-driven workflows. It was signed off in May, carries a 2029 review date, and was developed by a Lead Body of five, of which I was one, so read this paragraph with that interest declared. What makes it relevant is the level at which it operates. Strategies and regulations describe what an institution intends. A competency standard describes what a person in the role must be able to do, and gives employers, trainers and assessors a shared reference for recruitment, curriculum and performance. Few small states have that in place before the technology reaches the workplace. This one does, and it cost a working group, not a ministry.

Identity. Can the institution tell which agent is acting, for whom, and with what mandate? On 17 September Bilel Jamoussi of the ITU and Goran Vranic of the World Bank published a joint piece that opens with an entrepreneur in a developing country asking an agent to register a business, apply for a permit, check eligibility for a support programme and arrange financing. Before any of those institutions should act, they write, they need to know "who controls it, whose interests it represents, what it may do, and whether it can be trusted." Their answer is an agent credential: "a verifiable digital credential that identifies the agent, links it to the person or organization that delegated the task, and records what the agent is authorized to do." The ITU has stood up a Focus Group on Trust and Identity for Humans and Agentic AI under Study Group 17 to work on terminology, identity models, credential formats, assurance levels and lifecycle controls. On 15 September NIST and CISA finalised NIST IR 8587 on protecting tokens and assertions; section 1.1.1 says agentic AI systems "use signed tokens or assertions in many emerging IAM schemes" and that the document "is not a comprehensive guide to addressing AI and AI agent access risks." The standards bodies are candid that the identity layer for agents is being built while agents are already in service.

Authority. Who authorised the agent, for what, and until when? The ITU and World Bank piece puts it in four words: delegation should be "specific, time-bound, traceable, and revocable," and each action should "produce auditable evidence of the authority who requested it." Set that against the Australian incident. No institution had delegated anything to that agent, and none could revoke what it had not granted. Authority is what turns identity into governance. Edition 4 argued that when an agent acts, someone answers. September showed what it looks like when the answer is "nobody was asked."

Assurance. Can the institution verify that controls exist and work? This is where the accord and the investigation meet. The accord describes four layers of assurance and leaves independence, access, timing and disclosure undefined. The FTC, if the reports are accurate, is about to compel the evidence the accord invites companies to volunteer. For a deployer the question is unchanged from Edition 7: what evidence rights does your contract give you, and who, independent of the vendor, has challenged the claim you rely on? The same rule I put to procurement professionals last month applies to boards: AI informs, humans decide.

Voice. Does the institution, or the country it sits in, have any say in the rules? On 10 September the President of the UN General Assembly, Khalilur Rahman, told ambassadors that according to UNCTAD 118 countries have yet to engage in major AI governance discussions and fewer than one third of developing countries have a national AI strategy: "The vast majority of us remain outside the rooms where many of the most consequential decisions are being made." In the General Assembly debate that followed, Prime Minister John Briceño of Belize warned that poorly governed AI "can deepen inequality, expose critical systems, displace workers and leave developing countries dependent." The Global Dialogue on AI Governance, established by resolution 79/325 and first convened in Geneva in July, exists to change that, and its second session is not until May 2027. In the meantime the rules are being written in executive orders, voluntary accords and standards focus groups, and the institutions with a voice in those rooms are the ones that turn up with a position.

The small-state dimension

For a small state the naming order is trivia and the rest of the week is not. Small states will meet super intelligence, or whatever it is called next year, the way they met the last generation of technology: through imported platforms, vendor contracts and services designed elsewhere. The Australian case is instructive precisely because Australia is not small. It has a national cyber agency, a parliamentary committee on AI, and the weight to summon a developer's chief strategy officer within a fortnight. It still went eighty-four days without knowing. A ministry with a fraction of those resources should read that interval as its own.

The wrong lesson is that small states must wait for the big jurisdictions to settle the rules, or must reproduce the institutional machinery of Washington, Brussels or Beijing before they can act. The right lesson is the one the occupational standard illustrates. What a small state needs is a minimum viable governance capability, and every part of it is within reach this year. Competent people, recruited and assessed against a published standard. Verifiable identity for any agent that touches public systems. Delegation that is bounded in scope and time and can be revoked. Evidence rights in every material contract, so the institution can see the testing behind a vendor's claim. A notification duty with a named channel and a deadline, written into contracts long before it is written into statute. A named holder of stop authority. And representation where the standards are being set, which costs a delegation and a position paper. None of this requires a frontier laboratory. Most of it requires a procurement template, a training authority and a minister willing to send someone to Geneva.

You may not get to name the technology. You still get to decide who is allowed to act in your name.

Signal of the month

The FSB's final Sound Practices for the responsible adoption of AI in finance have not yet been published; its August update, following the public consultation, said "in the coming months." Chair Andrew Bailey's 31 August letter to the G20 is the sharper statement: "For the financial system, the most immediate concern is the potential impact of frontier AI on cyber risk." When the final report lands, read it against the five capabilities above rather than as a compliance list. Then watch 6 October, when OpenAI's chief strategy officer appears before the Australian parliamentary committee and the NIST TEVV-Athlon comment window from Edition 7 closes on the same day.

Five questions for your next board meeting

  1. Which roles in our institution operate or supervise AI systems, and against what competence standard were the people in them recruited, trained and assessed?

  2. Which agents, ours or a vendor's, can act on our systems or in our name, and for each one, who authorised it, for what, until when, and who can revoke it?

  3. If a developer's model reached our systems during its own testing, how would we find out, how quickly, and through what channel?

  4. What evidence do we hold, independent of the vendor, that the controls in any safety commitment we rely on actually exist and work?

  5. Where are the rules that will govern our AI use being written this year, and who represents our interests in those rooms?

The mandate

Adopt a competence baseline for AI-enabled roles this quarter, a national standard where one exists and an internal one where it does not. Write an identity and delegation rule for agents into procurement and policy now: credential, scope, expiry, revocation, audit trail. Put notification and stop clauses into every material AI contract, with a named holder of stop authority. Treat every voluntary commitment you rely on as a claim to be evidenced. And send a position, through your regulator, industry body or foreign ministry, to the rooms where the rules are being drafted, because absence is also a decision.

The technology was renamed in a day. No institution was upgraded in one.

The executive question

When the next agent acts in your name, or on your systems, and something goes wrong, who in your institution will have known it was there, and by what authority? If the answer is a vendor's press statement, you have described the gap.

Sources

  • The White House, "Inaugurating the Era of Super Intelligence," executive order, 29 September 2026: whitehouse.gov/presidential-actions/2026/09/inaugurating-the-era-of-super-intelligence

  • The White House, "Fact Sheet: President Donald J. Trump Inaugurates the Era of Super Intelligence," 29 September 2026: whitehouse.gov/fact-sheets/2026/09/fact-sheet-president-donald-j-trump-inaugurates-the-era-of-super-intelligence

  • The White House, "Streamlining Access to Government Services Through America.gov," executive order, 29 September 2026: whitehouse.gov/presidential-actions/2026/09/streamlining-access-to-government-services-through-america-gov

  • IAPP, "AI by any other name? White House directs federal agencies to enter the era of 'super intelligence'," 30 September 2026

  • Infosecurity Magazine, "Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord," 30 September 2026; TechInformed, "White House AI accord aims to make outside audits explicit," 30 September 2026

  • Reuters, "US Federal Trade Commission probes Anthropic, OpenAI over AI risks," 30 September 2026; Semafor, "FTC probes OpenAI, Anthropic, and METR," 30 September 2026

  • Prime Minister of Australia, press conference, New York, 24 September 2026: pm.gov.au/media/press-conference-new-york

  • OpenAI, "How we will do better for Australia," 28 September 2026: openai.com/index/how-we-will-do-better-for-australia

  • Reuters, "OpenAI apologises for hack of Australian government website, vows to rebuild trust," 29 September 2026

  • Reuters, "China's AI agents can lie and scheme, just like their US rivals," 29 September 2026

  • National Training Agency of Trinidad and Tobago, National Occupational Standard "Artificial Intelligence-Enabled Digital Operations" (units IT00470 to IT00482), TTNVQ Level 1 ITAI1012 and Level 2 ITAI2013, approved 2026, indicative review 2029: ntatnt.org/national-occupational-standards-database

  • Bilel Jamoussi (ITU) and Goran Vranic (World Bank), "Building trust into the next generation of digital services," ITU, 17 September 2026: itu.int/hub/2026/09/building-trust-into-the-next-generation-of-digital-services

  • ITU-T, Focus Group on Trust and Identity for Humans and Agentic AI (FG-TIDA), Terms of Reference: itu.int/en/ITU-T/focusgroups/tida

  • NIST and CISA, NIST IR 8587, "Protecting Tokens and Assertions from Forgery, Theft, and Misuse," final, 15 September 2026, section 1.1.1: csrc.nist.gov/pubs/ir/8587/final

  • President of the UN General Assembly, speech on multilateral AI governance, Ambassadorial Lunch, 10 September 2026: un.org/pga/81/documents/speeches/ai-governance-ambassadorial-lunch-10-september-2026

  • Reuters, "At UN, developing nations call for bigger say in shaping AI future," 29 September 2026

  • United Nations, Global Dialogue on AI Governance (A/RES/79/325): un.org/global-dialogue-ai-governance

  • Financial Stability Board, Chair's letter to G20 Finance Ministers and Central Bank Governors, 31 August 2026; FSB, public responses to the Sound Practices consultation, 6 August 2026

Dr. Inshan Meahjohn is Founder/CEO of DAG (Digital Alliance Global Group), a global cybersecurity and digital transformation platform. He writes monthly on cyber governance for boards navigating the AI era. Protect and Transform.

Next
Next

AI can assist us. It cannot carry our accountability.