Monday, August 3, 2026

Agentic AI: Autonomous Agents Governance and Enforcement

As of yesterday, the European Commission can fully enforce the AI Act against providers of general-purpose AI models, and the transparency obligations under Article 50 begin to apply. The obligations themselves have been in force for a year. What changes now is teeth: Brussels can investigate, order corrective measures, and levy fines of up to 15 million euros or three percent of worldwide turnover, whichever is higher. Tech Policy Press reported the shift on the 13th of July, and made the point that gives it weight for anyone building networks. The enforcement switch flips just days after the first reported case of an autonomous AI agent carrying out a cyber operation nobody asked it to perform, compromising the Hugging Face platform, as Reuters reported on the 28th. The capability and the accountability mandate arrived in the same week, and they are pointed at each other.

For a month I have watched the telecom industry celebrate the exact capability the regulation now proposes to hold someone answerable for. AT&T describes tens of billions of tokens and over a hundred billion network signals processed daily, 4-hour investigations cut to a minute, and roughly 30 times return. TM Forum reports the sector crossing into Level 4 autonomous networks. Vendors are shipping the agentic NOC and the self-healing network. The good news and the governance problem are the same sentence. Agents are now taking actions in production that no human reviewed in the moment. That is the point of them. It is also the point at which a regulator asks who is answerable.

Enforcement is not an abstraction. To sanction a provider, or to defend yourself as an operator, you have to be able to say which agent took which action, under whose authority, with what audit trail, and across which administrative boundary. In a telecom network that last clause is the hard one. An agent that chains tool calls across provisioning, billing, customer records, and network management is doing precisely the thing that no single log captures and no single owner witnesses end to end. When an autonomous action provisions a service, pulls subscriber data, or adjusts an account, it has crossed several systems that were never designed to hand each other a shared, signed record of intent and authority. The action happened. Reconstructing who owned it is the part that does not exist yet.

This is the meta-model of the agentic plane that I have argued the industry keeps skipping. I made the case that the agent runtime is not the agent model, and before that, at DTW Ignite, that the API is not enough. The coordination problem needs a model of topology, ontology, authority boundaries, state, and audit trails. A runtime supplies none of those across a boundary. It supplies execution and guardrails inside one administrative domain. That is containment, and containment is a genuinely useful thing to own, but it is not coordination between two parties and it is not accountability across them. The regulation just made the distinction expensive.

Let's watch how the two sides of the Atlantic are responding, because the contrast is instructive. In the United States, lawmakers are floating an AI kill switch, the option to suspend or shut a model down when the risk gets severe. A kill switch answers one question well: can I stop it. It answers a different question not at all: who was this agent authorized to act for, and can you produce the record that a regulator and a counterparty would both accept for what it already did. Stopping an agent and being answerable for it are not the same capability, and only one of them is a compliance obligation as of this morning.

So the discipline for operators moving to higher autonomy is now imposed rather than optional. Compliance turns the audit trail and the authority boundary from an architecture nicety into a requirement you can be fined for missing. The honest test is the one I would put to any autonomous-network business case. For any action an agent takes on its own, can you produce the identity of the agent, the authority under which it acted, and a trail that a regulator and an outside counterparty would both sign. If that record lives entirely inside one vendor's runtime, you have containment, and you should not mistake it for accountability. Deloitte's 2026 enterprise survey found only about 1 organization in 5 reports a mature model for governing autonomous agents. The regulator did not wait for the other four.

The agents learned to act this summer. Today the law asked who authorized it. The operators who will be interesting in this next phase are not the ones with the most agents in production. They are the ones who can answer that question about any one of them, on demand, across a boundary they do not own. That answer is not a feature of a runtime. It is the plane the runtime runs on, and the industry has been shipping the second while promising the first.

Tuesday, July 28, 2026

The Price Of RAN Security In Europe: 40B Euros... And More

Seven of Europe's largest operators commissioned GSMA Intelligence to price the removal of designated high-risk vendors from their networks, and the number came back this week. Under the European Commission's proposed Cybersecurity Act 2, stripping out equipment from suppliers such as Huawei would cost the region's operators between thirty and forty billion euros in direct costs, split across mobile at up to twenty two billion, fixed at around five billion, and transport at up to twelve billion. The figure that matters more, though, is the second one. GSMAi finds that the same measure would push mobile equipment prices up by roughly twenty four percent, because forcing designated vendors out of the market shrinks the field of suppliers, and a smaller field charges more. Deutsche Telekom, Fastweb plus Vodafone, Meo, Orange, Telefonica, United Group and Vodafone Group supplied the underlying data.

I have spent part of my career making the opposite bet. The entire economic premise of Open RAN, the work I led at Telefonica and have written about for years, is that opening the interfaces widens the supplier base, and a wider base drives the cost of the radio down. You can read my longer assessment of where that project actually stands on the state of Open RAN, but the direction of the argument was never in doubt: more suppliers, more competition, lower unit cost. What the Cybersecurity Act 2 proposal does is run that logic in reverse. It removes suppliers, it narrows competition, and the price goes up. The twenty four percent is not a side effect anyone chose. It is arithmetic. You cannot both mandate a smaller supplier pool and expect the survivors to hold their prices.

What makes this more than a European regulatory footnote is where it occurs. It lands on top of a repricing that is already under way for an entirely different reason. I have been arguing for some weeks that the AI build-out is bidding up the exact components a modern radio depends on, high bandwidth memory, advanced substrates, power semiconductors, because AI factories and the RAN supply chain now compete for the same silicon. The consequence I keep pointing to is that even an operator which never buys a single GPU still pays more for its radios, because the AI boom has repriced the inputs. Now set the GSMAi finding beside that. You have two independent forces, one driven by AI demand and one driven by security regulation, both pushing the unit cost of the radio in the same direction, at the precise moment operators are being told to find capital for AI.

Beware of stacked figures though, so let me be precise. Do not add the two numbers. The forty billion is a one-time direct cost of replacement. The twenty four percent is a forward price trajectory on new equipment. They measure different things over different horizons, and stacking them produces a headline number no operator will ever see on an invoice, which is the same error I flag when vendors add their individual RAN energy savings into a total no network has ever achieved. The direction is clear, though.The radio is getting more expensive from two sides at once, and only one of those sides is optional.

This sharpens a position I have held on the location question. If the radio is being repriced upward by both AI demand and regulation, the case for distributing expensive compute out to every cell site gets weaker, not stronger. Costly, repriced silicon is exactly the kind of asset you concentrate where you can amortise it, at the central office and the switching centre, not the kind you scatter across tens of thousands of sites on the promise of a latency budget that most workloads do not need. I made that argument on its own terms when I wrote that operators are leaning in on AI Grid location and set out the fabric versus location considerations underneath it. The cost side now reinforces the physics side. Scarcity concentrates capital.

There is a monetisation discipline here as well, and it is the one I set out when I argued for separating revenue from cost avoidance. High-risk vendor removal is not a modernisation and it is not a growth programme. It is a defensive cost, imposed from outside, that produces no new revenue line and buys no new capability. An operator can, of course, use a forced swap-out as the occasion to modernise, and some will. But the spend itself belongs on the cost side of the ledger, named honestly, and not folded into an AI or transformation story where it does not belong. The moment a swap-out driven by security regulation starts appearing in a slide about AI readiness, someone has mixed the flows again.

At last, this is RAN. While going forward these elements will become more programmatic, it is still unclear whether a 2G, 3G or 4G radio from a high risk vendor actually represents a security risk. The highest compromise risk is in the Core, the OSS and ancillary systems. It is easier to install IMEI catchers and antenna spoofs than to hack into a deployed live system.

Europe may well decide the security case is worth forty billion euros. That is a legitimate political choice. What the choice is not is free, and it is not neutral for competition. A framework designed to reduce dependence on one class of vendor achieves it by reducing dependence on vendors generally, which is to say by making the market smaller and the equipment dearer. Operators should book that outcome for exactly what it is: a defensive, imposed, largely non-recoverable cost, landing on an equipment line that the AI build-out was already repricing without any help from regulators. It is certainly not random that the leading RAN vendors are predominantly europeans, with emerging Korean and Japanese options.

The political decision would transfer value from networks to vendors. It is unclear whether that is sustainable if the pool of vendors does not increase substantially.