The framework moves from human-supervised assistance to autonomous government action without identifying the control architecture between them. Without pre-execution authorization, policymakers are left to restrict capability or accept execution they cannot reliably govern.
A scenario framework without an authorization boundary
The Four Futures of AI, a docuseries produced by Fed Gov Today in collaboration with EY, opens with a serious question: "Will government shape AI's future or will AI shape government?" The ambition is considerable. Built on conversations with leaders across government, industry, and academia, the series presents four scenarios for how artificial intelligence could reshape public services, national security, and the economy by 2030: Growth, Transform, Constraint, and Collapse. Its stated purpose is to confront policymakers with the consequences of choices being made today. EY's companion enterprise treatment applies the same four labels to the business landscape and expressly describes them as tools for strategic thinking rather than predictions.
The defect sits at the level of the questions asked. The framework asks how quickly AI will advance, how dramatically it will transform organizations and government, how aggressively it might be restricted, and whether a dominant corporation might capture it. EY's companion analysis comes closer to the control problem. Under Constraint, it asks: "What mechanisms will you use to enforce AI governance?" The page does not answer that question at the level of an execution architecture or describe an enforcement point. Across the published materials, the act-specific question therefore remains unasked and unanswered: can an unauthorized AI action be prevented from executing?
That is not a peripheral omission. It is the question on which every proposed future depends. Adoption rates, capability curves, regulatory intensity, and market structure all presuppose an answer to a prior question: when an AI system reaches for a consequential action, does anything stand between that action and the governed environment, and does that thing render a verdict before execution rather than a report after it?
Without pre-execution authorization, the four futures eventually collapse into two control failures. Government can restrict AI autonomy until conventional human oversight can contain it, or permit autonomous execution without a reliable mechanism for determining and enforcing whether each consequential action is authorized.
These are not four coherent futures
Take the scenarios as published. Growth describes a rate and pattern of adoption: steady modernization, step-by-step optimization of infrastructure, accumulated efficiency. Transform describes a capability discontinuity: government deploying AGI-class systems to solve complex challenges autonomously. Constraint is presented by Fed Gov Today as a governmental response: heavy-handed restriction triggered by public fear. EY's companion treatment presents the same label more cautiously, as a measured regulatory reassessment following concrete AI failures. Collapse describes a political-economic outcome: a corporate monopoly with an insurmountable technological lead, and a state forced to innovate rapidly to preserve sovereignty.
These are four different kinds of things. Growth is an adoption trajectory. Transform is a capability trajectory. Constraint is a regulatory posture. Collapse is a market-structure outcome. They occupy different analytical dimensions, and nothing about them is mutually exclusive. A monopolistic provider could lead a transformative deployment. Incremental growth can proceed under regulatory restriction. Constraint can arrive as the political aftershock of transformation. Collapse can emerge through the gradual accretion of dependency rather than a sudden AGI breakthrough. A single government can occupy several of these boxes at once: transformation in defense, restriction in benefits administration, deepening provider concentration across both.
The framework is not a map of four alternative destinations. It places speed, capability, regulation, and market structure on the same axis and calls the resulting labels futures. This is not a complete scenario framework. It is a collection of capability trajectories, policy responses, and failure modes presented as though they were mutually exclusive futures.
The capability scenarios expose the missing middle
Growth and Transform are the framework's two capability-expansion scenarios, but they rest on different control premises.
The two companion treatments do not give Growth a single control premise. The Fed Gov Today episode keeps AI largely in an assistive role: copilots draft, analyze, triage, predict, and guide, while a human-in-the-loop safeguard is expressly retained in defense and intelligence. That postpones the authorization problem by keeping the human at the consequential boundary and can govern systems whose outputs remain recommendations. EY's companion enterprise treatment goes further. It describes domain-specific AI agents proficient across finance, HR, legal, and other operational functions, enabling highly automated back offices, AI-augmented front offices, and agentic workflows. That version brings the authorization problem forward because agents are no longer characterized solely as recommendation systems. Neither treatment explains what replaces per-action human approval when an agent is permitted to act.
Transform moves directly across that line. Its agents initiate workflows, make decisions, pull records, flag inconsistencies, and complete tasks without human prompting. Constraint identifies determinations involving benefits, priority services, and law enforcement that must remain human. Collapse adds human approval before kinetic force. These examples can affect the exercise of state authority. The series specifies human control for some of them, but it never describes the enforcement architecture that makes the requirement non-bypassable or establishes authorization for autonomous actions outside the categorical prohibition.
EY's companion Transform scenario describes enterprise-grade AI platforms as "robust, trustworthy and widely accessible," but it does not identify an execution-time mechanism by which trustworthiness is established or enforced. Trustworthiness appears as a premise of the scenario rather than an enforceable property of the system.
As autonomy increases, per-action human approval becomes less compatible with the intended benefit. But removing humans from individual execution decisions does not remove the requirement for authority. Autonomy changes who performs the action. It does not create the authority to perform it.
The published framework leaves the decisive authorization questions unanswered. How is the contemplated action represented at the boundary? Whose authority permits it? What authority was delegated, and was that delegation valid for this action, context, and time? What verdict existed before execution? Could the system or its operator bypass that verdict? What happens when authorization cannot be established? These questions arise as soon as an agent moves from recommendation to execution. They do not depend on the arrival of AGI in 2030.
Transform without a runtime authorization boundary is not governed autonomy. It is delegated capability without enforceable limits. A government that cannot determine whether an unauthorized action can execute does not yet have an AI governance strategy. It has a deployment program followed by an incident-response plan.
The controls the series names
The episode materials are not silent on control. Four elements bear directly on whether consequential actions remain governed: human-in-the-loop requirements, AI assurance, post-incident investigation, and what the Collapse episode calls the authorization process. Each has value. None, as described, supplies a complete runtime authorization boundary.
The first is human review. Human review can be a valid source of authorization. But a "human-in-the-loop" requirement does not by itself specify an enforcement architecture. The published descriptions do not explain how the required approval is bound to the contemplated action, what prevents execution without it, what occurs when the human is unavailable, or what evidence allows the resulting verdict to be reconstructed independently. The problem is not the presence of the human. It is the absence of a defined runtime authorization boundary around the human's authority. A prohibition without an enforcement point may be a binding policy or legal rule. It is not yet an execution control.
Read together, Transform and Constraint reveal the framework's control limit. Transform derives its value from agents that complete workflows without human prompting. Constraint restores accountability by reserving consequential determinations to humans. The framework can describe autonomous capability, and it can describe human control, but it does not describe autonomous execution that remains subordinate to a non-bypassable authorization boundary.
The second instrument is AI assurance, described in the Constraint episode as auditing models to understand how safe they are, why they decide as they do, and where their biases lie. As described here, that is model evaluation. It addresses whether a system is generally likely to behave acceptably. It says nothing about whether a specific action was permitted before it executed.
The third is an NTSB-style investigative body for AI failures. Institutionalizing post-incident review is sensible. It also locates accountability after execution, once the failure has already occurred.
The fourth is the word "authorization" itself, which appears in the Collapse episode in the procurement and deployment context: agencies are described as cutting through authorization-process red tape through sandboxes and acquisition accelerators. That is authorization to acquire, introduce, or operate a system. It does not by itself determine whether the deployed system may execute a particular action. System-level authorization and act-specific runtime authorization are different controls. The series describes the former, not the latter.
The Constraint scenario confuses precision with restraint
The two companion treatments frame Constraint differently. The Fed Gov Today episode begins with public backlash forcing government to "slam on the brakes," warns that excessive regulation could surrender technological advantage to strategic adversaries, and later recasts "constraints" as safe boundaries that give government employees confidence to experiment. EY's enterprise treatment instead describes a "measured reassessment" following AI trading-system malfunctions, persistent errors in AI-powered financial reporting, medical AI misdiagnoses, new liability issues, and AI content generation proving less commercially viable than anticipated. The EY treatment is more specific than a simple backlash narrative. But it does not answer its enforcement question at the level of an execution architecture, and neither treatment identifies an act-specific execution boundary.
The terminology obscures an important architectural distinction. A constraint can be precise: a condition evaluated against a specific action at execution time. Restraint is broader. It withholds a class of capability because authorized and unauthorized actions cannot be distinguished reliably at the execution boundary. The Fed Gov Today episode moves between these meanings, treating heavy regulatory restraint and enabling technical guardrails as variations of the same idea. They are not.
Model assurance and guardrails address alignment. Human review supplies manual authorization. Post-incident investigation supplies accountability and visibility after execution. Each addresses a legitimate problem. None, as described, creates a non-bypassable pre-execution authorization boundary for autonomous action.
Restricting capability and restricting broad categories of use often function as proxies for act-specific authorization when selective runtime enforcement is unavailable. They need not always be proxies: some conduct may properly be prohibited categorically. The architectural problem arises when authorized and unauthorized actions are suppressed together because the system cannot enforce the distinction at execution time.
The apparent conflict between governance and innovation is partly manufactured by architectures that can monitor AI conduct but cannot condition execution on authorization. Pre-execution authorization does not mean everything is permitted. It means restriction becomes specific, enforceable, and attributable: this action, under this authority, at this time, with this verdict on record.
Collapse begins before monopoly
The Collapse scenario locates the sovereignty threat in a future event: a corporation achieves an insurmountable technological lead, and the state must respond. This understates the problem by placing it too late.
Sovereignty is weakened when government depends on the same provider to supply the AI capability, interpret the applicable rules, enforce those rules, record the system's own conduct, and attest that the conduct was compliant. Each function may be delivered competently. The concentration is the defect. When the governed party generates the evidence of its own compliance, the arrangement is self-attestation, however polished the dashboard.
The Collapse episode's proposed remedies confirm the gap. Multi-model strategies, open-source platforms, sandboxes, and acquisition accelerators address market structure. As described, none relocates enforcement or evidentiary control outside the governed provider. If each provider still controls its own enforcement and compliance evidence, a government running five vendors holds five provider accounts of compliance and still no independent one.
The distinction to hold is observability versus authorization. A detailed record supplied after execution may establish what the provider says occurred. It does not establish that the action could not occur without prior authorization. Access to provider-controlled logs is access to the provider's account of itself. Sovereignty over AI execution requires something different: control over the authorization boundary and the ability to reconstruct an authorization verdict independently of the governed system.
That requirement holds even in a competitive market with several vendors. Monopoly aggravates the condition. It does not create it.
The omitted architecture
Three questions are routinely conflated in AI governance discussions, and the four-futures framework inherits the conflation. Visibility asks what happened. Alignment asks whether a system is generally likely to behave acceptably. Authorization asks whether this specific action was permitted before it executed.
Logs, monitoring, explainability tooling, model evaluations, guardrails, and post-event audits typically address visibility or alignment, and they have value there. Identity and access management can establish identity, credentials, delegated scope, and permissions over defined resources. These controls do not necessarily establish whether this specific AI-generated action was authorized under the applicable authority chain, policy state, context, and time. A system can be observable, broadly aligned, and properly credentialed, yet still execute an action for which act-specific authorization was never established.
The missing condition is a runtime authorization boundary: an enforcement point through which a consequential action must pass before it reaches the governed environment. At the interface level, the required properties are these:
- A verdict exists before execution.
- The verdict space is exactly ALLOW, DENY, or ABSTAIN.
- DENY blocks execution. ABSTAIN blocks execution pending authorized human override.
- The boundary is non-bypassable.
- If authorization cannot be established or the required authorization artifact cannot be produced, execution remains blocked. This is fail-closed governance.
- A tamper-evident authorization artifact binds the contemplated action, applicable authority, policy state, verdict-influencing inputs, time, and verdict.
- An independent party can reconstruct the authorization verdict without access to, or reliance on, the governed system's internal account.
The change this produces is precise. The system is not asked whether the AI is generally trustworthy. It is asked whether this action is authorized now.
This is also where the human-in-the-loop instinct lands on solid ground. Under ABSTAIN, the human is not a staffing assumption distributed across workflows. The human enters at a defined point, when the boundary blocks execution pending authorized human override, with the authority and the evidence on record.
The future the framework cannot describe
It is tempting to package this as a fifth future and place it beside the other four. That would concede too much to the taxonomy. Authorization is not another macro scenario. It is the control condition that determines whether the capability-expansion scenarios remain governable and whether Constraint or Collapse become likely.
Under that condition, capable AI may continue to advance. Autonomous systems may perform consequential work. But their authority remains externally defined, execution remains conditional, uncertainty blocks rather than silently permits, and every verdict leaves independently reconstructable evidence.
Each of the four labels then changes character. Growth proceeds without allowing accumulated operational capability to become undeclared authority. Transform proceeds without self-authorizing autonomy. Constraint ceases to be the default response when prohibited actions can be blocked selectively at execution time. Collapse becomes less likely when capability, enforcement, and compliance evidence are not controlled by the same provider.
Choose an authorization architecture before choosing a future
Scenario exercises are not analytically neutral. They shape the option space presented to policymakers and can influence where institutional attention and investment are directed. A taxonomy that omits the execution boundary directs attention toward monitoring, restriction, and provider assurances because those are the categories it makes visible. Pre-execution authorization remains outside the framework, not by an expressed decision, but by omission.
Government does not yet face a choice among four futures. It faces a prior choice about control. Either consequential AI actions become subject to pre-execution authorization at a non-bypassable runtime boundary, or policymakers are left choosing between two inadequate responses: limiting AI until conventional human supervision can contain it, and deploying it at scale while hoping that observability, alignment, and after-the-fact accountability will substitute for authority. One path suppresses capability to compensate for missing control. The other discovers unauthorized execution after the fact. Neither is governance.
