Blog

From three laws of robotics to the governance of artificial intelligences

In 1942, for Isaac Asimov, imagining rules capable of governing a robot's behavior was still largely a matter of science fiction. Yet the three principles he proposed at the time already raised a question that concerns us directly today: what limits should be placed on a machine when it is given the ability to act?

Asimov's first law protected the human being against the robot's actions and against the consequences of its inaction. His second established the robot's obligation to obey humans, within the limits imposed by the first. The third allowed it to protect its own existence as long as that protection remained compatible with the previous two.

Artificial intelligence today gives this reflection a very concrete scope. It is available to the general public, embedded in companies, and progressively connected to software, data, infrastructures, and decision-making processes. AI agents add a further dimension, since they can use tools and carry out sequences of actions with varying degrees of autonomy.

At Quantum Beyond, we approach this evolution through principles that lie at the heart of our mission: security, trust, sovereignty, resilience, and control of digital environments. An organization's ability to harness artificial intelligence will largely depend on its ability to determine the authority it wishes to entrust to it and to keep that authority within clearly established limits.

The first of the three laws retains remarkable relevance. Harming a human being, however, takes on a much broader meaning in a digital environment. An AI can contribute to the disclosure of confidential information, facilitate fraud, produce an erroneous recommendation, influence an important decision, compromise an IT system, or trigger an operation with financial consequences.

Inaction deserves the same attention. An AI tasked with monitoring an infrastructure may detect a dangerous situation before a human can analyze it. Depending on the responsibilities entrusted to it, it could send an alert, suspend an operation, isolate a piece of equipment, or trigger an emergency procedure. Each of these possibilities corresponds to a different level of authority.

This notion of authority becomes central when we examine the second law, that of obedience to humans. An organization is made up of people holding different responsibilities and powers. An employee, a manager, an IT administrator, a cybersecurity lead, and an executive can all interact with the same system without holding the same rights. Internal policies, contractual obligations, regulations, and laws also frame their actions.

An AI must therefore operate within this structure of authority. The identity of the person making a request, their permissions, the context of that request, and the powers they can delegate to the system become information essential to how it operates.

An employee authorized to consult certain data could, for example, ask an AI to analyze it. That permission does not necessarily give them the right to transmit it to a third party, to copy it to another platform, or to allow an autonomous agent to use it in a series of external actions.

The delegation of authority to artificial intelligences thus becomes a natural extension of the principles of digital identity, authentication, authorization, least privilege, and Zero Trust.

The third law raises a different question. Protecting the “existence” of an artificial intelligence has little practical meaning when transposed directly to today's technologies. The integrity of the system, however, is essential.

Models, data, instructions, digital identities, cryptographic keys, connections, APIs, control mechanisms, and activity logs must remain trustworthy. An AI whose instructions have been altered or whose digital identity has been compromised can continue to function perfectly from a technical standpoint while carrying out actions contrary to the organization's intentions.

Integrity also includes the ability to regain control. An organization must be able to restrict an agent's permissions, interrupt an operation, isolate a system, revoke an identity, or deactivate an autonomous function when circumstances require it. The democratization of artificial intelligence considerably amplifies this issue, because the systems are beginning to work together.

An instruction issued by a person can be received by an AI, transformed into several tasks, distributed to different agents, executed through APIs, and propagated across multiple IT systems. A single human intention can thus produce dozens, or even thousands, of digital actions. This capability changes the scale at which an error can spread.

A poor instruction given to a person generally has a human speed of execution. A badly formulated instruction handed to an autonomous system can be executed simultaneously across several environments and reproduced as quickly as the infrastructures allow. Speed therefore becomes a component of risk in its own right.

The governance of these environments can rest on several simple principles: protection of people and their rights, legitimate authority, proportionality of permissions, system integrity, traceability of actions, reversibility, and the maintenance of human control.

Proportionality deserves particular attention. An AI tasked with preparing a financial analysis can be given the access it needs to the data concerned without having the ability to make a payment. An agent tasked with detecting vulnerabilities can examine an infrastructure without automatically holding the authorization to modify production systems. An AI preparing a response intended for a customer can produce the content while leaving the authorization to send it with the person responsible. Each capability can thus be associated with a precise level of authority.

This approach becomes particularly important with autonomous agents. Their effectiveness rests precisely on their ability to carry out several operations without requesting human validation at each step. Governance that is too restrictive would eliminate a significant part of their value. Authority that is too broad would considerably increase the possible consequences of an error, a compromise, or a malicious instruction.

Designing that autonomy therefore requires a fine understanding of the permissions needed, their duration, the context in which they can be used, and the events that must trigger human validation.

This reflection also leads to traceability. When an action results from a chain made up of a human, an AI, several agents, and various systems, the organization must be able to reconstruct that chain. Who issued the initial instruction? Which identity authorized it? Which agents were involved? Which data was used? Which decisions were made? Which operations were ultimately executed? This information becomes indispensable for cybersecurity, compliance, incident management, and organizational accountability.

The three laws imagined for a robot operating alongside humans could thus inspire six principles adapted to intelligent systems today: protect people, recognize legitimate authority, limit permissions to what is necessary, preserve the integrity of systems, ensure the traceability of actions, and maintain control and recovery mechanisms.

One cross-cutting principle naturally connects the six: the authority entrusted to an artificial intelligence should be proportionate to the mission it is given.

Artificial intelligence is advancing at an exceptional pace, and its democratization is accelerating its integration into organizations. Every new connection to a database, an application, an API, an infrastructure, or another agent increases its potential for action. It also increases the importance of properly defining its environment of authority.

The three laws of robotics had the merit of placing the human being at the center of the relationship between person and machine. That idea retains all of its value. Today's technologies now allow us to extend it with concrete mechanisms for governance, identity, security, traceability, control, and resilience.

For Quantum Beyond, this reflection fits directly into our vision of technology capable of strengthening organizations and the people who make them up. Artificial intelligence can considerably increase a team's capabilities when it operates in an environment where responsibilities, permissions, and control mechanisms are clearly established. Digital sovereignty takes on a very practical dimension here: an organization remains in control of its technologies, its data, and the authority it delegates to them.

The next generations of AI will be able to carry out more tasks, coordinate more systems, and take charge of increasingly complex operations. This evolution will give organizations considerable possibilities. It will also entrust them with a fundamental responsibility: consciously determining how far they wish to give a machine the power to act.