Fewer than ~10 nations have wired the agentic foundation onto a healthy digital state — and perhaps two or three have done it well. That gap is the story of the agentic decade.
About this report · How to read it
The European Nexus for Strategic Intelligence (ENSI) builds decision-grade intelligence on how nations architect technology. This issue maps the next layer of the state: the public infrastructure that lets AI agents — software that perceives, reasons and acts within bounded authority — do useful, safe, accountable work at population scale. It is not an AI-strategy PDF and not a chatbot procurement; it is a reading of the agentic literature against the national-architecture canon, resolved into a buildable stack.
This report is grounded in a verified collection of 142 downloaded PDFs and ~174 catalogued sources spanning 12 folders — from national architectures (Estonia, Singapore, India, the UAE) and the digital-state frameworks (eIDAS, NIST, FedRAMP) to the agentic corpus: the Agentic State vision paper, NASCIO 2026, OpenAI's governing-practices, the MCP and A2A protocols, and the agent-systems research (ReAct, RAG, Reflexion, MemGPT, τ-bench). Every number traces to a source; agentic adoption figures the literature could not count precisely are labelled (est.).
Magenta is the one accent: emphasis and the load-bearing layers. Green marks data-positive, coral marks an alert. Two coding systems run through every page — the five priority tiers and the eight stack layers.
P0 Bedrock — no agentic state without it P1 Core — defines a serious agentic state P2 Differentiator — separates the leaders P3 Advanced — the maturing edge P4 Frontier — the experimental frontier
L1 Compute & Models L2 Data, Knowledge & Memory L3 Tools & Integration L4 Trust & Control · cross-cutting L5 Agent Runtime L6 Orchestration L7 Experience & Mission L8 Governance Spine · cross-cutting
Source chips (e.g. NASCIO 2026) close findings and tables; bold renders magenta throughout and always marks the thing that matters on the page.
Contents
Three depths: 90 seconds — pp. 1–10 · 15 minutes — add the framework, adoption curve & optimal stack · Full read — the 50 principles, 50 components, 10 archetypes & 7 cases. Every component carries a priority (P0–P4) and an adoption figure; agentic estimates are labelled (est.).
Executive summary · 1 of 2
For thirty years the organising metaphor of national technology was the digital service — a form turned into a web page, a registry turned into an API. The best states built that layer well: Estonia's X-Road, India's identity-payments-data stack, Singapore's government-as-a-platform, the EU's interoperability frameworks. That achievement is now the floor, not the ceiling. A new substrate has arrived — AI agents — and NASCIO frames the shift bluntly as the move from "AI that assists" to "AI that acts."
National Agentic Technology Infrastructure (NATI) is the public infrastructure a nation must build so that agents can act usefully, safely and accountably at population scale. It is a stack — compute, models, data, memory, tools, identity, orchestration, governance — re-conceived around a worker that reasons and acts. The central claim of this report is that the digital state and the agentic state are not rivals: the agentic state is what you build on top of a working digital state, and it fails without one. An agent is only as good as the identity it can verify, the registry it can trust, the tool it can call, and the human who can stop it.
The optimal design at this stage is clear and convergent. It is a sovereign agent platform provisioned centrally for all of government, on which every agent is a grounded, reflective reason–act–verify loop with governed memory, reaching the world through an MCP tool layer and other agents through an A2A federation, all running under supervised autonomy — bounded action, mandatory human gates, agent identity, authenticated delegation, full observability, a tested kill-switch — evaluated continuously against a mandatory eval harness and a binding national risk framework, and sitting atop a healthy digital state.
The win is not any single exotic pattern. It is having all of the agentic P0–P1 components wired together onto a working digital foundation — which fewer than ~10 nations have done, and perhaps two or three have done well. The decisive strategic fact is that the agentic race is being run on the foundations laid by the digital race: nations that built X-Road-class interoperability, population-scale identity and clean registries already hold half the agentic P0 stack, while those that skipped the digital foundation will find that no amount of agent procurement substitutes for it.
The agentic state is the digital state's canon — identity, registries, federation, interoperability, governance, oversight — extended to a worker that reasons and acts. The win is having the agentic P0–P1 layer wired onto a healthy digital foundation, which fewer than ~10 nations have done.
The pages that follow translate this into a buildable architecture: a priority model from P0 Bedrock to P4 Frontier, an eight-layer stack, fifty principles, fifty components and ten archetypes — and a scorecard of who, today, is closest to the optimal design.
Executive summary · 2 of 2
Two paragraphs of consequence, then the five things a decision-maker must internalise.
The defining risk of agents is confident error; the defining requirement of public administration is defensible decisions. Grounding resolves the tension — retrieval from authoritative registries, with citations, turns an agent's output into something it can prove, so ungrounded agents on official matters automate unaccountability. And because models are replaced every few months, a continuous evaluation harness measuring capability and consistency is the difference between a controlled rollout and a silent regression — τ-bench's finding that agents often fail on repeated trials is the single most important deployment caution in the evidence base.
The other half of the answer is governance as architecture. For software that acts, identity, authenticated delegation, least-privilege scopes, human approval gates and a tested kill-switch are not a brake bolted on afterwards — they are structural members of the design. Supervised autonomy is the only pattern present in every credible governance source, and the maturity discipline — climb, do not leap — is how a state earns autonomy as reliability is proven. The order is the strategy.
No nation has the full optimal stack. The frontier is a composite — the US's platform, Estonia's digital foundation and framework, the UK's assurance discipline, Singapore's governance toolkit, the EU's binding risk law, and the UAE's mission ambition. The report's task is to name the components, rank the architectures, and show the assembly order.
The dashboard · 1 of 2
The foundation and the frontier, read together. The connectivity, identity and cyber numbers are hard global figures; the agentic-adoption tiles are labelled (est.) where the literature could not count precisely.
The top row is the digital foundation the agentic state is built on — broadband, coverage, 5G, cyber response. The lower rows are the agentic frontier, where hard counts thin out and the synthesis estimates begin: the population of nations with a wired P0–P1 stack is small, and the platform builders are fewer still. Estimates are derived from the leaders documented in folders 08–12 and are explicitly indicative.
The dashboard · 2 of 2
Two hero charts and a share view. The leaderboard is an indicative composite against the optimal stack (0–100, est.); the drop-off shows how adoption collapses as you climb the priority tiers.
No global index yet counts "agentic-ready" nations. FIG 1–3 are ENSI composites built from the documented leaders (USAi, the Agentic State framework, NASCIO's production states, NAIS 2.0, the EU AI Act) and are directional, not measured.
The master diagram
Read top to bottom. Magenta bands are the load-bearing layers; each carries its name, one-line role, and its P0 component. Everything sits on the digital-state foundation — remove it and the stack falls.
Key findings · 1 of 2
The load-bearing conclusions of the evidence base, each closing with its strongest source. Findings 1–6 cover the strategy and the architecture of trust.
Findings 1–6 establish the strategy (continuity, the gap, the platform) and the architecture of trust (grounding, supervised autonomy, agent identity). Findings 7–12, overleaf, cover how agents reach the world, how they are proven reliable, and where the adoption curve breaks.
Key findings · 2 of 2
Findings 7–12 cover integration, reliability, data readiness, the leaders, the cliff, and the rule that governs the whole sequence.
These twelve findings are a dependency graph, not a menu. The remainder of the report walks them in order — the framework and landscape (Movement B), the principles, components and architectures (Movement C), the cases and recommendations (Movement D), and the risks and evidence base (Movement E) — so a nation can see not just what the agentic state is, but the sequence in which it is actually built.
The agentic race is being run on the foundations laid by the digital race — no amount of agent procurement substitutes for the identity, registries and interoperability beneath it.
MOVEMENT B · THE REFRAME
Almost every government that has put a budget line against "agentic AI" has framed it as a purchase: a chatbot here, a copilot there. That framing is the costliest mistake a nation can make — because an agent that reasons and acts on citizens is not a product you procure. It is infrastructure you provision.
For thirty years the organising metaphor of national technology was the digital service — a form turned into a web page, a registry turned into an API. The contrarian core of this report is that the next layer breaks that procurement logic. NASCIO's 2026 report frames the shift as the move from "AI that assists" to "AI that acts." Software that "perceives, reasons, and takes autonomous action within defined boundaries" is not a feature bolted onto a service. It is a new factor of production — a class of digital labour that converts policy into daily service.
And labour is provisioned, not bought off a shelf. The US GSA's USAi is a government-wide platform — chat, API and an evaluation console over multiple models — offered to every agency at no marginal cost; the EU's GenAI4EU plays the same role. Neither is "a chatbot the government bought." Each is a shared substrate on which safety, identity, evaluation and cost-control are operationalised once and inherited everywhere.
A chatbot answers; an agent acts. The moment software can move money, change a legal status, or take an irreversible step, it inherits the entire governance apparatus of the state — identity, authorisation, audit, liability, oversight. You cannot procure that as a SKU. The question is therefore never "which AI do we buy?" It is "what infrastructure must we provision so that agents can do useful, safe, accountable work at population scale?"
The agentic state is the digital state's canon — identity, registries, federation, interoperability, governance, oversight — extended to a worker that reasons and acts.
MOVEMENT B · THE REFRAME · CONTINUED
Every dollar mis-spent on agentic AI can be traced to one of a handful of category errors. Each myth is intuitive, procurement-friendly and wrong. Each mechanism is the infrastructure pattern the leaders actually adopted instead.
| The myth (the wrong question) | The mechanism (what the leaders do instead) |
|---|---|
| Buy a chatbot for each agency. | Provision one sovereign agent platform — shared model access, shared guardrails, shared observability, shared tool catalogue — that every ministry builds on (USAi, GenAI4EU). Safety and capability are inherited, not re-purchased. |
| AI that assists. | AI that acts, under supervised autonomy — bounded action spaces, mandatory human-approval gates, a tested kill-switch. Autonomy is earned level-by-level up a maturity model, not switched on (NASCIO five-phase model). |
| More models = more capability. | Tools + grounded data + identity = capability. An agent without tools is a text generator; an agent with the right tools, retrieving from authoritative registries, acting under a verifiable identity, is a worker (Toolformer; RAG; MCP). |
| Agents replace the digital state. | Agents are the digital state's canon, extended. They amplify whatever they stand on — including bad data and broken process. They fail without the eID, registries, data-exchange and security beneath them. |
| It's an AI strategy (a PDF). | It's an operating stack — compute, models, data, memory, tools, identity, orchestration, governance — provisioned, instrumented and measured by resolved outcomes, the way the EU Digital Decade reports binding KPIs. |
The number of agents deployed measures nothing. Count what matters: a resolved citizen outcome, a civil-servant hour returned, a cost-per-resolution that falls. Instrument the platform for task-completion, reliability under repetition, and time saved — and report it like a binding target, not a press release.
Procurement, not pilots, moves adoption. The US OneGov strategy buys for "government as one customer," with agentic deals struck centrally and FedRAMP 20x fast-authorisation clearing the path. Buy agent capabilities and tokens with pre-cleared models — not bespoke per-agency contracts that re-litigate safety each time.
If the procurement document names a product, it is the wrong question. If it names a capability provisioned once and governed for all of government, it is the right one. Agents are infrastructure, not a feature — and infrastructure is provisioned, instrumented and governed, never simply bought.
MOVEMENT B · CONTINUITY
The agentic state and the digital state are not rivals. The agentic state is what you build on top of a working digital state — and it fails without one. An agent is only as good as the identity it can verify, the registry it can trust, the tool it can call, and the human who can stop it.
The Algorithmic State Architecture (arXiv 2503.08725) models the state as four stacked layers — Digital Public Infrastructure → Data → Interoperability → Intelligence — with the intelligence (agentic) layer explicitly sitting on top of the other three. You do not skip to it; you earn it. The strategic consequence is inconvenient: nations that built X-Road-class interoperability, population-scale identity and clean registries start the agentic race with half the P0 stack already in place. Those that skipped the digital foundation will find no amount of agent procurement substitutes for it.
This is why the FDA's agency-wide agentic premarket-review rollout depends on structured submission data; why Estonia's Agentic State paper lists existing X-Road interoperability and a "sovereign tech stack" as enablers. The continuity is mechanical, not rhetorical — each load-bearing principle of the digital canon has a direct agentic successor that inherits the parent's discipline rather than replacing it. Read bottom to top, the four layers are a dependency graph, not a menu.
Agents that reason and act — grounded, supervised, governed. The capstone, reached only after the three layers beneath it.
X-Road-style signed data exchange, base registries as single source of truth. Federation reborn as MCP + A2A.
Clean, current, machine-readable, governed records. The ground truth an agent grounds against via RAG.
eID, payments rails, connectivity, sovereign cloud, zero-trust. The trust root every transaction depends on.
The agentic state is not a leap past the digital state. It is the digital state's canon — identity, registries, federation, interoperability, governance, oversight — extended to a worker that reasons and acts. The order is the strategy: L1–L3 first, intelligence last.
MOVEMENT B · CONTINUITY · THE INHERITANCE MAP
The agentic canon is the digital canon, line by line, with one world-changing clause added: the actor is now a worker that reasons and acts. Where a NATI principle has a direct digital ancestor, the synthesis flags it [↔ Pn]. The map below reads the agentic layer against the national-architecture canon.
| Digital-state principle / component | Its agentic successor |
|---|---|
| eID + assurance levels (trusted identity at the root of every transaction) | Agent identity + authenticated delegation — every agent has a verifiable identity; a citizen or official grants it scoped, time-bounded, revocable authority (OAuth/OIDC extended, arXiv 2501.09674). |
| Base registries (single source of truth) | Agent-ready registries / RAG ground truth — clean, queryable systems of record the agent grounds against; what it generates is a derived view, never an alternative truth. |
| X-Road federation (autonomous nodes, signed point-to-point exchange) | MCP + A2A — agent-to-tool (Model Context Protocol) and agent-to-agent (Agent2Agent) standards: federation reborn at the agent layer. |
| Interoperability framework (EIF; reusable building blocks; RIHA catalogue) | Tool & agent registries — a governed catalogue of approved tools and agents with capability metadata and assurance status (AGNTCY Agent Directory). |
| Zero-trust security (PDP/PEP, continuously verified, least privilege) | Action-scoping + kill-switch — per-agent least-privilege action sets, default-deny on irreversible operations, a tested emergency stop and rollback. |
| Once-only principle (don't re-ask for what the state already holds) | Governed tiered memory — working, long-term and episodic case memory, governed as a regulated personal-data store (purpose limits, retention, deletion). |
| Central digital agency (binding reference architecture, law, targets) | Central agent authority — one accountable owner of the national agent platform, under law defining permissible autonomous action and liability. |
| Tamper-evident logging (Estonia's KSI ledger) | Agent observability + immutable logs — queryable, tamper-evident records of reasoning, tool calls and actions: the precondition for any audit. |
The optimal national agentic architecture is the same sentence as the digital one — a federated, API-first, building-block platform with a trusted identity at its root and a signed exchange layer instead of a central database — now staffed by governed, grounded, supervised agents that reason and act on top of it.
MOVEMENT B · THE FRAMEWORK
The reference design is one stack of eight layers, sitting atop a healthy digital state. Two layers — Trust & Control (L4) and the Governance Spine (L8) — are cross-cutting. The win is not any single exotic pattern; it is having all eight wired together.
| Layer | What it is | Tier |
|---|---|---|
| L8 | Governance Spine (cross-cutting) — binding risk framework · liability law · central agent authority · eval harness · oversight | P0 |
| L7 | Experience & Mission — citizen super-assistant · civil-servant copilots · policy twin · proactive life-event services | P0 |
| L6 | Orchestration — durable stateful workflows · orchestrator-worker · A2A federation · human-approval nodes | P1 |
| L5 | Agent Runtime — reason–act–verify loop · reflection · planning · skill library | P0 |
| L4 | Trust & Control (cross-cutting) — agent identity · delegation · action scopes · kill-switch · observability · gateways | P0 |
| L3 | Tools & Integration — MCP servers over every system · tool/agent registry · computer-use legacy bridge | P0 |
| L2 | Data, Knowledge & Memory — agent-ready registries · RAG · vector+graph · context engineering · governed memory | P0 |
| L1 | Compute & Models — governed frontier + sovereign models · model gateway · managed inference · cost routing | P0 |
Role. The engine every agent runs on. P0 component: governed frontier-model access (#1). Signal: ~15–25 nations run a governed national model-access programme; USAi abstracts many models behind one gateway. P0 bedrock
Role. What agents know and remember. P0 component: authoritative, agent-ready registries (#8) + RAG layer (#10). Signal: interoperable base registries in ~40 nations; agent-ready in fewer. P0 bedrock
Role. How agents reach the world. P0 component: MCP tool layer (#41) — the "USB-C for AI." Signal: standard ~18 months old; early adoption in a handful of leaders. P0 bedrock
MOVEMENT B · THE FRAMEWORK · CONTINUED
The middle of the stack is where autonomy is made survivable. L4 (Trust & Control) is cross-cutting: nothing autonomous ships before it. L5 builds the worker; L6 makes it run for hours and across agencies.
Role. The structural member that makes autonomous action legally survivable. P0 component: agent identity (#33) + authenticated delegation (#34) + secure gateways (#40), with action-space constraints, a tested kill-switch (#36) and immutable observability (#37). Signal: production-grade national agent-identity exists in single digits of nations (est.). This is the gate the whole stack turns on.
Role. How the worker itself works — the atomic unit of agency. P0 component: the standard reason–act–verify loop (#23), from ReAct and the Claude Agent SDK, with reflection (#24, Reflexion) and planning (#25) layered on. The verify step separates a reliable agent from a confident-but-wrong one. Signal: the de-facto standard in every serious build (est.).
Role. Turning a fragile prompt-chain into a durable process that survives crashes and hand-offs. P1 component: a stateful orchestration runtime (#27, LangGraph/AutoGen) with orchestrator-worker decomposition (#28), A2A inter-agency federation (#42) and human-approval nodes. Signal: standard tooling embedded in leading platforms; multi-agent orchestration a front-runner-only differentiator (est.).
Supervised autonomy — bounded action, mandatory human gates, agent identity, authenticated delegation, full observability, a tested kill-switch — is the only pattern that appears in every credible governance source: the UK AI Playbook, NASCIO, the EU AI Act's high-risk requirements, OpenAI's practices. For a state it is not a constraint on the architecture. It is the architecture.
MOVEMENT B · THE FRAMEWORK · CONTINUED
The top of the stack is where citizens meet the agentic state, and the spine that runs through all of it. L7 is built last and continuously; L8 in parallel from day one. An L7 mission deployed without L1–L6 beneath it is the most dangerous configuration in the design.
Role. The visible agentic state — where policy becomes daily service. P0 component: citizen super-assistants, civil-servant copilots, a national policy twin and proactive life-event services — all bounded and human-gated. Signal: the UAE's agents-in-service vision; Singapore's NAIS 2.0; the Tony Blair Institute's "Reimagined State." Where to start: the Alan Turing Institute found ~41% of GB public-sector working time is supportable by generative AI (49% in education) — target the highest-volume, highest-burden, lowest-risk functions first.
Role. Governance is architecture; for agents that act, it is the load-bearing wall. P0 components: a binding national risk framework (#48 — NIST AI RMF / EU AI Act / Singapore's Model Gov Framework) and a mandatory eval harness (#47 — AgentBench, GAIA, τ-bench's pass^k metric), plus a liability chain (#38) and an oversight institution (#49). Signal: a binding framework applied to agents exists in ~10–20 nations; mandatory eval regimes in very few (est.). τ-bench's finding that agents fail on repeated-trial consistency is the single most important deployment caution in the collection.
The 50 components map onto the eight layers. The distinctively agentic P0 set is the gate almost every nation fails:
P0 frontier model access P0 agent-ready registries P0 RAG layer P0 tool-use / function calling P0 MCP tool layer P0 agent identity P0 authenticated delegation P0 secure gateways P0 human-in-the-loop gates P0 observability + logs P0 governed memory P0 eval harness P0 binding risk framework P0 national agent platform P1 sovereign inference P1 model gateway P1 orchestration runtime P1 A2A interop P2 GraphRAG P2 multi-agent P3 edge inference P3 computer-use bridge
Pre-requisite: fix the digital state. Then L1–L2 foundation → L3–L4 trust spine (nothing autonomous ships before L4) → L5–L6 runtime → L8 governance in parallel from day one → L7 mission last and continuously. The order is the strategy.
MOVEMENT B · THE GLOBAL LANDSCAPE
Readiness for the agentic state is not one number; it is two. A nation's position is set by the maturity of its digital foundation (eID, registries, exchange, cloud) and its agentic capacity (platform, identity/delegation, eval, MCP). Plot the two and four quadrants appear — and almost everyone is in the wrong one.
| Low agentic capacity | High agentic capacity | |
|---|---|---|
| Strong digital foundation | Primed. Half the agentic P0 stack already built (registries, eID, exchange) but no platform, agent identity or eval yet. Estonia, Denmark/Nordics, Korea, India. | Agentic frontier. Foundation + the agentic P0–P1 layer wired on. Fewer than ~10 nations; perhaps 2–3 done well. United States (federal), Singapore, UK, leading US states. |
| Weak digital foundation | Behind the gate. Neither layer. Buying agents here yields demos, not infrastructure — you automate dysfunction at machine speed. The long tail of the ~190 economies in the GTMI. | Built on sand. Mission ambition and procurement energy without clean registries or identity beneath — the most dangerous quadrant. The cautionary case for any nation that skips L1–L4. |
The empirical spine beneath the map is the global connectivity and government-tech census — the floor every agentic deployment stands on:
MOVEMENT B · THE GLOBAL LANDSCAPE · READINESS
Network readiness is the best available proxy for the digital foundation the agentic race is run on. The Network Readiness Index 2024 ranks 133 countries; its leaders are the same nations closest to the optimal agentic stack.
But readiness only describes the foundation. The agentic scorecard ranks each leader by the archetype it is strongest at — and names the gap that keeps even the front-runners short of the full optimal stack:
| Nation / bloc | Strongest archetype | Main gap |
|---|---|---|
| US (federal) | Sovereign platform | Coherent governance across a fast rollout (USAi + OneGov + FDA agents). |
| Estonia | Federation + capstone | Scaling the Agentic State framework to a production platform. |
| United Kingdom | Supervised autonomy | A unifying agent platform at USAi scale (AI Playbook + Turing). |
| Singapore | Platform + governance | Moving from copilots to bounded autonomy (NAIS 2.0 + AI Verify). |
| UAE | Mission / experience | Open governance + eval depth (Minister of AI; agents in visas). |
| EU (bloc) | Federation + governance | Speed — turning frameworks into deployed platforms (Apply AI). |
| Leading US states | Supervised autonomy | Shared platform + identity depth (8+ in production — NASCIO). |
No nation has the full optimal stack. The frontier is a composite — the US's platform + Estonia's foundation + the UK's assurance discipline + Singapore's governance toolkit + the EU's binding risk law + the UAE's mission ambition. The agentic race is run on the foundations laid by the digital race.
MOVEMENT B · THE SCORING LENS
Every component and architecture in this report is placed on a five-step priority ladder. The tiers are not a wish-list; they are a dependency graph. P0 is what you build first because without it there is no safe agentic action at all.
P0 Bedrock P1 Core P2 Differentiator P3 Advanced P4 Frontier
| Tier | Definition | Who has it |
|---|---|---|
| P0 · Bedrock | Without it there is no safe agentic action. Build first. 19 components. | Inherited digital P0: dozens. Agentic P0: single digits to ~15 nations. |
| P1 · Core | Defines a serious agentic state; present in the leaders. 16 components. | ~5–20 — US, EU bloc, UK, Singapore, UAE, Estonia, leading US states. |
| P2 · Differentiator | Separates front-runners from followers. 9 components. | ~3–10 — GraphRAG, multi-agent, skill libraries, agent registries. |
| P3 · Advanced | Top-tier only. 4 components. | ~2–8 — edge inference, computer-use at scale, episodic memory. |
| P4 · Frontier | The fully agent-native state — intelligence as capstone. | ~1–3 — the state that built every layer beneath it first. |
Agentic infrastructure is two-to-three years old as a governed national concern, so there is no ITU-grade census of it. Every adoption figure in this report is therefore one of three kinds, always labelled — and the reader should weigh them accordingly.
Drawn directly from sources: 8+ US states in production (NASCIO 2026); the FDA's rollout; USAi & GenAI4EU exist; ITU/World-Bank census numbers. Cited to source, treated as fact.
For components the agentic state reuses from the digital state — identity, registries, cloud — counted via folder 04's indices (~40 nations with interoperable registries). Solid, but a floor: digital ≠ agent-ready.
Reasoned, order-of-magnitude bands marked (est.) — triangulated from the strategy literature. Never precise counts.
On the foundational digital components agents depend on, dozens of nations qualify. On the distinctively agentic components — agent identity, delegation, eval harnesses, governed memory, the MCP layer, the national platform — the number with a governed, production-grade capability is in the single digits to low tens. That is precisely why the window is open.
FAMILY A · SYSTEMIC & STRATEGIC
The agentic state is not an AI strategy PDF or a chatbot procurement; it is a governed expansion of the state's capacity to act, built deliberately on top of a working digital foundation and resourced like headcount.
Family A contains the strategy's spine: P2 and P6 are non-negotiable 🟥 foundations — a working digital state and a governing authority. Skip them and everything above is an expensive demo.
FAMILY B · AGENT DESIGN & REASONING — I
Autonomy is a cost and a risk, spent only where dynamism is genuinely required. The atomic unit of agency is an inspectable reason–act–observe loop — and legibility is a governance asset, not a luxury.
A loop you cannot read is a loop you cannot govern. Interpretability is not a nicety in the public sector — it is the precondition for accountability.
The first half of Family B fixes the shape of a public-sector agent: simplest-pattern-first, an explicit ReAct loop, a mandatory verify step, self-correction, and visible planning. Two of these five (P11, P12) are 🟥 foundational — they govern whether an agent can be inspected and trusted at all.
FAMILY B · AGENT DESIGN & REASONING — II
An agent without tools is a text generator; an agent with the right tools is a worker. Memory turns a chatbot into a colleague — and a colleague whose reasoning, plans and tool calls are all on the record.
P16 is the hinge of the whole stack: capability is dominated not by the model but by the catalogue of governed tools an agent can reach. It is why Family F (tools & integration) carries five 🟥/🟧 principles of its own — and why a national platform should out-invest its models with its connectors.
FAMILY C · MODELS & COMPUTE
Agents are only as capable as the models beneath them, and frontier capability is concentrated in a handful of providers. Model access is now the agentic equivalent of energy security — to be secured, diversified and managed, never assumed.
P24, P25 and P26 are one argument in three parts: agentic inference is bursty, fan-out is expensive, and naïve deployment meets a cost cliff on first contact with population scale. Managed capacity, model routing and latency SLOs are what keep the engine room affordable.
FAMILY D · DATA & STATE
Everything an agent produces is a derived view, never an alternative truth. Authoritative registries are the ground truth; data readiness is a precondition, not a parallel workstream; and an agent's memory of citizens is regulated personal data.
Family D's spine is P28–P29–P35: registries are truth, readiness precedes deployment, and memory is regulated. Three of eight principles here are 🟥 foundational — the highest concentration of any family, because an agent that automates dirty data simply scales the error.
FAMILY E · IDENTITY, TRUST & ACCOUNTABILITY
An action you cannot attribute is an action you cannot govern. This is the densest 🟥 family in the canon: identity, scoped delegation, liability, action gating, human oversight, an interruptible kill-switch and real-time observability — six of seven are foundational.
"The AI did it" must never be a valid defence. For every consequential agent action there is a named responsible human or institution, or there is no deployment.
FAMILY F · TOOLS & INTEGRATION
Tool calls into government systems must pass through the same secure, signed, logged discipline as X-Road traffic — never direct database access. Standardise the connector, standardise agent-to-agent coordination, and treat discovery as infrastructure.
Family F is X-Road for agents. P43 (MCP) is the connector, P44 (A2A) is cross-agency federation, P45 is the RIHA-style registry, and P48 is the signed gateway. The digital state's interoperability canon is not replaced — it is extended to a caller that reasons and acts.
FAMILY G · EVALUATION, SAFETY & RESILIENCE
The smallest family carries the two most absolute rules: no deployment without an evaluation harness, and a binding national risk-management spine. For agents that act, governance is not paperwork — it is architecture.
τ-bench's finding that agents frequently fail on repeated-trial consistency — passing once, then failing the same task on retry — is why P49 demands reliability-under-repetition, not just a one-shot benchmark. An agent that works in the demo and fails the fourth caller is not deployable.
The principles are a dependency graph, read as a sequence of four tiers.
The agentic state is not a leap past the digital state — it is the digital state's canon (identity, registries, federation, interoperability, governance, oversight) extended to a worker that reasons and acts.
MOVEMENT C · §15 · THE 50 COMPONENTS
An agent is only as capable as the model it runs on and the silicon that serves it. Layer 1 is the engine room: governed access to frontier reasoning, a sovereign fallback for data that cannot leave the country, and the burst capacity that population-scale agent fan-out devours. Two of its seven components are P0 — without model access and serving capacity there are simply no agents.
| # | Component | Tier | What it is | Adoption |
|---|---|---|---|---|
| 1 | Frontier model access (governed) | P0 | Assured, governed access to frontier LLMs — the reasoning engine every agent runs on | ~15–25 nations (est.) |
| 2 | Sovereign / open-weight inference path | P1 | In-country, controllable inference for data that cannot leave national control | ~10–15 nations (est.) |
| 3 | Managed inference capacity | P0 | GPU/accelerator serving capacity for inference-heavy, bursty agent workloads | ~20–30 nations (est.) |
| 4 | Model gateway / abstraction layer | P1 | A stable internal API hiding specific providers — optionality, no lock-in | ~10–20 nations / inst. (est.) |
| 5 | Cost-and-capability routing | P2 | Sends each step to the cheapest model that can do it | Few national platforms (est.) |
| 6 | Inference observability & FinOps | P2 | Telemetry on token spend, latency, throughput per agent, with quotas | Minority of platforms (est.) |
| 7 | Edge / low-latency inference | P3 | Inference pushed to the edge for latency-sensitive, data-local tasks | Handful of nations (est.) |
Effectively every nation can buy API access; almost none has governed access — central contracts plus a routing layer so agencies draw only on vetted models. The flagships are the US USAi platform and the EU's GenAI4EU; governed national programmes exist in an estimated 15–25 nations, clustered among the US, UK, Singapore, the UAE and the Gulf, and China. The gap between "can buy" and "governs" is the first place the curve bends.
Agent tasks fan out into many model calls, so serving capacity — not model quality — is the binding constraint at scale. National AI-compute initiatives (the US AI Action Plan infrastructure pillar, EU, UK, Gulf, India, Japan, Korea) put roughly 20–30 nations in the frame, but explicit capacity reservation tuned for bursty agentic load remains rarer than the headline count suggests.
MOVEMENT C · §15 · THE 50 COMPONENTS
Agents automate whatever data quality they are fed; bad registries plus agents produce errors at machine speed. Layer 2 is the substrate of ground truth — authoritative registries, a data-readiness programme, and the retrieval pipeline that grounds every official answer in a citable source. Three of its nine components are P0: registries, governance, and RAG are not parallel work, they are prerequisites.
| # | Component | Tier | What it is | Adoption |
|---|---|---|---|---|
| 8 | Authoritative, agent-ready registries | P0 | Clean, current, machine-readable systems of record — the ground truth agents act on | ~40 base; fewer agent-ready (est.) |
| 9 | Data-readiness & governance programme | P0 | Quality, lineage, access rights, stewardship over data agents consume | ~30–50 nations (est.) |
| 10 | Retrieval-Augmented Generation (RAG) layer | P0 | Pipeline grounding agent output in authoritative sources | Most serious pilots (est.) |
| 11 | Vector knowledge store | P1 | Dense embedding index for semantic search over unstructured corpora | Standard where RAG runs (est.) |
| 12 | Graph knowledge store / GraphRAG | P2 | Entity-relationship graphs for multi-hop, verifiable reasoning | Minority of platforms (est.) |
| 13 | Context-engineering layer | P1 | Discipline of assembling, compressing, ordering what enters the context window | Formalised in few (est.) |
| 14 | Long-context capability | P2 | Million-token models holding large state in-context | Any frontier-model user |
| 15 | Structured-output / schema layer | P1 | Typed, schema-constrained outputs that are auditable and chainable | Standard in mature builds (est.) |
| 16 | Consent / data-empowerment for agents | P2 | Consent infrastructure governing what data agents may access & remember | DEPA-style ~15; agent-aware few (est.) |
Interoperable digital base registries exist in roughly 40 nations, but agent-ready — clean, exposed via governed APIs, with lineage an agent can cite — is a higher bar that fewer clear. This is the inheritance thesis in miniature: the nations that built the digital foundation start the agentic race with this component half-built; the nations that did not will find that buying agents on dirty registries yields confident, fast, wrong answers.
Ungrounded generation on official matters is a defect, not a feature. The RAG pipeline — chunk, embed, index, rewrite, re-rank — wires an embedding model and a vector index into the agent loop so every answer traces to an authoritative source. It is ubiquitous in private deployments and a standard component of most serious national pilots; the differentiator is no longer having RAG but governing its corpus and provenance.
MOVEMENT C · §15 · THE 50 COMPONENTS
Memory turns an agent from a one-shot tool into an institution that carries a case across sessions and learns from experience. Layer 3 climbs from the context-window scratchpad every agent has, through OS-style paging and episodic streams, to the governed memory store the law actually requires — because an agent's memory of citizens is personal data. Two P0s anchor it: working memory, and the regulated store that makes the rest lawful.
| # | Component | Tier | What it is | Adoption |
|---|---|---|---|---|
| 17 | Short-term / working memory | P0 | The context window as the agent's active scratchpad for the current task | Universal to any agent |
| 18 | Long-term memory with paging | P1 | OS-style tiered memory (MemGPT) for an unbounded effective horizon | Leading platforms (est.) |
| 19 | Episodic memory | P2 | Time-stamped memory stream retrieved by recency × importance × relevance | A minority (est.) |
| 20 | Semantic memory & reflection | P2 | Distilled higher-level facts synthesised from raw episodes, with forgetting | Research→early prod. (est.) |
| 21 | Governed memory store (regulated data) | P0 | Agent memory treated as regulated personal data — purpose limits, retention, deletion | Operationalised in very few (est.) |
| 22 | Skill / workflow library | P2 | Catalogue of validated, reusable agent skills shared across agencies | A few leaders (est.) |
The moment an agent remembers a citizen, its memory becomes a regulated personal-data store — subject to purpose limitation, retention limits and deletion rights, with audit over every read and write. The governance literature recognises this as a requirement; almost no nation has operationalised it. It is the quietest P0 in the catalogue and one of the most consequential: an ungoverned memory is a standing data-protection breach that compounds with every interaction.
A versioned national repository of approved agent workflows is the agentic eGovFrame — build once, reuse many. Following Voyager's skill-library pattern, validated skills become shared assets across ministries rather than re-implemented per agency. It is nascent: a few leaders are assembling catalogues, but most builds still reinvent the same casework loop in every department, paying the integration cost repeatedly.
MOVEMENT C · §15 · THE 50 COMPONENTS
Layer 4 is the mechanics of agency: the reason–act–verify loop, the tool-calling that turns a text generator into a worker, the approval gates that hold a human in command of consequential action, and the orchestration runtime that carries a workflow over hours or days. Four P0s define it — the loop, tool use, human-in-the-loop gates — and they are where "demo" becomes "infrastructure."
| # | Component | Tier | What it is | Adoption |
|---|---|---|---|---|
| 23 | Standard agent loop (reason–act–verify) | P0 | Explicit, inspectable gather→act→verify loop — the atomic unit of agency | De-facto standard (est.) |
| 24 | Reflection / self-correction | P1 | Generate–critique–revise loops that catch the system's own errors | Leading deployments (est.) |
| 25 | Planning & task decomposition | P1 | Decompose a goal into an ordered, adaptable plan exposed for audit | Standard in complex agents (est.) |
| 26 | Tool-use / function-calling | P0 | Deciding when/how to call external tools and folding results back | Universal; safe use is the gap |
| 27 | Orchestration runtime (stateful) | P1 | Control plane for long-running, multi-step workflows with persistence & recovery | Leading platforms (est.) |
| 28 | Multi-agent orchestration | P2 | Manager agent decomposing work and delegating to specialised workers | Front-runners only (est.) |
| 29 | Human-in-the-loop approval gates | P0 | Mandatory review/override before consequential or irreversible actions | 8+ US states; leaders (NASCIO 2026) |
| 30 | Verification / self-test step | P1 | A check or second agent before committing an action | Leading practice (est.) |
| 31 | Computer-use / browser-agent | P3 | Agents operating human UIs directly for un-API'd legacy systems | Pilots in a few nations (est.) |
| 32 | Workflow-vs-agent decision standard | P2 | Published guide mapping task properties to the simplest sufficient pattern | Rare as national policy (est.) |
The universal guardrail across the UK Playbook, NASCIO and the EU AI Act: mandatory review and override before any irreversible action, implemented as approval nodes in the runtime. One of the few agentic P0s with a hard signal — 8+ US states run agentic tools with these gates operationalised (NASCIO 2026).
An explicit gather-context → act → verify loop (ReAct, the Claude Agent SDK) is the atomic unit of agency and the basis of interpretability: an inspectable loop is an auditable agent. It is de-facto standard in every serious build — so the differentiators live upstairs in orchestration and downstairs in trust.
MOVEMENT C · §15 · THE 50 COMPONENTS
This is the load-bearing layer of the agentic state — the agentic extension of eID. An unattributable action is an ungovernable one, so every agent needs a verifiable identity, a scoped and revocable mandate, a least-privilege action space, an immutable log, and a named human on the legal hook. Six of its eight components are P0, more than any other layer, and they are exactly where adoption is thinnest.
| # | Component | Tier | What it is | Adoption |
|---|---|---|---|---|
| 33 | Agent identity service | P0 | Verifiable identities for every agent instance — attribution of action | Single digits of nations (est.) |
| 34 | Authenticated delegation infrastructure | P0 | Scoped, time-bounded, revocable, logged authority — OAuth/OIDC for agents | Very few nations (est.) |
| 35 | Action-space constraint / least-privilege | P0 | Per-agent action sets, default-deny on irreversible operations | Inconsistently done (est.) |
| 36 | Kill-switch & interruptibility | P1 | A tested emergency stop and rollback for every production agent | Tested in few (est.) |
| 37 | Agent observability & immutable logging | P0 | Real-time monitoring + immutable logs of reasoning, tool calls, actions | Leaders (est.) |
| 38 | Liability & accountability framework | P0 | Legal chain naming a responsible human for every consequential action | Binding regimes in few (est.) |
| 39 | Guardrails & policy-enforcement layer | P1 | Content/safety filters, domain rules, output provenance on agent actions | Adopted by leaders (est.) |
| 40 | Secure agent-to-system gateways | P0 | Policy-enforcing gateways between agents and systems — the X-Road discipline | Inherited; agent-specific in leaders (est.) |
Issuing and managing verifiable identities for every agent instance is the foundation of the whole trust layer — an action no one can attribute is an action no one can govern. The fix is to extend existing national identity infrastructure to issue agent identities. It is a recognised requirement, yet production-grade national agent-identity exists in only single digits of nations. This is the single steepest fall in the catalogue.
The agentic extension of eID: the ability for a citizen or civil servant to grant an agent a scoped, time-bounded, revocable, logged authority — OAuth/OIDC extended for agents. It is the technical basis of "acting on behalf of," and it is emerging in only very few nations as actual plumbing. Without it, every agent action is either over-privileged or unattributable; with it, delegation becomes governable infrastructure.
MOVEMENT C · §15 · THE 50 COMPONENTS
The final two layers reach outward and upward. Layer 6 is how agents touch the world — the MCP tool layer (the national "USB-C for AI"), agent-to-agent federation, registries, and the unifying national platform every ministry should inherit. Layer 7 is the governance spine: the mandatory eval harness, the binding risk framework, the oversight institution, and the workforce that works alongside agents. Five P0s span the two.
| # | Component | Tier | What it is | Adoption |
|---|---|---|---|---|
| 41 | Model Context Protocol (MCP) tool layer | P0 | Every system exposed as a governed MCP server — the national "USB-C for AI" | Handful of leaders (est.) |
| 42 | Agent-to-agent interoperability (A2A) | P1 | Open standard letting agents discover & delegate across vendors & ministries | Nascent; pilots (est.) |
| 43 | Agent & tool registry / discovery | P1 | National registry of approved agents/tools with capability & assurance metadata | Very few registries (est.) |
| 44 | Tool-calling correctness & scale tooling | P2 | Map intent to correct API calls across thousands of services, no hallucination | Front-runners (est.) |
| 45 | Integration to legacy via computer-use bridge | P3 | Governed computer-use as a monitored bridge to never-API'd systems | Early pilots (est.) |
| 46 | National agent platform (unifying substrate) | P0 | Shared platform binding models, tools, memory, guardrails, observability | ~5–15 nations (est.) |
| 47 | Agentic evaluation harness | P0 | Required eval suite — capability, reliability (pass^k), safety, policy adherence | Mandatory regimes very few (est.) |
| 48 | National AI risk-management framework (binding) | P0 | Master control spine — NIST AI RMF / EU AI Act tiers / Singapore MGF | Binding & applied ~10–20 (est.) |
| 49 | Oversight & assurance institution | P1 | A body & process for human oversight, escalation, independent assurance | A minority of nations (est.) |
| 50 | Workforce & capability programme | P1 | Training civil servants to work with agents; role-transition planning | ~20–40 nations (est.) |
Every registry and line-of-business system exposed as a governed MCP server with a typed contract — the national USB-C for AI. Platform value is dominated by the breadth of tools agents can safely call. The standard is ~18 months old; national adoption sits in a handful of leaders.
The shared substrate binding models, tools, memory, guardrails and observability so every ministry inherits safety rather than re-inventing it — government-as-a-platform, agentic. Real platforms exist in ~5–15 nations: USAi, GenAI4EU, the UK, Singapore, the UAE, Estonia.
τ-bench shows agents fail on consistency, so no eval means no deploy — yet mandatory regimes exist in very few nations. The binding risk framework (NIST AI RMF, EU AI Act, MGF) is the load-bearing wall; applied to agents, live in ~10–20.
MOVEMENT C · §15 · THE CENTRAL FINDING
Read the 50 components down their priority tiers and the catalogue resolves into one shape: a steep descending curve. On the foundational digital pieces agents reuse, dozens qualify. On the distinctively agentic components — agent identity, delegation, eval harnesses, registries — the count with a governed, production-grade capability is single digits to low tens, falling toward one or two at the frontier.
For digital infrastructure, nearly every nation held the P0 layer and the drop-off came later, at P2–P4. For agentic infrastructure it starts almost immediately: the seven distinctively agentic P0 components exist together in fewer than ~10 nations. The curve does not taper — it cliffs.
The optimal agentic architecture is not exotic — it is the agentic P0–P1 components built and wired onto a healthy digital state. Almost no one has done it yet.
MOVEMENT C · §15 · THE CENTRAL FINDING
The short leaderboard is not a counsel of despair — it is the strategic opening. Because the agentic P0–P1 layer is held by so few, a nation that already built the digital foundation can leap to the front of a race barely two years old. The table restates the curve as a stepped ledger: how many nations clear each tier, and what the tier gates.
| Tier | Comp. | Nations (est.) | Who has them & what the tier gates |
|---|---|---|---|
| P0 Bedrock | 19 | digital: dozens agentic: <~15 | The agentic P0 — identity, delegation, eval harness, governed memory, MCP, platform, binding risk framework — is the real gate |
| P1 Core | 16 | ~5–20 | The "serious agentic state" band: US, the EU bloc, UK, Singapore, UAE, Estonia |
| P2 Differentiator | 9 | ~3–10 | GraphRAG, multi-agent orchestration, skill libraries, registries |
| P3 Advanced | 4 | ~2–8 | Edge inference, computer-use at scale, episodic memory in production |
| P4 Frontier | — | ~1–3 | The fully agent-native state — folded into P3 |
The nations that built the digital foundation — Estonia, Singapore, the UAE, the UK, leading US states — start the agentic race with components 8 (registries), 9 (data governance), 16 (consent), 40 (secure gateways) and 46 (national platform) already half-built. The agentic state is the digital state's canon — identity, registries, federation, interoperability, governance, oversight — extended to a worker that reasons and acts. The nations that did not face the harder lesson: buying agents without the foundation yields demos, not infrastructure — a fast, confident way to be wrong at population scale.
Hard figures — 8+ US states in production (NASCIO 2026), the FDA agency-wide rollout, USAi and GenAI4EU — are cited to source. Inherited digital-state counts trace to the digital components catalogue. Every (est.) figure is a reasoned, order-of-magnitude band: no global census of national agentic infrastructure yet exists, and any single precise number should be treated with caution.
PART 1 · THE RANKED ARCHETYPES — 1 OF 6
The ten types are not rivals but emphases; a mature national stack braids several together. They are presented below to a single anatomy — shape, why it ranks, trade-off, exemplars and a tier/role chip — so the run reads as one comparable family.
A single, centrally-provisioned national platform giving every agency shared model access (behind a gateway), shared tools (via MCP), shared memory, guardrails, observability and an eval harness — at no marginal cost. Ministries build agents on the platform rather than buying them piecemeal.
The agentic successor to Singapore's SGTS and the UK's GDS — the single highest-leverage move a state can make. It is where every other principle is operationalised once: safety, identity, evaluation, cost control. Without it a nation gets a thousand ungoverned pilots; with it, governed infrastructure.
Needs a powerful, well-funded central authority and the political capital to make the platform mandatory. Weaker fit for highly federal states unless paired with the federation pattern (#5).
THE RANKED ARCHETYPES — 2 OF 6
Every consequential agent is a reason–act loop whose every factual claim and action is grounded in retrieval from authoritative sources — base registries, law, policy, case files — through a RAG layer (vector + graph), with citations and structured outputs. Ungrounded generation on official matters is treated as a defect.
For a state, correctness and provability outrank cleverness. The foundational RAG work and the RAG survey establish grounding as the antidote to hallucination; OECD/GPAI makes authoritative government data the ground truth agents must act on. This is what makes an agent's output defensible — it can show its sources.
Quality is bounded by data readiness; on a messy registry the RAG-agent faithfully retrieves garbage. It forces the correct but expensive discipline of data-readiness first.
For a state, correctness and provability outrank cleverness. A government that deploys ungrounded agents on official matters is automating unaccountability.
A manager/orchestrator agent decomposes a complex task, delegates sub-tasks to specialised worker agents, and synthesises their results — the agentic analogue of a case team. Both Anthropic's Building Effective Agents and OpenAI's Practical Guide name this the primary multi-agent pattern.
Government work is cross-domain — one benefit claim may touch identity, tax, health and housing. Specialised agents, each with its own tools and policy scope, cooperate under one coordinator, scaling to casework a single agent cannot hold. It maps naturally onto the federated structure of government itself.
Coordination overhead, error propagation between agents, harder debugging. Anthropic's own guidance: don't reach for multi-agent until a single agent provably cannot do the job.
THE RANKED ARCHETYPES — 3 OF 6
Agents operate autonomously within bounded action spaces, but every consequential or irreversible action passes through a mandatory human approval gate, with escalation paths, full observability and a tested kill-switch. Autonomy is earned level-by-level up a maturity model.
The only pattern that appears in literally every credible governance source — the UK AI Playbook, NASCIO's maturity model, the EU AI Act's high-risk requirements, OpenAI's governance practices, the oversight paper (arXiv 2506.04836). For a state, supervised autonomy is not a constraint on the architecture; it is the architecture — what makes autonomous action politically and legally survivable.
Human gates cap throughput and can decay into rubber-stamps when the reviewer lacks time, information or authority. The design challenge is meaningful oversight, not theatrical oversight.
Each agency runs its own agents over its own systems; agents discover and delegate to each other across boundaries via an open agent-to-agent standard (Agent2Agent's capability-advertising "Agent Cards"; AGNTCY's federated Agent Directory). No central monolith — a mesh of autonomous, interoperating agents, mirroring X-Road's federation at the agent layer.
The agentic reincarnation of the #1 digital archetype (X-Road federation). It preserves agency autonomy and data ownership while enabling cross-agency action — a citizen-services agent securely delegating a sub-task to a tax or registry agent it discovered. For large, federal, sovereignty-conscious states it is the natural shape.
Nascent standards (A2A donated to the Linux Foundation only in 2025), immature security/trust models for cross-agent delegation, and harder end-to-end accountability across a mesh.
THE RANKED ARCHETYPES — 4 OF 6
Every government registry, database and line-of-business system is exposed as a governed MCP server with a typed contract; agents are MCP clients that integrate through one standard — "build once, integrate everywhere." The state's API estate becomes a uniform, discoverable tool-surface, behind policy-enforcing gateways.
The agent surveys and the tool-use literature (Toolformer, Gorilla, ToolLLM) are unanimous: an agent's value is dominated by the tools it can safely call. MCP is the emerging open standard that turns the whole government estate into agent-callable tools without bespoke wiring — the agentic extension of the digital state's API-first principle, and the substrate beneath every other pattern.
Exposing systems as tools multiplies the attack surface; demands rigorous gateway-level auth, scoping, rate-limiting and logging. The standard is young and evolving.
Long-running processes — a visa case, a procurement, a benefits review — are modelled as durable, stateful graphs (LangGraph-style): nodes are agents/tools/decision points, state is checkpointed and persisted, and the workflow survives failure, supports retries and interposes human-approval nodes. Process, not chat, is the unit.
Real public-service work runs for hours, days or weeks and must survive crashes, restarts and hand-offs. Orchestration runtimes provide the persistence, branching and recovery that turn a fragile prompt-chain into a durable business process — the pattern that makes agents reliable enough for casework rather than just Q&A.
Engineering complexity; modelling government processes as graphs is real work and can ossify if not maintained.
THE RANKED ARCHETYPES — 5 OF 6
Agents critique and revise their own work before committing it — a generate→critique→revise loop, often with a separate evaluator agent — and store lessons from failures in episodic memory (Reflexion's verbal reinforcement learning; the evaluator-optimizer workflow). The verify stage of the Claude Agent SDK loop is the production form.
In public service, a system that catches its own mistake is worth more than one marginally more accurate that never doubts itself. Reflection (arXiv 2303.11366) measurably improves reliability without retraining and produces an auditable trail of self-correction — valuable for accountability.
Extra latency and cost per task; reflection can entrench a confident error if the critic shares the generator's blind spot — hence prefer an independent evaluator.
Agents carry persistent, tiered memory — working memory (context), long-term memory with OS-style paging (MemGPT), episodic memory (the recency–importance–relevance stream of Generative Agents) and consolidated semantic memory — all governed as regulated personal data. The agent carries a case across sessions and accumulates institutional knowledge.
Statelessness is the difference between a chatbot and a colleague. For recurring relationships — a citizen's multi-year benefits history, an ongoing investigation — memory is what makes the agent useful and humane. The memory literature gives the architecture; the governance literature insists it be regulated.
Agent memory of citizens is a serious privacy and security liability — it must be purpose-limited, retention-bounded, deletable and audited, or it becomes a surveillance apparatus. The architecture is inseparable from its governance.
THE RANKED ARCHETYPES — 6 OF 6
For the long tail of government systems that will never expose an API, agents operate the human user interface directly — reading the screen, clicking, typing (Anthropic computer use; WebArena's web-task environment) — inside a tightly sandboxed, monitored, strictly-scoped environment, as a deliberate transition mechanism.
Every state has decades of un-API'd legacy software; without a bridge those systems are invisible to agents and the agentic state stalls at its own legacy boundary. Computer-use is the pragmatic — and genuinely powerful — bridge. It ranks last because it is also the highest-risk integration mode: an agent with general UI control and weak scoping is the most dangerous configuration in this entire document.
Brittle, slow, and dangerous if under-governed; a destination only by mistake. Treat strictly as a transition while the underlying systems are API-enabled or replaced.
As with the digital archetypes, the top patterns are complementary emphases, not rivals. #1 (sovereign platform) is where you build; #4 (supervised autonomy) is how you stay safe; #2 (grounded RAG) is how you stay correct; #6 (MCP tools) and #5 (A2A federation) are how agents reach the world and each other; #3 / #7 / #8 / #9 are how the agents themselves are built; #10 is how you bridge the legacy past. The optimal stack on the pages that follow is the braid of all ten.
PART 2 · THE OPTIMAL NATIONAL AGENTIC STACK · 2026
PART 2 · WHY THIS IS THE OPTIMAL DESIGN NOW
Every credible leader — USAi, GenAI4EU, the Agentic State sovereign stack — converged on a shared platform because it lets a nation operationalise safety, identity, evaluation and cost-control once and inherit them everywhere. A thousand agency pilots cannot be governed; one platform can.
The defining risk of LLM agents is confident error; the defining requirement of public administration is defensible decisions. RAG + authoritative registries + citations resolve the tension — the agent can always show its source. Ungrounded agents on official matters automate unaccountability.
Unanimously across the governance sources, autonomous action on citizens must be bounded, gated, attributable, interruptible and overseen (EU AI Act, UK Playbook, NASCIO, OpenAI). This is not a brake on the architecture; it is a structural member of it — climb the maturity model, don't leap.
The digital state's load-bearing idea was a trusted identity at the root of every transaction. The agentic state extends it: every agent has a verifiable identity (arXiv 2401.13138) and acts only under scoped, revocable, authenticated delegation (arXiv 2501.09674) — letting an agent act on behalf of a citizen without dissolving accountability.
The single best digital archetype was X-Road's federation — autonomous nodes interoperating through a standard, no central monolith. MCP (agent-to-tool) and A2A (agent-to-agent) reproduce exactly that shape: integrate through open standards, preserve agency ownership, avoid a central black box.
Stateless, single-shot agents are toys. Tiered memory (MemGPT, Generative Agents) and self-correction (Reflexion, verify stages) make agents reliable across long-horizon casework — provided memory is governed as regulated personal data. Architecture and governance are inseparable.
The Algorithmic State Architecture models intelligence as the capstone of DPI → Data → Interoperability → Intelligence. L1–L7 are useless without the digital state beneath them, and L7 (mission) is dangerous without L1–L6. The order is the strategy.
The agentic state is the digital state's canon — identity, registries, federation, interoperability, governance, oversight — extended to a worker that reasons and acts. The win is having the agentic P0–P1 layer wired onto a healthy digital foundation — which fewer than ~10 nations have done.
The win is not any single exotic pattern; it is having all of the agentic P0–P1 components wired together onto a working digital foundation — which fewer than ~10 nations have done, and perhaps two or three have done well.
PART 2 · THE BUILD SEQUENCE
The reference design is also a sequence. Each step depends on the one beneath it; the discipline is to refuse to ship autonomy before the trust spine exists, and to roll out mission last and continuously.
The optimal national agentic architecture, in one sentence, is the same sentence as the digital one — extended by a single, world-changing clause: a federated, API-first, building-block platform with a trusted identity at its root and a signed exchange layer instead of a central database — now staffed by governed, grounded, supervised agents that reason and act on top of it. No nation has the full stack. The frontier is a composite — the US's platform, Estonia's digital foundation and framework, the UK's assurance discipline, Singapore's governance toolkit, the EU's binding risk law, the UAE's mission ambition — and the decisive fact is that the agentic race is being run on the foundations laid by the digital one.
CASE STUDY 01 · UNITED STATES (FEDERAL)
The United States is closest on the single highest-leverage move in this collection — the shared, government-wide agent platform. GSA's USAi gives every agency a unified chat, API and evaluation console over multiple leading models, free at the point of use; OneGov buys "government as one customer" with agentic deals already struck; and the FDA has taken agents from pilot to an agency-wide premarket-review rollout.
The platform pattern is the US's decisive advantage: where weaker states accumulate a thousand ungoverned pilots, Washington operationalises model access, cost-routing and an eval console once and lets agencies inherit them. The AI Action Plan ("Winning the Race") supplies the compute-and-infrastructure pillar beneath it. The gap is governance coherence: a fast, deliberately deregulatory rollout risks outrunning the supervised-autonomy discipline the rest of this report treats as load-bearing.
#1 Sovereign Agent Platform USAi is the live exemplar of government-as-a-platform, agentic edition — the agentic successor to Singapore's SGTS and the UK's GDS.
Platform maturity is racing ahead of a unifying supervised-autonomy and oversight spine. The strategic question is whether the US can keep grounding, eval harnessing and human-gating in step with a deregulatory rollout — or automate unaccountability at machine speed. The platform is there; the governing wall must keep pace.
CASE STUDY 02 · ESTONIA
Estonia did not start the agentic race; it defined it. The Agentic State vision paper (Ilves/Kilian) is the first framework for the agentic transformation of core government functions, and it could only have come from the nation with the deepest digital floor to build on: X-Road federation, population-scale eID, clean base registries and KSI tamper-evident logging.
This is the inheritance thesis made flesh. Estonia begins the agentic race with half the P0 layer already laid — a signed data-exchange bus, a trusted identity at the root of every transaction, and a RIHA registry of trusted services that is the natural ancestor of an agent registry. Its strongest archetype is therefore federation reborn at the agent layer: autonomous nodes interoperating through a standard, no central monolith. The gap is execution scale — moving from a world-leading framework to a production agent platform at USAi's reach.
#5 Federated Inter-Agent Mesh plus the capstone intelligence layer — the agentic reincarnation of the #1 digital archetype, X-Road federation.
Estonia has the design and the foundation; what it must now demonstrate is the scaled, governed production platform on top of them. The enablers the Agentic State paper itself names — agent governance, a sovereign tech stack, cyber and people — are the build-out still ahead. The foundation is unmatched; the capstone is half-built.
CASE STUDY 03 · UNITED KINGDOM
The UK leads on the dimension that makes autonomous action survivable: supervised autonomy and assurance. The AI Playbook for the UK Government sets ten principles plus procurement and assurance guidance for safe public-sector AI, and the Alan Turing Institute supplies the evidence base that tells the state where to point agents first.
Turing's Mapping the Potential quantified that ~41% of public-sector working time in Great Britain is spent on activities supportable by generative AI (49% in education) — exactly the "start where the time is, not where the hype is" discipline. Combined with the Playbook's human-oversight and assurance requirements, the UK is the clearest exemplar of the human-in-the-loop, earn-your-autonomy model. The gap is a unifying national agent platform at USAi scale — the UK has the governance and the targeting, but not yet the single shared substrate the leaders converge on.
#4 Supervised Autonomy The only pattern that appears in every credible governance source — and the one the UK has institutionalised earliest through the Playbook + assurance.
The UK has the assurance discipline and the evidence-led targeting but lacks a single shared agent platform at USAi's reach. Governance without a platform governs nothing at scale; the next move is to wire the ten principles into one inherited substrate every department builds on.
CASE STUDY 04 · SINGAPORE
Singapore pairs the deepest public-service AI embedding with the world's most operational governance toolkit. National AI Strategy 2.0 (three systems / ten enablers / fifteen actions) drives AI deep into public service, while the Model AI Governance Framework for GenAI sets nine governance dimensions, paired with the AI Verify testing toolkit that turns governance from a PDF into a test you can run.
This is the platform-plus-governance archetype: SGTS already gave Singapore a government-as-a-platform base layer and reusable whole-of-government APIs, and Singpass gives ~97% identity coverage. The combination of NAIS 2.0's embedding and AI Verify's testability makes Singapore the model for measurable, conformant agentic AI. The gap is the move from copilots — AI that assists — to bounded autonomy — AI that acts — under those same controls.
#1 Platform + #8 Reflective / Eval AI Verify operationalises the eval-harness discipline (P49) — testability is governance made real.
Singapore's governance and embedding are exemplary, but its agents still mostly assist rather than act. The next move is to climb the maturity model into supervised, gated autonomy — applying the nine dimensions and AI Verify to agents that take consequential actions, not only to assistants that draft them.
CASE STUDY 05 · UNITED ARAB EMIRATES
The UAE leads on the experience-and-mission layer — the vision of agents as front-line public servants. The National Strategy for AI 2031 frames agents as the "workhorses that convert policy into daily service," and the world's first Minister of State for AI supplies the central, top-down authority the platform pattern needs.
The UAE's strength is mission clarity and institutional will: a single accountable office, a strong platform drive, and a concrete agents-in-service vision spanning visas, logistics and citizen services, all on the UAE PASS eID, signature and SSO foundation. This is the "treat agents as a new factor of production" principle taken seriously at the top of government. The gap is the governance counterweight — open eval depth and transparent oversight to match the mission ambition, so autonomy is earned rather than simply mandated.
#7 Mission / Experience Citizen super-assistants and proactive life-event services (visas, logistics) — agents at the front line of service delivery.
The mission ambition outpaces the published governance. To make top-down autonomy survivable, the UAE needs open eval harnesses, transparent oversight institutions and a binding risk framework on par with its delivery drive — so that agents that act on citizens are demonstrably grounded, gated and accountable.
CASE STUDY 06 · EUROPEAN UNION (AS A BLOC)
The EU brings the one thing no other actor has: a binding risk framework. The EU AI Act (Regulation 2024/1689) is the world's first horizontal, enforceable AI law — risk tiers, high-risk requirements, mandatory human oversight — and the Apply AI / GenAI4EU programmes give the bloc a sovereign-platform play with explicit agentic-AI support for public administration.
The EU's strongest archetypes are therefore federation and governance: the AI Act as the compliance perimeter every member state must build inside, plus A2A/AGNTCY interoperability momentum that mirrors the bloc's deep heritage in cross-border interoperability (EIF, eIDAS, Once-Only). The gap is speed — turning binding frameworks and funded programmes into deployed, production platforms before the frontier moves on. The EU writes the rules of the road faster than it builds the road.
#5 Federation + #4 Governance The AI Act is the binding spine (P50); A2A/AGNTCY is X-Road federation reborn at the agent layer.
The EU's binding law and funded programmes are world-leading; its risk is turning them into production platforms slower than the frontier moves. The challenge is institutional velocity — shipping the deployed agentic infrastructure as fast as it ships the regulation.
CASE STUDY 07 · LEADING US STATES
The most concrete agentic-production evidence in this entire collection comes not from a national government but from the US states. NASCIO's 2026 report, Beyond Generation, documents 8+ states already running agentic tools in production — and crucially, they reached them by climbing a five-phase maturity model, not leaping.
That maturity model — assistive GenAI → context-aware GenAI → task-level automation → stateful multi-step workflows → adaptive/proactive agents — is the emblematic sequencing instrument of the whole field, and the states are its proof of concept: supervised autonomy earned level by level, with oversight at each prior level before more autonomy is granted. The strongest archetype is supervised autonomy. The gap is the shared platform and the identity/delegation depth that a national actor like USAi can provide but a single state cannot easily build alone.
The states have the discipline; what they lack is a shared agent platform and the identity/authenticated-delegation depth a national actor provides. Fifty separate climbs of the same maturity model is the federal case for a USAi-class substrate underneath them.
MOVEMENT D · §23 — CROSS-CUTTING
Read across the seven profiles and the pattern is unmistakable. No nation has the full optimal stack, but every leader converged on the same small set of moves — and every failure traces to the same small set of omissions. The order is the strategy.
A shared platform, not piecemeal procurement. USAi, GenAI4EU and the Agentic State's sovereign stack all converged on one substrate because safety, identity, evaluation and cost control are operationalised once and inherited everywhere. A thousand agency pilots cannot be governed; one platform can.
A working digital foundation underneath. Estonia's X-Road, Singapore's SGTS, the UK's One Login, the UAE's UAE PASS — every leader is building agents on a healthy identity-and- registry floor. The agentic race is being run on the foundations laid by the digital race.
Supervised autonomy, earned by maturity. The UK Playbook, NASCIO's five phases, the EU AI Act and OpenAI's practices all insist autonomy be bounded, gated, attributable and interruptible — and climbed, not leapt. This is a structural member of the architecture, not a brake on it.
Grounding and an eval harness. Singapore's AI Verify and the τ-bench/AgentBench/GAIA discipline make correctness measurable. Leaders deploy agents that can show their source and pass a documented suite before — and during — production.
1 · Buying agents without the foundation. Procuring autonomous tools onto broken
registries, missing eID and un-API'd systems. The agent faithfully retrieves and amplifies
garbage at machine speed; the result is an expensive demo, not infrastructure.
2 · Ungoverned pilots. A thousand agency experiments with no central platform —
no shared guardrails, no shared observability, every ministry re-failing at safety alone.
3 · No eval harness. Deploying without measuring capability and reliability
under repetition. τ-bench's pass^k finding — that agents fail on repeated-trial consistency —
is the single most important deployment caution in this collection, and it is invisible
without a harness.
4 · No kill-switch, no human gate. Autonomous action on citizens with no tested
emergency stop, no rollback and no meaningful approval gate. An autonomy you cannot halt is
an autonomy you cannot deploy.
The decisive strategic fact is that the agentic race is being run on the foundations laid by the digital race — the nations that built X-Road-class interoperability, population-scale identity and clean registries start with half the agentic P0 stack already in place.
MOVEMENT D · §23 — THE BUILD-ORDER INSIGHT
The build-order insight is the whole strategy: you earn the intelligence layer, you do not skip to it. The matrix below sequences the synthesis build order into ten concrete actions — fix the digital state, stand up L1–L2, build the L3–L4 trust spine before anything autonomous ships, then runtime, governance in parallel, and mission last and continuously.
| Action | Owner | By when | Measured how |
|---|---|---|---|
| 0 · Fix the digital state — eID, agent-ready registries, X-Road-style exchange, sovereign cloud, zero-trust | Central digital agency | Pre-requisite | Registry quality/lineage score; eID coverage %; data-exchange uptime |
| 1 · Stand up the national agent platform — shared model access behind a gateway, tools, memory, observability | Central agent authority | 0–12 mo | Agencies onboarded; marginal cost-per-agency → 0 |
| 2 · Model gateway + managed inference — multi-model optionality, cost routing, sovereign/open-weight fallback | Platform team | 0–12 mo | Models routable; cost-per-resolution; sovereign inference path live |
| 3 · RAG + registry grounding layer — vector + graph stores, citations, structured outputs | Data office | 6–18 mo | % of agent claims grounded & cited; hallucination defect rate |
| 4 · Expose systems as MCP servers behind policy-enforcing gateways; tool & agent registry | Platform + agencies | 6–24 mo | Registries exposed as governed tools; gateway-mediated calls % |
| 5 · Agent identity + authenticated delegation — scoped, revocable, logged; nothing autonomous ships before this | Identity authority | 6–18 mo | Agents with verifiable identity %; delegation scopes audited |
| 6 · Observability, kill-switch & human gates — immutable logs, tested emergency stop, approval nodes | Central agent authority | 6–18 mo | Kill-switch drill pass; % consequential actions gated; log coverage |
| 7 · Eval harness, mandatory — capability + pass^k reliability + safety + policy-adherence; re-qualify on every model change | Oversight institution | 0–18 mo, continuous | % production agents passing documented suite; re-qual cadence |
| 8 · Binding risk framework + liability law — NIST AI RMF / EU AI Act / SG Model Gov; named responsible human per action | Legislature + central authority | 0–24 mo, parallel | Every system mapped to a risk tier; accountability chain legislated |
| 9 · Roll out mission services — citizen super-assistant, civil-servant copilots, proactive life-events — highest-burden, lowest-risk first | Line agencies | 12 mo+, continuous | Citizen outcomes resolved; civil-servant hours returned; maturity-phase |
Rows 0–8 are the trust spine; row 9 is the only one citizens see — and it ships last, on top of everything above it. The Algorithmic State Architecture models intelligence as the capstone of DPI → Data → Interoperability → Intelligence. L1–L7 are useless without the digital state beneath them, and L7 (mission) is dangerous without L1–L6. The order is the strategy.
MOVEMENT E · §24 — RISKS & COUNTER-ARGUMENTS
A confident report owes its reader the strongest case against itself. The thesis — that nations should wire the agentic P0–P1 layer onto a healthy digital foundation now — faces four serious objections, each grounded in this collection's own evidence. None overturns the spine; each sharpens it.
The pass^k problem. τ-bench's central finding is that agents which pass a task once often fail it on repeated trials — consistency, not peak capability, is the binding constraint. GAIA reports models at ~15% on real-world assistance where humans score ~92%. A state that deploys agents on consequential casework before reliability is proven is automating an unaccountable error rate. Rebuttal: this is precisely why the eval harness (P49) and supervised autonomy (P40) are foundational, not optional — the thesis requires measuring pass^k and gating on it, which is the opposite of naïve deployment.
The standards are two years old. A2A was donated to the Linux Foundation only in 2025; MCP is young and evolving; the agentic archetypes are mostly proven in the private sector and in pilots, not as governed national infrastructure. Building national plumbing on moving standards risks expensive churn. Rebuttal: the load-bearing investments — clean registries, eID, delegation, observability, an eval harness — are standard-agnostic. They pay off regardless of which agent protocol wins, which is why the build sequence front-loads them and treats the protocols as the replaceable top layer.
Agent memory is a surveillance apparatus in waiting. Long-horizon agents that remember citizens, and computer-use agents with general UI control, are the two highest-risk configurations in this report. A single ungoverned incident could set public trust back a decade. Rebuttal: the architecture is inseparable from its governance — governed tiered memory as regulated personal data (P35), least-privilege scopes, kill-switch and immutable logs are not add-ons but structural members. The thesis bans the dangerous configuration, it does not enable it.
The OECD's survey of 200 government AI use cases found the public sector has "limited precedent for autonomous software in government" while the private sector races ahead. This is the steelman's strongest card: government has never run software that acts on citizens at scale, and caution is warranted. But the OECD frames it as both a warning and an opportunity — the precedent gap is exactly why building the governed foundation now, deliberately and in sequence, is the responsible path rather than waiting for the private-sector pattern to arrive ungoverned.
MOVEMENT E · §24 — OUTLOOK
Where does national agentic adoption land by ~2030? The honest answer is a fan of scenarios, anchored to the one hard signal we have — fewer than ~10 nations have wired the agentic P0–P1 layer onto a healthy digital foundation today.
| Scenario | What drives it | What it looks like in 2030 |
|---|---|---|
| BEAR | Frameworks stall as PDFs; pilots churn; a safety incident freezes trust; standards fragment | ~15 nations; agents stuck at assistive copilots; autonomy politically radioactive |
| BASE | The platform pattern proves out; leaders scale to production; fast-followers inherit USAi/AI-Act-class blueprints | ~30 nations with governed P0–P1; supervised autonomy normal in high-volume, low-risk functions |
| BULL | MCP/A2A standards diffuse; shared platforms + open eval harnesses become reusable public goods | ~50 nations; the agentic capstone becomes the new digital-government baseline, as e-services did after 2010 |
The variable that separates bear from bull is not model capability — it is governance velocity and whether nations build the foundation first. The states that built X-Road-class interoperability and population-scale identity start every scenario with half the agentic P0 stack in place; the rest find no amount of agent procurement substitutes for it.
MOVEMENT E · §25 — METHODOLOGY
This report rests on a curated, verified corpus assembled with a single discipline: every URL was checked to resolve, only real multi-page PDFs were downloaded, and living specifications were recorded as links, not faked as downloads — an evidence base you can audit, not a bibliography you must trust.
Verify every URL. Each source was found via live web search and its URL verified to resolve before it entered the catalogue. Nothing was cited from memory or assumed to exist.
Only real PDFs. Where a free PDF existed, it was downloaded and checked with file / pdfinfo to confirm it was a real, multi-page document. 142 sources passed this bar (96 digital + 46 agentic).
Link-only for living specs. Canonical specs published as living HTML or Git (X-Road ARC-G, GovStack, MOSIP, MCP, A2A, AGNTCY) and bot-blocked pages (OECD, UAE, EU, GSA) were recorded as LINK-ONLY with a working URL — never fabricated as downloads.
Grounding & est. discipline. Every number traces to the folder-04 indices or a named source. Agentic infrastructure is ~2 years old with no ITU-grade census, so most adoption figures carry an explicit (est.) label; only hard signals — 8+ US states (NASCIO), the FDA rollout, USAi/GenAI4EU — are cited as fact.
A report arguing that states must ground their agents in verifiable, cited, authoritative sources cannot itself rest on unverified claims. The grounding rule we recommend for national agents — show your source, label your estimates — is the same rule this evidence base was built under. Method is the argument.
MOVEMENT E · §26 — THE EVIDENCE BASE
The full collection is twelve thematic folders — the seven that document the digital state and the five that document its agentic capstone. The counts below are the catalogued totals; together they form the spine of every claim in this report.
| # | Folder | Scope | Sources |
|---|---|---|---|
| 01 | Architectures · Europe | Estonia X-Road, Finland, Denmark, Norway, NL, Germany — real stacks | 16 |
| 02 | Architectures · Asia | Singapore, India Stack, S. Korea, Japan, China, UAE — real stacks | 16 |
| 03 | EU/UK/US frameworks | EIF, eIDAS/EUDI, NIST, FedRAMP, FEAF, GAIA-X, Zero Trust | 15 |
| 04 | Indices & frameworks | ITU, UN, World Bank, OECD, GSMA, NRI — the measurement layer | 15 |
| 05 | Digital Public Infrastructure | UNDP/G20, GovStack, MOSIP, Mojaloop, X-Road, DEPA | 15 |
| 06 | Technical architecture | Broadband, 5G/6G, Open-RAN, IXP, RPKI, DNS, edge, sovereign cloud, ZT | 18 |
| 07 | Emerging-nation reference | Smart Africa, Diia, PIX, Rwanda, ASA, GEA reference models | 16 |
| 08 | Agentic strategies · national | Agentic State, NASCIO, UK Playbook, NAIS 2.0, USAi, AI Action Plan, OECD, TBI, Turing, UAE, EU | 13 |
| 09 | Agent architectures & patterns | ReAct, Reflexion, Toolformer, ToT, CoT, surveys, Generative Agents, Voyager | 13 |
| 10 | Requirements & foundations | NIST AI RMF, EU AI Act, Visibility, OpenAI practices, AgentBench/GAIA/τ-bench, SG Model Gov | 11 |
| 11 | Agent data & state | RAG, MemGPT, Generative Agents, GraphRAG, KG+LLM, context engineering, OECD govt-data | 10 |
| 12 | Agent tools & integration | MCP, A2A, Gorilla, ToolLLM, API-Bank, WebArena, computer-use, AutoGen, LangGraph, AGNTCY | 12 |
MOVEMENT E · §26 — THE EVIDENCE BASE
From ~174 catalogued sources, these ~14 are the load-bearing references — the documents the principles, components and architecture rankings most directly rest on. Each is a real, verified source or a canonical LINK-ONLY specification.
These marquee sources are why the report can make its central claim with confidence: the agentic state is the digital state's canon — identity, registries, federation, interoperability, governance, oversight — extended to a worker that reasons and acts. Every one of those words traces to a verified document above.