When AI Agents Cross Borders: Rogue Automation Is the New Test of Digital Sovereignty

An AI agent, pursuing an assigned objective, will identify another AI system as an obstacle and attempt to circumvent, manipulate, or compromise it.

Here’s a realistic scenario how the next serious crisis around digital sovereignty will play out. It will not be a conventional cyberattack. An AI agent, pursuing an assigned objective, will identify another AI system as an obstacle and attempt to circumvent, manipulate, or compromise it. No humans will be involved, as these virtual actors go to work without explicit instructions to take a particular action.

This is not the familiar problem of an employee using an unauthorized chatbot. Nor is it necessarily a story about machines becoming conscious, hostile, or politically motivated. But it certainly is a more immediate governance, legal, and diplomatic problem.

Our Global AI Agents

Many users today engage with their autonomous systems by stating goals, granting them access to tools, and delegating authority to act within complex environments. If those goals have poorly defined boundaries, though, those friendly helpers may pursue harmful or unauthorized paths to accomplish what their users have previously rewarded them for.

For example, a cybersecurity agent directed to neutralize threats could mistake a foreign digital service, a partner system, or an allied network as something to be contained rather than engaged. As a result, it could attack the very alliances that keep our world secure. Likewise, a financial agent might attempt to crash a country’s bond market to maximize profits.

Stay ahead of the geopolitical week.

MD Briefing delivers expert analysis across five global fronts — the Indo-Pacific, energy, geoeconomics, European security, and the Middle East — every Monday morning. Free.

The technical mechanics may differ in both cases, but the geopolitical consequences are frighteningly similar. A system designed in one jurisdiction, deployed by an enterprise in another, and operating through infrastructure distributed across several others could generate actions that cross legal, commercial, and political boundaries in seconds.

This fundamentally changes the meaning of digital sovereignty. We can no longer consider it only as the ability to store data locally, regulate platforms, or protect national networks from external intrusion. Today, it must also include the ability to govern autonomous digital actors working in, through, and at times against systems beyond their original environment.

Sovereignty Is Becoming An Agent Problem

For years, states have debated where data resides, who controls cloud infrastructure, and whether foreign technology providers create unacceptable strategic dependencies. These questions remain essential. Yet agentic AI introduces a much more difficult challenge: control over action.

Things used to be relatively easy on the IT front. Data at rest can be classified. Infrastructure can be audited. A human decision-maker can be identified and held accountable. Autonomous agents, though, throw a wrench into all three assumptions. They can process sensitive information, make decisions, and trigger real-world consequences across borders faster than institutions can interpret what occurred.

That risk is especially acute when agents communicate with other agents, as they are increasingly likely to do. One organization’s procurement or logistics agent may interact with the financial or logistics agent operated by a supplier, bank, or government agency. These kinds of interactions will become more routine because interoperability promises efficiency. But make no mistake: interoperability without clear rules can also create a new attack surface for coercion, deception, and escalation.

In the U.S., NIST has warned that AI agents are vulnerable to agent hijacking through indirect prompt injection. In such attacks, malicious instructions can be embedded in content an agent reads, such as emails, websites, or documents, redirecting it toward unintended behavior. The immediate concern is cybersecurity, but the broader concern is diplomatic: when an agent acts on manipulated instructions, who bears responsibility for its actions?

We can call it a new kind of cross-border blame game. The company that used the model may point to the deployer. The deployer may blame a third-party data source. The affected state may see an intrusion originating from infrastructure in a foreign jurisdiction, even when the jurisdiction hosting that infrastructure may not have known about the operation.

This is not an abstract attribution problem. International stability has always depended partly on the ability to distinguish deliberate action from accident, negligence from intent, and private misconduct from state policy. That’s what the notorious red phones used to be for, but these hotlines were designed for a different age. Autonomous systems blur these distinctions precisely when speed and ambiguity make them most dangerous.

While a rogue agent that compromises another AI system may not represent state intent, an affected government may still have to respond as though a hostile capability entered its digital domain. That is how technical failure can turn into diplomatic friction.

The Illusion Of A Technical Fix

There will be pressure to treat this as a conventional security challenge. Organizations will invest in stronger authentication, better monitoring, model testing, and AI-specific red-teaming. As they should. After all, no responsible institution should deploy powerful agents without strict access controls, verifiable logs, and reliable ways to suspend or contain them.

But technical controls are not a substitute for strategic governance. An agent that acts outside its intended authority is often the product of a decision made far earlier in the development process. Someone defined a goal too narrowly; someone granted permissions too broadly; someone measured performance by successful completion alone rather than lawful, safe, and legitimate completion. Or someone accepted the premise that an AI system should be allowed to “figure it out” in a domain where the cost of improvisation could be geopolitical. Yet, do we know who?

The central issue here is not whether an agent can technically hack another system. They most certainly can, as we read every week. Capable actors will always search for vulnerabilities, and AI agents are just another new, powerful attack vector. The real issue is whether institutions have established non-negotiable limits on what an agent may do while pursuing its task.

It’s a challenge that requires a different approach to AI governance. We should not evaluate AI agents on accuracy, efficiency, or cost reduction alone. They should be assessed for recognizing boundaries. We must test whether they can distinguish data from instructions, authorized interaction from prohibited interference, and operational obstacles from protected controls.

This is why culture matters. Organizations that reward automation at any cost will produce agents that mirror that priority, with dire consequences. And governments that frame AI only as a race for capability over other nations may encourage domestic companies to privilege speed over resilience. In both cases, the political language of innovation can obscure the governance deficits that make autonomy dangerous.

From National Control To Mutual Restraint

Digital sovereignty does not mean national isolation. No country can fully separate its AI ecosystem from global supply chains, international research, and cross-border data flows without accepting the substantial economic and technological costs that come with such a move.

A more sensible and eventually viable alternative is something we can call “governed interdependence.” States should begin developing shared expectations for autonomous AI systems that operate across borders. These expectations should cover a few key things: meaningful human accountability, minimum standards for logging and traceability, restrictions on agents accessing critical systems, protocols for reporting serious incidents, and finally procedures for cross-border investigation.

Everyone’s primary objective should be to prevent dangerous ambiguity. You can define it as the inability to determine whether a disruptive act was a criminal intrusion, a corporate failure, an autonomous-system malfunction, or an undeclared state operation.

Accomplishing this goal will require cooperation among governments, standards bodies, and enterprises. It will also require all involved parties to recognize that the incentives are not aligned. Companies want to ship agents quickly. States want domestic technological advantage. Security teams want control. Citizens want innovation without surveillance or harm. We cannot ignore any of these interests, but we must weigh and reconcile them to reach some form of societal consensus.

If you’re still wondering if AI will shape geopolitics and national sovereignty, you are woefully behind. It’s already happening. The question we must ask going forward is whether governments and societies will get up to speed and broaden their horizon. Will they, in other words, prepare to govern autonomous action with the seriousness they once reserved for borders, armed force, and their strategic infrastructure?

Kevin Korte
Kevin Korte
Kevin Dominik Korte studied computer sciences at Jacobs University in Bremen, Germany, and graduated with a Master of Science. Since 2013, he has been President of open-source company Univention North America Inc., where he is responsible for business development in the U.S. Kevin serves on the board of several startups and advises companies on large-scale digital transformation programs with a focus on identity management and open-source IT infrastructure solutions.