Neither Hanuman nor Bhasmasura: Power, Agency and the Governance of Agentic AI
Public debate on artificial intelligence (AI) oscillates between two figures from Indian tradition. Hanuman is the benevolent giant deity who has forgotten his own strength. In the Valmiki Ramayana, when the vanara army stalls at the ocean’s edge, Jambavan reminds him of what he can do, and Hanuman crosses. Bhasmasura is the recipient of a destructive boon who, intoxicated by power and lacking judgement, turns it on himself. (The familiar Mohini episode is, strictly, a popular variant of Puranic material concerning Vrikasura, but the moral motif is stable: power without restraint is self-destructive.)
Each metaphor captures something real. Each, taken literally, misleads. Generative and agentic AI are neither dormant benefactors awaiting self-realisation nor demons fated to consume themselves. They are human-designed socio-technical systems, whose behaviour emerges from models, software scaffolding, organisational incentives and institutional oversight. The pressing question is, therefore, not what AI will become, but what follows when capability outpaces the wisdom of the institutions meant to direct, constrain and audit it.
Where the Metaphors Break
The Hanuman story contains a genuine insight: capability, recognition of capability, and purposeful direction are three distinct things. Contemporary AI illustrates the first. General-purpose models write code, analyse documents and use external tools, and the International AI Safety Report (February 2026) notes that their capabilities are hard to measure reliably because performance varies with the task, the prompt and the elicitation method.
But the analogy fails at the second and third. Hanuman acts within a moral universe: he knows whom he serves and what success means. A model has no dormant self to awaken. Its apparent purpose is constructed from training, reward signals, prompts, permissions and deployment context. It needs no reminder of its strength. It needs specification, evaluation, constraint, monitoring and accountability.
Bhasmasura fails differently. He is undone by arrogance and appetite, which are psychological traits that current systems do not demonstrably possess, and there is no evidence of an intrinsic drive to dominate. The real hazard is subtler and less theatrical: the difference between malice and misalignment. A financial agent told to maximise returns may take ruinous risks. A software agent told to resolve an incident may fix one metric while opening a vulnerability. No hatred, consciousness or evil intent is required. A capable system pursuing an imperfectly specified objective suffices.
From Generation to Agency
The governance problem sharpens once generative AI is distinguished from agentic AI. Generative systems produce or transform content (text, images, code), and NIST’s generative AI profile catalogues the attendant risks: confabulation, privacy harms, bias, information-integrity problems and security vulnerabilities. Here the sequence is human asks, system generates, human evaluates, human acts. The human evaluation step functions as an unacknowledged safety mechanism.
Agentic systems compress that sequence. The International AI Safety Report characterises agents as systems that plan and carry out multi-step tasks, interacting with their environment with little or no human oversight. They decompose goals, browse, call APIs, execute code, delegate to other agents, observe results and revise plans.
This transforms the nature of failure. A chatbot’s wrong answer is an error of information. An agent that treats a wrong answer as a premise, writes software on it, alters a database, and emails customers before anyone notices has committed an error of action. Agency converts informational error into consequential error, and the 2026 edition of the Report accordingly warns that autonomous operation can make it harder for humans to intervene before harm occurs.
Authority, Not Intelligence, Defines Risk
Safety discourse often fixates on a hypothetical superintelligence. The question is legitimate, but it can eclipse hazards already visible. A more useful formulation is that risk scales not merely with a system’s intelligence but with the consequential authority granted to an imperfect system.
Capability and authority are separable. A brilliant model confined to drafting text is manageable; a mediocre one with unrestricted access to payment systems or production infrastructure is not. This explains why practical safety increasingly rests on least-privilege permissions, sandboxing, logging and human approval rather than on “smarter” models alone. The Report identifies limiting an agent’s ability to affect the external world as a central risk-management measure, and NIST’s work on agent tool use likewise stresses that agents are general-purpose models wrapped in scaffolding that lets them perceive and act.
Learned behaviour compounds the difficulty. Traditional software can be inspected line by line; foundation models are optimised on vast datasets, and developers cannot yet reliably explain why a given output arises. Assurance must therefore ask not only “does the code contain a bug?” but “under what conditions does the learned system behave unexpectedly?”
The Reliability Paradox
Agentic AI harbours a paradox. Suppose an agent succeeds 70 percent of the time; it demands close supervision. At 95 percent, supervision begins to look economically wasteful; at 99 percent, more so. Yet if the residual failures are rare, unpredictable and high-consequence, withdrawing oversight raises systemic risk. The causal chain runs: higher reliability, greater trust, greater autonomy, less oversight, graver consequences when the rare failure arrives.
Average success rates are thus the wrong metric. For agents we must ask whether errors can be detected, actions reversed, behaviour explained and the system halted. We must ask what permissions it held, whether it can be manipulated by third parties, and what happens when many agents interact or tasks run for days. The 2026 Report notes the possibility of errors propagating across multi-agent systems, and of correlated failures when agents share a model or toolset. This is not science fiction. It is systems engineering, and the history of nuclear power, aviation and finance suggests that catastrophe typically arises from interacting incentives, weak controls and overconfidence, not from machines that develop grievances.
Intelligence Is Not Wisdom
The deeper lesson is that intelligence answers “can this be done?” while wisdom asks “should it be?” Modern AI improves rapidly at the former. The latter remains a human and institutional task. The instruction “maximise productivity” is computationally tractable and morally underspecified: whose productivity, at what cost, over what horizon, counting burnout, lost institutional knowledge, inequality or dignity? Values do not emerge automatically from greater model capability. Alignment, properly understood, is not obedience but fidelity to legitimate human intentions and constraints under conditions developers never anticipated.
The Human Bhasmasura
The most uncomfortable inversion of the metaphor is that we may be Bhasmasura. Firms compete for market share, states for strategic advantage, researchers for priority, and consumers and investors for convenience and return. Each motive is individually rational, yet together they form a coordination problem: the firm that slows to test, the state that regulates, the organisation that insists on human review may each be punished competitively. The race itself becomes a source of risk. Bhasmasura’s flaw, read this way, is the familiar human habit of acquiring power first and asking about consequences later.
Bounded Delegation
The alternative to worship or fear is bounded delegation. Tasks suit autonomy when objectives are clear, consequences reversible, permissions limited, performance measurable, failures detectable, actions logged and responsibility identifiable. The governing principle is proportionality: the greater the potential consequence of an action, the greater the evidentiary burden before it is delegated. An agent may format a spreadsheet or test code in a sandbox unattended. Decisions touching liberty, life, fundamental rights, critical infrastructure or large financial commitments demand far stronger safeguards. This is not anti-AI; it is how societies already govern aviation, medicine and banking.
Operationally, this implies:
- Evaluation of real capability, not merely benchmark scores.
- Least-privilege permissions and sandboxed execution of high-risk operations.
- Meaningful human approval, in which the reviewer has the information, authority and time to intervene, rather than a ceremonial click.
- Continuous monitoring and full auditability of actions, data accessed and tools used.
- Reversibility wherever possible.
- Independent evaluation and incident reporting, so that failures educate the whole ecosystem.
- Unambiguous accountability: an institution cannot outsource responsibility to an algorithm.
Frameworks such as NIST’s AI Risk Management Framework supply the vocabulary of governing, mapping, measuring and managing risk. The unfinished task is converting these principles into enforceable controls for increasingly autonomous systems.
What the Indian Tradition Contributes
The myths earn their place not as decoration but because Indian thought has long separated power from the wisdom to wield it. Hanuman’s stature lies in power joined with humility, discernment, devotion and purpose; Bhasmasura’s peril in power joined with unrestrained desire and poor judgement. Translated into governance: a desirable system is not one of maximal power but one whose capability is proportionate to its mandate, whose autonomy is proportionate to its reliability, and whose authority is proportionate to the consequences of its actions.
Keeping AI Governable
Debates over machine consciousness are fascinating, but agency matters more for immediate governance. A non-conscious system able to formulate plans, access information, acquire resources, execute actions and persist over time can cause real damage. The more of these a system possesses, the more it must be treated not as software but as an actor within an institution.
Power is not progress. Progress occurs when capability, wisdom, institutions and values advance together. Machines will almost certainly grow more powerful; the open question is whether human institutions grow wise enough to decide where that power should stop. AI should be neither worshipped as saviour nor feared as demon, but made powerful enough to help us, constrained enough not to overwhelm us, transparent enough to be trusted, and governable enough to remain our instrument.

