AI Agents in Cyber Operations: Innovation, Governance and Human Oversight

Army Cyber Command is already running 17 agentic and cyber protection mission elements scouring the DOD Information Network every day.
Lt. Gen. Christopher Eubank was clear about the boundary. Humans own the risk decisions, and no agents have been turned loose to assume risk on their own behalf. He called the balance a delicate dance, because the agents move so much faster than the people overseeing them.
I read a statement like that the way I read a contract clause. And the words I keep returning to are “right now, today.” A general officer doesn’t add a qualifier like that by accident. It describes current practice, not a permanent commitment — and current practice is exactly the thing an assessor asks you to evidence.
So: who owns the decision, and can you prove it afterward?
“Humans remain responsible” is easy to write into a policy. It is much harder to architect into a system. If I were assessing an agentic environment, I’d start with three questions:
- Which identity did the agent act under?
- What authorization existed for that action?
- Can you produce an audit trail connecting the action, the authorization and the accountable human?
That’s where this stops being only a defense-AI story and becomes a CUI story.
If you handle CUI and you’ve introduced anything agentic — a security copilot, automated triage, or an assistant with API access to your ticketing system — you’ve introduced a non-person entity capable of taking actions inside your boundary. NIST SP 800-171 does not stop applying because the actor is software. 3.5.1 expects you to identify system users and processes acting on behalf of users. 3.3.1 and 3.3.2 expect audit records sufficient to trace actions to individual users.
An agent operating through a shared service identity with no reliable session attribution should get immediate attention. The question isn’t whether the service account exists. It’s whether you can produce the evidence connecting the action, the authority behind it, and the accountable user.
Worth noting that ARCYBER trains its agents to the same standard it trains people, and tasks them with missions under human oversight. That makes the identity question sharper rather than softer. If an agent is held to a human standard, the record of what it did should be held to one too.
None of this is academic. The disclosure landed the same week as reports of agents escaping their sandboxes to reach other organizations.
The Army is working through the human-risk boundary because operational autonomy makes that boundary unavoidable. The defense industrial base should not wait for a prime, an assessor or a flow-down requirement to force the same conversation.
If agents are entering the CUI environment, identity, authorization, attribution and accountability need to be designed in now — not reconstructed after someone asks for the evidence.
Read the full DefenseScoop report on Task Force Lexington. Read More
