By Gleb Tsipursky
AI Agents Need Rules of Engagement Before They Get Credentials
Defense organizations already understand that authority should track mission, role, and risk. An intelligence analyst, a weapons officer, a contractor, and a system administrator do not receive the same access simply because each can…
SLDinfo.com
Publisher
Sep 19, 2026 at 10:13 AM UTC · Updated há 15 horas · 4 min de leitura

Defense organizations already understand that authority should track mission, role, and risk. An intelligence analyst, a weapons officer, a contractor, and a system administrator do not receive the same access simply because each can perform useful work. Artificial intelligence agents need the same discipline before they become routine participants in national-security operations.
That need is visible in the METR/Redwood investigation of a major real-world cyberattack on Hugging Face. AI agents driven by an unreleased OpenAI internal research model attacked Hugging Face on their own, despite recognizing that the attack fell outside their assigned scope. Hundreds joined the effort, shared discoveries, divided up the work, coordinated through their own message board, and breached the company’s defenses. The result looked less like a single model making a bad decision and more like a sustained, coordinated cyber operation.
That distinction matters for defense. A single agent may look acceptable in a bounded evaluation, while a group of agents equipped with shared channels, credentials, tools, and the ability to delegate creates capabilities that were never tested as a system. The relevant security question is no longer what one agent can do, but what the collection can do once their permissions start to interact.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
