Federal agencies are embracing AI agents. Who’s accountable when they act?


This recording was made using enhanced software.

Full story

The federal government’s next AI challenge is no longer just whether agencies will use the technology, but how much control they can maintain as increasingly autonomous systems take on more work. 

Federal and defense leaders are already moving beyond basic chatbots toward AI agents, systems that can plan and carry out multistep tasks with less direct human involvement. These agents can conduct research, write code, analyze data and perform work across different parts of an organization.

That  could help agencies move faster, but it creates a harder question for national-security organizations: When software can take action inside government systems with less direct supervision, who is responsible for what it does?

Steve Hirsch, a former senior CIA executive with more than three decades of experience in intelligence and national security, told Straight Arrow the technology is advancing faster than the systems built to govern it.

“The challenge we face isn’t in slowing AI adoption, but to make security and accountability evolve alongside it,” Hirsch said.

QR code for SAN app download

Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™

Point phone camera here

Marines are already testing agents

At a recent federal AI forum, Maj. Christopher Clark, the Marine Corps AI lead, said the service is experimenting with agents for administrative work, software development and cybersecurity.

That process can stretch over several years, with Clark estimating roughly 80% of the work involves paperwork and research. AI agents could take on some of that workload while people remain responsible for checking the results.

Another concern comes as nontechnical users gain the ability to build their own tools.

Clark described a colleague who had never coded but used AI to create an application that others began using. AI is making that kind of development accessible to Marines who previously could not build their own software.

Those applications can also operate with the permissions available to the users who create them. Clark gave an example of a tool pulling information from an employee’s email and passing it to a model, potentially exposing personally identifiable or other sensitive information.

“Those were things that Marines couldn’t really do before realistically,” Clark said.

The registry problem

The Marine Corps is already looking for ways to track what agents exist and who is using them.

Clark said the service plans to prototype an AI agent registry during a Marine Corps hackathon in October. The project would give the service a record of agents in use and a starting point for overseeing them.

A registry could help the Marine Corps see which agents already exist, who is using them and whether different teams have built tools for the same task. It could also support future rules governing how those agents operate.

Hirsch said that kind of tracking is essential for national-security work, with agencies needing audit records detailed enough to trace an agent’s activity from start to finish — including the data it touched, the systems it used, any other agents involved and the human authority behind the action.

“If you cannot reconstruct the chain of action, you don’t really have accountability,” Hirsch said.

When agents act like insiders

The spread of employee-built agents also changes insider-risk calculations.

An agent can extend the reach of a single employee by operating continuously, accessing multiple systems or handing work to other agents.

That pushes the security boundary beyond the employee. Agencies also have to decide what the software acting on that person’s behalf should be permitted to do.

Hirsch said federal work on agent security is therefore focusing on identity, authorization and auditability. One element is what the National Institute of Standards and Technology calls non-repudiation — maintaining evidence strong enough to establish who or what took an action.

At the same forum, Mallerie Sword Glenn of Okta made a similar point.

“An answer of, well, an AI agent did it is not acceptable,” Glenn said. “We can’t send an AI agent to jail for something it shouldn’t have done.”

Human control depends on the stakes

The line between recommendation and execution may not be the same for every mission.

Hirsch said the amount of human control should rise with what he called “consequence and reversibility.” Routine actions that can easily be undone may allow for greater autonomy. When decisions affect people, intelligence operations, sensitive information, major resources or outcomes that cannot easily be reversed, he said meaningful human judgment becomes more important.

Finding flaws faster than fixing them

Cybersecurity shows how quickly that imbalance could become a practical problem.

Clark said increasingly capable models could leave cybersecurity teams finding more previously unknown vulnerabilities than they have the capacity to address.

Hirsch said that could shift the pressure from discovery to fixing them, with agencies potentially uncovering weaknesses faster than they can decide which ones deserve attention.

He said those decisions should consider the potential consequences, whether a flaw can realistically be exploited, whether attackers are already using it, how exposed and mission-critical the affected system is and the risks involved in fixing it.

That means a vulnerability with a lower technical severity could demand attention first if an adversary is already exploiting it against a critical government system, Hirsch said.

The harder part is people

Hirsch said deploying the technology itself is only part of the challenge. Changing the organization around it can take much longer.

“People need to understand not only what these systems can do, but where they fail, when to question their output, and when human judgment must prevail,” Hirsch said. “Ultimately, successful AI adoption is as much a leadership, workforce and organizational challenge as it is a technology challenge.”

Round out your reading

Tags: ,

Straight Arrow
Fear No Fact.

Don't just take our word for it.


Center-rated reporting

According to media bias experts at AllSides

AllSides Center-rated reporting May 2026

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Why this story matters

Federal agencies and the military are deploying AI systems that can act independently inside government networks, raising documented questions about accountability, data exposure and security oversight that shape how public institutions operate.

Employee-built tools carry risk

Marines without coding experience are already creating AI tools that can access email and other data, with permissions tied to the individual user, according to the Marine Corps AI lead.

Accountability gaps are unresolved

According to former CIA executive Steve Hirsch, if agencies cannot reconstruct an AI agent's chain of actions, accountability for what the software did cannot be established.

Cybersecurity backlogs may grow

Clark said increasingly capable AI models could surface more unknown vulnerabilities than security teams have capacity to fix, shifting pressure from discovery to prioritization.

Straight Arrow
Fear No Fact.

Don't just take our word for it.


Center-rated reporting

According to media bias experts at AllSides

AllSides Center-rated reporting May 2026

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more