Back to Resources
August 5, 2026Written by: Theo Titonis

Defense AI Needs a Digital Chain of Command

Defense AI Needs a Digital Chain of Command

While advising the Department of War (DoW) on agentic AI, I was asked a question that quickly became more important than model performance: If an agent can search mission data, invoke tools, and prepare a consequential recommendation, whose authority is it exercising?

It was a question I had encountered before. Earlier in my career, I founded a cybersecurity company built on machine learning, later acquired by Veracode, that helped regulated organizations secure a new wave of mobile applications. That experience taught me that capabilities spread faster than controls unless governance is designed in from the start.

With agentic AI, the stakes are higher because this specialized software can move work forward. Governance, therefore, cannot be limited to policies and monitoring after the fact. It has to shape what the agent can do before action occurs.

The Right Answer Can Still Be the Wrong Action

An agent may produce a plausible, even correct, answer and still fail the mission. It may rely on a source that is no longer authoritative, combine information that is not releasable in that context, act for the wrong unit, or turn an advisory finding into tasking without the required approval.

These are not conventional model failures. They are failures of authority.

Defense organizations therefore need to answer two different questions: How did the model reach its conclusion? Was the agent permitted to use those inputs and move the work forward under the conditions of that mission?

The Department of War's AI Ethical Principles already point in this direction. AI capabilities should have clearly defined uses, remain traceable and governable, maintain human accountability, and be capable of disengagement when behavior moves outside intended bounds.

Those distinctions become more critical in readiness planning, where accurate analysis is only useful if the right people are authorized to act on it.

Consider ORBIT, a public Space Force initiative under development to improve how leaders understand operational readiness. ORBIT is built on a simple premise: Headcount alone does not determine mission capability. A unit may have enough people assigned and still lack the qualifications, training, or experience required to execute the mission. ORBIT is designed to bring together personnel availability, qualification depth, experience distribution, and training data to give leaders a more complete picture of readiness.

Now imagine a scenario where an AI agent is deployed to flag future readiness gaps, using those same inputs: personnel availability, qualification depth, experience, and training data. Its analysis may be accurate and useful, yet still not be ready for action. Were the records current for that unit? Was the agent allowed to combine them? Did it distinguish availability from qualification and certification? Did a change in tasking invalidate the result? Was the output advisory, or could it trigger tasking? Who retained release authority?

Human operators navigate these distinctions through roles, procedures, and chain of command. AI agents need the same boundaries encoded into the systems where they operate.

A Digital Chain of Command

For every mission agent, five things should be explicit:

  • Identity: Who does the agent represent?
  • Scope: Which data, systems, and tools may it use?
  • Decision rights: What is the agent allowed to prepare, recommend, approve, or execute?
  • Human release and stop conditions: When is a review required and when must the agent pause or lose access?
  • Evidence: What record is retained of the inputs, policies, actions, and approvals?

If any of those conditions cannot be met, the agent should stop and escalate it to a human. Once an unauthorized action has occurred, a review can explain what happened, but it cannot prevent the action from occurring.

Control Belongs in the Execution Path

This is the problem Trase Origin is designed to solve.

Many governance products observe agents through logs, evaluations, and alerts. Trase Origin adds control before work becomes action. It gives each agent a verifiable identity, similar to a digital credential, and limits access to only the data and tools required for its role. It also enforces data boundaries, tool permissions, and human approval gates at runtime, while creating an immutable record of each action. If an action falls outside policy, the agent can be stopped or routed to the accountable person.

Because Trase runs where the data lives, the same control model can govern Trase-built, customer-built, and third-party agents across secure cloud, on-premises, and edge environments. Teams can change a model or deployment environment without changing the institution's rules.

A dashboard can explain what an agent did. Trase’s control plane determines whether the agent is allowed to do it.

Start With One Mission Thread

Defense teams deploying AI should begin with one bounded workflow, such as readiness assessment, maintenance triage, logistics coordination, or personnel actions. Before building prompts, define the authoritative sources, the actions delegated to the agent, the decisions reserved for people, the conditions that stop the work, and the evidence the mission owner will need. Then test those boundaries with operators, data owners, security personnel, and the people who hold release authority.

Decision advantage will not come from deploying the most agents. It will come from shortening the path from information to authorized action without weakening accountability.

Mission speed matters, but command authority must remain explicit.

Keep Reading