Alessandro AleddaInsider Threat and Risk

ArticlesAgents Execute. They Don’t Command.

Tactical autonomy is real. Command autonomy is not arriving with it.

17 JUNE 2026  |  4 MIN READ

I work in insider risk day to day. I don’t build the models or train them. I am the one who decides what to do when a system flags a human being, and answers for it. That vantage point is narrow, but it is honest, and it is the one I write from.

So when “agentic” became the word of the year in cybersecurity, I did what most operators quietly do. I smiled.

The smile has an origin I can place. Earlier this year I was sitting in a room at a security event, listening to the agentic story told the way it usually is, wrapped in a military analogy. It was a good analogy. Good enough that I caught myself reaching for it, building my own version in my head, before the second half of the reaction caught up.

I smiled first because the analogy is genuinely right. The last decade of warfare taught a real lesson: the expensive, centralized platform has given ground to the cheap, distributed, semi-autonomous one. Mass moved from the few to the many. Survival started to depend on dispersion and a small signature rather than armor. Initiative pushed downward, toward the edge, toward the unit that acts without waiting for the order. Reaching for that picture, myself included, is not wrong.

I smiled a second time because that is exactly where a good analogy gets shortened into a slogan, and a slogan is where good ideas go to be sold.

Here is the part the brochure leaves out. The battlefield decentralized autonomy. It never dissolved command. Tactical execution moved to the edge: faster, more local, more independent. But the decision about what matters, which objective is worth the risk, when to stop, that did not autonomize. It was pushed down a level. It was never handed to the machine. The forces that confused the two, that mistook a swarm in motion for a plan, produced movement, not victory. A swarm without an objective does not sit still. It does damage at full speed.

Cyber is living the same shift, and the same confusion.

The tactical autonomy on offer is real, and I want to be clear about that, because skepticism is not denial. For the record, I work with this technology by choice: I do detection engineering, I follow the field, and these tools genuinely extend what a defender can do. Triage, correlation, containment, response at a tempo no human can match: the value is real, and I have no interest in pretending otherwise.

The shadow is that the market narrates tactical autonomy as if command autonomy were arriving with it. As if the system will soon decide, on its own, what counts as a threat, what deserves escalation, and how much risk the organization is willing to absorb. But that last decision is not technical. It is a question of intent, context, accountability, and consequence. An agent can carry out the response. It cannot own the decision, because it cannot own the responsibility. And command with no one to answer for it is not autonomy. It is abdication.

This is where context, the most underestimated word in our field, stops being a platitude. A capability without a clear “why” is not neutral. It is counterproductive. Speed and autonomy added to a system that has no intent do not make it more effective. They make it fail faster. Hardware without a reason behind it does not improve the outcome. It crashes the system more efficiently.

And nowhere does this bite harder than in insider scenarios, which happen to be where I live now.

Insider risk is the discipline where context is everything. The same signal, the same file movement, the same access at the same odd hour, is benign or catastrophic depending entirely on the intent and the human situation behind it. An agent that executes without understanding that context is not an efficient analyst. It is a machine making high-speed decisions about things it does not understand. That is not maturity. That is the precise point where the agentic story meets reality and loses.

None of this is an argument against the technology. It is an argument about where the line sits. Technology should be allowed to take more and more of the tactical load. Governance has to hold the line on command. The failure mode, in war and in defense, is the same: letting the first quietly absorb the second, seduced by the speed.

The data will keep telling us what happened. People still have to decide why it matters, and whether to act. That decision is not a feature waiting to be shipped. It is the job.