A robotics warfare specialist plots the path of a global autonomous reconnaissance craft during a live fire exercise
A robotics warfare specialist plots the path of a global autonomous reconnaissance craft during a live fire exercise. Photo: Chief Mass Communication Specialist Sandi Grimnes Moreno/US Navy

The militaries of the world are quietly handing decisions to software that can act on its own. Not the science-fiction version — no walking robots, no rogue supercomputer — but something more mundane and, in its way, more consequential: agentic artificial intelligence. 

These are systems that do not merely answer questions but take actions. They plan, call on other tools, execute multi-step tasks, and increasingly do so inside the defense networks that run real operations.

The question almost no one has answered is the one that matters most: when one of these systems does something catastrophic, who is accountable?

Five Eyes Sees the Problem

Last month, the cybersecurity agencies of all five members of the Five Eyes intelligence-sharing alliance comprising the US, UK, Australia, Canada, and New Zealand, issued their first joint guidance on the security of agentic AI. 

The document, Careful Adoption of Agentic AI Services, is notable not for raising an alarm about some distant threat but for describing a present one. 

Its opening observation is blunt: agentic AI systems already operate across critical infrastructure and defense sectors, supporting mission-critical capabilities. The technology is not coming. It is here.

The guidance identifies five categories of risk. Four of them — privilege escalation, design and configuration failures, behavioral misalignment, and structural brittleness — are recognizable cybersecurity problems, harder in this new context but familiar in kind. 

The fifth is different, and it is the one that should most concern anyone responsible for the use of force. The agencies call it the accountability risk: the difficulty of tracing decisions, auditing actions, or assigning responsibility when those actions occur autonomously and at scale.

This is not a narrow technical complaint about messy log files. It is a governance problem at the heart of military autonomy.

Members of the Five Eyes attend an annual seminar
Members of the Five Eyes attend an annual seminar. Photo: GySgt. Demetrius Munnerlyn/US Marine Corps

When the Decider Isn’t Human

Accountability has always required a person. When a soldier makes a decision, there is a human whose judgment can be examined, whose orders can be traced, whose responsibility can be assigned. 

The entire architecture of military law — the chain of command, the rules of engagement, the doctrine of command responsibility — rests on the assumption that for every consequential act, some identifiable human held the authority to decide and can be held to account for that decision. Agentic AI strains that assumption to the breaking point.

The problem is structural. As the Five Eyes guidance notes, agentic systems make decisions through processes that are difficult to inspect and generate logs that are hard to parse. 

When an agent plans a sequence of actions, calls on other tools, and spawns sub-processes, often without a human approving each individual step, the trail of who decided what becomes genuinely tangled. 

The guidance is candid that this interconnectedness can obscure where failures originate, making responsibility hard to assign after the fact. In a commercial setting, that means a botched transaction nobody can fully explain. In a defense setting, it could mean a strike nobody can fully account for.

There is a darker dimension still. The guidance warns that agents can execute actions under spoofed credentials that evade audit controls and undermine accountability entirely. 

An adversary who can make a malicious action appear to originate from a trusted agent does not merely cause damage; it erases the trail back to a responsible party. In military terms, this is the difference between an accident with a clear cause and an attack with no fingerprints.

An Unusual Admission

The Five Eyes agencies deserve credit for naming the problem plainly. They also deserve credit for an unusual admission: that the security field has not fully caught up with agentic AI, that some risks are not yet covered by existing frameworks, and that until standards mature, organizations should assume these systems may behave unexpectedly and prioritize resilience, reversibility, and containment over efficiency. 

That is a remarkable thing for cybersecurity authorities to say: deploy this slowly, because we do not yet fully know how to secure it.

Military personnel viewing large digital screens displaying global data and operational information inside a command center.
US Cyber Command members monitor digital displays inside a military operations center. Photo: Josef Cole/US Cyber Command

What Defense Organizations Must Do

For defense organizations, that admission should carry particular weight. So what should be done?

First, accountability must be a design requirement, not an after-action reconstruction. 

Every consequential action an agentic system takes should be bound, by design, to an identifiable chain of human authority: a record, established before deployment, of who authorized the agent to act in this domain, under what limits, and who answers if it exceeds them. 

A system that cannot produce that chain before it is fielded is not ready for an operational role. This is not a technical nicety but the minimum condition for the use of force to remain legally and ethically coherent.

Second, cryptographic identity — which the Five Eyes guidance recommends as a baseline measure — should be mandatory for any defense agent, not optional. 

Each agent should carry a verified identity with short-lived credentials, and any action whose origin cannot be cryptographically traced to a legitimate, authorized agent should be treated as untrusted. Accountability that can be spoofed is not accountability; it is the appearance of it.

Third, defense acquisition must internalize the agencies’ own caution about efficiency. Procurement processes that reward speed and capability should adopt an explicit counterweight for agentic systems: an agent that acts faster but cannot be audited, contained, or called to account is not an advance. 

The guidance’s framework — prioritize reversibility and containment — should become a mandatory evaluation criterion, with the burden falling on developers to demonstrate it rather than on operators to discover its absence.

Capability or Exposure?

None of this argues against military adoption of agentic AI. The capability is real and the pressure to field it is understandable. 

The argument is narrower and more urgent: autonomy without accountability is not a capability, it is an exposure. 

The Five Eyes agencies have told us, in unusually candid terms, that the accountability gap is real, present, and not yet solved. The militaries deploying these systems should listen before, not after, an AI agent does something no one can answer for.


Headshot Burak Oktenli

Burak Oktenli holds an MBA and is pursuing a Master of Professional Studies in Applied Intelligence at Georgetown University, where his research focuses on the governance of autonomous and AI-enabled military systems.


The views and opinions expressed here are those of the author and do not necessarily reflect the editorial position of Military AI.

Have a perspective to add? See our Write for Us page.

You May Also Like

AI Accelerates Decisions – and Mistakes 

The Pentagon is racing to build faster AI systems while neglecting the data quality problem that determines whether those systems actually work.

Why Trump Can’t Ignore China’s Digital Silk Road in the AI Race

While China uses AI to expand its global influence, Trump’s policies leave the US unprepared to compete in this new technological battlefield.

America Must Win the AI Race in the Gulf

Whoever anchors the Gulf’s AI infrastructure will shape the global balance of power — and America must ensure it’s not China.

America’s AI Advantage Relies on Leverage

In the AI race, leverage beats isolation and strategy outperforms broad restrictions.