Agencies are moving quickly to adopt AI, but Red Hat chief architect says agentic AI implementation requires strong frameworks.
With many agencies looking to adopt artificial intelligence, including agentic AI, forward-leaning cybersecurity policies and practices may be more important than ever.
The federal government is moving to adopt AI to streamline both internal processes and public interactions. But AI adoption needs to come with proper safeguards, said Michael Epley, chief architect and security strategist at Red Hat.
“We are deploying these AI agents mostly because we want to gain the automation, the efficiency of these generative tools and apply those to real world problems,” Epley said during Federal News Network’s Cloud Exchange 2026.
“The real challenge is we’re deploying these AI agents without strong frameworks for understanding how to control these agents. We’re granting them very broad access because we want these agents to essentially automate what humans do, but we’re not constraining those AI agents.”
Organizations may be granting AI agents broad access to data and tools to streamline their operations, but that also requires corresponding controls, he said.
“Some of these existing frameworks are great in that we can leverage what we already know about how to apply these frameworks, typically designed around how human actors work in our systems, and apply those to AI agents using the same principles,” Epley said.
Zero trust and traceabilityHe pointed the zero trust cybersecurity architecture that agencies have been directed to adopt since 2021. Zero trust presumes a network or system will be breached and adopting controls that limit the damage.
“Applying those means things like least privilege,” he said. “Even though we want our autonomous agents to act independently, it also means only granting them access to the tools and the systems and the data that they actually need to operate in a given time, and then revoking those accesses when they’re no longer needed, and doing that on a per agent or per access basis.”
Epley also argued actions taken by an AI agent should ultimately be “traceable” to a human being who takes ownership of the actions and outcomes.
“That traceability can be done through, say, token exchanges or other techniques that mean that the agent is really acting on behalf of a human,” he said. “Even though it’s operating autonomously through that agent process, but ultimately that’s traceable back to a human that’s in control and responsible for that interaction.”
AI security concernsRecent advancements in the cyber capabilities of models like Anthropic’s Claude Mythos have further entrenched security concerns. Advanced models have demonstrated the ability to quickly find software vulnerabilities and exploit them.
“AI is unlike humans. It’s very persistent,” Epley said. “It doesn’t give up, it doesn’t get bored, and it will continue. If a human directs it to find a vulnerability or find a weakness in your cloud or your infrastructure, it will find those.”
While that could be a boon for nefarious hackers, the cybersecurity community is also beginning to use those models to find and patch vulnerabilities in areas like open source software.
“This has really highlighted the power of AI but also the need to have things like strong controls and zero trust to constrain it — and to make sure that these AI systems do not exceed their boundaries and the controls that we apply to those AIs to limit those actions,” Epley said.
Discover more articles and videos now on the Cloud Exchange event page.
Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.