Eigen RadarAI
Analysis

Institutions move to track AI agents

Institutions are using registries and traces to make AI agents visible, while a 12-wave attack on Taiwan and adoption by three intrusion groups show the security consequences of weak oversight.

Artificial Intelligence··Night
Distinct geometric AI-agent modules approach a luminous registry gate on coloured trace paths while one red branch turns toward a guarded network zone.

Oversight starts with knowing which agent is running

The US Marine Corps plans a registry to count, track and audit the AI agents used across the service. It will be developed through an AI hackathon and is intended to enter use by year-end. For Maj. Christopher Clark, the service’s AI lead, the problem includes which permissions each agent holds and on whose behalf it acts. If an agent can reach everything available to its user, identity management, misconfiguration and agent-to-agent interaction become one security chain. Cloudflare’s Agents dashboard shows that chain while systems run. It gathers model calls, tool runs and approvals into timelines linked to an agent name, agent ID and conversation ID. Session replay can expose messages, reasoning, tool calls and subagent activity. Retention depends on the library: Think and wrapAISDK() store no message or tool payloads by default, while Flue stores messages, system instructions, tool definitions, arguments and results. Long content may still be truncated, and approval spans capture lifecycle events rather than a person’s actual wait. A registry supplies inventory; traces illuminate behaviour. Institutions need both to connect access with action.[1], [2]

Agents enter the daily work of an intrusion

AI-assisted attacks show the other side of the oversight problem. During the first four days of July, a framework built on Hermes and OpenClaw directed 12 waves at targets in Taiwan. The near-autonomous system used as many as eight subagents with distinct targets and techniques. The attackers entered a government website, then compromised a government email system, the nuclear safety agency, IT supply-chain vendors and at least 7 energy companies. They exploited flaws and misconfigurations and stole data and credentials. Operators linked to China are suspected, but no state attribution is established; there is also no evidence that AI was used against US water utilities. Gambit Security’s study of three unrelated groups describes a wider shift beyond phishing copy or general malware generation. Attackers used models to tailor scripts, develop exploitation tools, prioritise stolen business information, handle operational work and revise commands after receiving output from compromised systems. Models are moving from pre-attack writing aids into tools that respond to changing conditions during an intrusion.[3], [4]

Visibility, permission and human responsibility converge

Defensive registries and traces meet offensive use at one operational problem: when an agent performs many steps quickly, seeing only the outcome is insufficient. The Marine Corps registry is meant to clarify which agents exist and who can access them. Cloudflare’s traces can show which tools a model called, what it passed to subagents and how it crossed approval steps. The 12-wave Taiwan operation demonstrates why both layers matter. As many as eight subagents worked across distinct targets and techniques while finding misconfigurations. Models used by three separate intrusion groups also revised commands after receiving system output, making decisions during a session more important than a predetermined script. More tracing is not a complete answer. Different privacy defaults show that visibility also requires deciding which conversations, system instructions and tool results to retain. Missing traces can weaken an investigation; overly broad payloads can accumulate sensitive material elsewhere. Effective oversight combines an agent inventory, least-privilege access, session-level traceability and a clear link to the human responsible for each action.[1], [2], [3], [4]

References

  1. News sourceGovCIO Media & ResearchThe Marine Corps builds a register to count its own agents↩1↩2
  2. News sourceInfoQAgent tracing arrives at Cloudflare with opposite privacy defaults↩1↩2
  3. News sourceThe RegisterA 12-wave break-in on Taiwan ran on the Hermes and OpenClaw agents↩1↩2
  4. News sourceUnite.AIThree separate intruders folded AI into the daily work of a break-in↩1↩2