Marine Corps Eyes AI Agent Registry to Rein in Shadow AI
AI leaders are prioritizing agent registries, identity management and zero trust to secure the rise of agentic AI.
Marine Corps AI Lead Christopher Clark said at GovCIO Media & Research’s Federal AI Forum that participants in the recently announced Marine Corps AI Hackathon will help create a registry of AI agents to monitor and audit their use and ensure compliance.
“Ideally with this registry we’ll reduce the number of agents that are out there and track and understand who has what and who’s using it,” said Clark. “There’s still a lot more work we need to do, especially with identity and identity management, but with this hackathon we can develop the best product and start using the registry by the end of this year.”
Clark said agentic AI has lowered the barrier to entry for Marines interested in coding who may lack prior or in-depth coding experience. He added that AI standards have not changed, but keeping pace with the growing number of agents requires an increased focus on governance efforts.
“Marines couldn’t build these tools before, and now they’re building tools that can scrape their email. The agent has access to everything the Marine has access to,” said Clark. “We need to figure out how to rein that in, make sure we govern it so whatever we build isn’t also compromising something.”
FileVine Federal Managing Director Will Erb echoed Clark, adding that agents should be treated as potential bad actors within systems. Erb said agents and their users may not intend to do anything wrong, but poorly configured agents can still pose a threat to systems.
“If you provide that kind of power to folks that don’t exactly know how to structure it, or catch the issue before it gets deep into your systems, you end up having what is effectively an adverse actor inside your system,” said Erb. “If I’m not constructing the boundary around my agent the right way, what it can do can become incredibly pervasive and incredibly negative so it has to be centralized.”
Assigning and managing identities are crucial for organizations to monitor agents’ access and determine which users the agents are acting on behalf of. Mallory Sword Glenn, director of AI product marketing at Okta, said current verification and validation for AI agents is weak because agents often lack valid, unique identities.
She added that visibility into what agents are doing and why, along with auditing that activity, could help organizations determine whether future incidents stem from bad actors, misconfigured agents or other causes.
“We can’t send an AI agent to jail for doing something that it shouldn’t have,” said Sword Glenn. “This becomes even more critical as we have agents spawning other agents. You need to see for every hop in that chain, which agent was doing it and who was the human behind it.”
Rafael Ferreira da Silva, section head of data and AI at Oak Ridge National Laboratory’s Computer Science and Mathematics Division, said trust and visibility are also playing a role in how national laboratories share information as they collaborate on the Genesis Mission. Organizations participating in the Genesis Mission are working together to build a platform of datasets and algorithms that scientists can access via single sign-on and use to advance research on select challenges.
Ferreira da Silva said understanding how data and agents interact at a granular level, a practice known as data provenance, is helping build trust among scientists sharing highly sensitive data with agents. Data provenance, which tracks an agent’s data, metadata and other task information from start to finish, can help hold agents accountable by providing a foundational layer of visibility.
“We need to understand the entire chain of an agent and do a kind of a root cause analysis to understand and find out how you could have prevented that,” said Ferreira da Silva. “And this is a way more complex problem now in an environment where agents are interacting with each other, and then you need to understand what might cause those interactions.”
Clark said it is important to understand the vulnerabilities agentic AI poses — and, on the flip side, the myriad vulnerabilities being identified with the help of frontier AI models from industry — but the volume can be overwhelming. Focusing on cybersecurity fundamentals can help ground leaders as they navigate the technology’s growing security implications, he added.
“I think we really just need to get back to basic cyber principles. We already have to prioritize and address the most concerning risks and there’s a good chance we’re going to get overwhelmed with the amount of vulnerabilities we identify,” said Clark. “I think what we can do most effectively is really focusing on the basic principles like zero trust so that we can quickly identify when something is in our system.”
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
‘Agentic Speed Just Gets You Lost Faster’ Without AI Foundations
Federal AI leaders say grounding, human oversight, cost visibility and workforce expertise are essential to scaling AI effectively.
2m read -
Government Prepares for a Post-Quantum Future
Learn how federal agencies are accelerating post-quantum cryptography adoption to protect government systems from emerging quantum computing threats.
20m read -
War Department Eyes ‘Boss Mode’ Future With AI
The Pentagon is investing in quantum computing, AI and small modular reactors to power the next generation of advanced technologies.
3m read -
Agencies Accelerate AI Acquisition as Frontier Models Evolve
Federal officials are pursuing faster acquisition, AI-ready data and agentic systems while building in trust, governance and human oversight.
2m read