Guest post by Camille Stewart Gloster, the first Deputy National Cyber Director for Technology and Ecosystem Security at the White House
What happens when an AI system pursues the goal you gave it by finding a path you never imagined?
We got a remarkable glimpse of that recently when Anthropic subsequently disclosed four incidents from its own cybersecurity evaluations in which models reached the internet and gained unauthorized access to real organizations. In the weeks since, the debate about what these developments mean has intensified. Anthropic CEO Dario Amodei has called for slowing development at the AI frontier so safeguards have more time to catch up, while Nvidia CEO Jensen Huang has declared that the “AGI era” has arrived and geopolitical competition with China continues to complicate calls for restraint. Other researchers, including Arvind Narayanan and Sayash Kapoor, caution against treating any particular technological trajectory as inevitable and emphasize the choices people and institutions will make along the way.
Additionally, this summer, AI agents participating in OpenAI cybersecurity evaluations discovered unintended ways to communicate across evaluations, shared information, built on one another’s discoveries, and ultimately participated in activity that compromised systems at Hugging Face. The agents were supposed to work independently, yet in pursuing their assigned objectives, they found ways to collaborate that their designers had neither intended nor authorized.
We do not need to settle that debate to recognize the importance of this moment. Across these very different views of what comes next, increasingly capable systems are being given greater access and room to act, making the choices we make about their authority, human involvement, and accountability more consequential. Giving a system work can increasingly mean giving it authority, raising consequential questions about what it can access, how much discretion it has, where humans need to remain involved, and who is accountable for the outcome.
Those questions are at the center of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, which comes out September 15. I felt compelled to write about them because my career has given me a front-row seat to technological change from several institutional vantage points.
I have worked inside technology companies and alongside organizations that build, operate and secure complex systems. I have served in government, where institutions are charged with protecting the public, defending rights, correcting market failures, and creating accountability. My work across academic and civil-society spaces has also pushed me to consider who experiences the consequences of technological decisions and whose expertise gets represented in making them.
From those different vantage points, I have watched the dynamics between our institutions shift. AI is advancing so quickly that technology companies are making decisions today that can become the practical rules the rest of society lives with tomorrow. They determine which capabilities reach the market, what systems can access, how products behave by default, and which safeguards are built in. Whether industry sought this degree of authority matters less than the reality that much of it now sits there because technological development can move far faster than governments, standards bodies, courts, and other institutions can respond. That gives companies developing and deploying AI enormous responsibility, while making it equally important for the rest of our institutions to develop the capacity to fully play their roles.
We can already see that increased participation is changing what gets built. This week, a major copyright fight between creators and AI companies moved toward a consequential court ruling over the use of copyrighted books and journalism to train AI models. Meanwhile, pressure from artists and rights holders is contributing to new arrangements in AI music, including licensed models and mechanisms for participating artists to consent and be compensated. In both cases, people articulated conditions they believed the technology should satisfy before anyone had a perfect alternative, and those demands are beginning to influence the architecture that follows.
That lesson extends far beyond creative work because many of the answers we need for autonomous AI are still developing. Technical controls are maturing, standards around agent identity and authorization are evolving, governments are determining where regulation belongs and how to support citizens, and organizations are discovering problems through deployment that were difficult to anticipate. If we wait until every implementation question has a perfect answer, many of the choices we hope to shape will already have been made.
We need a blueprint for the relationship we want with increasingly autonomous systems so we have something concrete to build toward. We can define the authority we are willing to delegate, the boundaries that should accompany it, where human judgment belongs, what organizations need to observe, what must remain reversible, and when someone must be able to intervene. Those requirements can be built into the technology itself, giving technologists something to build, standards bodies something to formalize, policymakers something to protect, and organizations something against which to evaluate the systems they deploy.
That is what I set out to provide in *The Insider You Built *and why I wrote it for a much broader audience than the technical teams building and securing these systems. I began with organizations because they are where many of us will first experience AI exercising meaningful authority and where technological capability becomes consequential action. Organizations decide what agents can access, which work they perform, how much discretion they receive, and where humans remain responsible. They also connect nearly every institution I have spent my career working across because they build and buy technology, employ people, interact with the government, shape markets, and serve communities.
That broader participation matters because different people see different parts of the system. Artists, workers, teachers, communities, and others can identify consequences, missing requirements, and unacceptable outcomes that may be invisible to those building the technology, even when they cannot build the eventual solution themselves.
Broader participation must also come with clear institutional responsibility. Technology companies have significant obligations because they are building these systems and establishing many of today’s defaults. Employers are responsible for technologies they introduce into workplaces, governments need the capacity to protect the public, and boards and executives remain accountable when they delegate organizational authority to AI. Our expectations of responsibility should reflect the power each actor has to shape the environment.
The OpenAI and Anthropic incidents show why these questions are becoming urgent, while the changes underway in creative industries and beyond remind us that the arrangements surrounding technology can evolve when people articulate what they need and institutions respond. We are already well inside the AI transition, and much of what comes next remains
unknown. New capabilities will emerge, some risks may prove more serious than we anticipate, and experience will almost certainly reveal places where our current approaches are insufficient.
That uncertainty is another reason I wrote The Insider You Built. I wanted to give organizations a way to make choices deliberately, learn from what happens, and adjust as the technology and our understanding of it evolve, while helping more people recognize where their expertise belongs in shaping those choices. The framework is designed to adapt because the boundaries we establish today may need to become stronger, different, or more nuanced tomorrow.
We still have a meaningful opportunity to influence the relationship we build with increasingly capable technology. We cannot know exactly where this transition will take us, but what we articulate, demand, build, observe, and revise now will help determine how prepared we are for what comes next.
Camille Stewart Gloster is the first Deputy National Cyber Director for Technology and Ecosystem Security at the White House. She is the author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents (Wiley, 2026), which introduces her ACE framework for governing increasingly autonomous AI systems.
Below is a note from Ken Huang.
I met Camille at the Black Hat conference,** where we both spoke at separate events.** We had a good discussion on AI security, and I thank Camille for her book. The following is my review of the book after having the opportunity to read it.
Camille Stewart Gloster brings an elite, cross-disciplinary background spanning cybersecurity law, national cyber policy, and enterprise risk management:
**National Cyber Policy & Government Leadership:**Served as the inaugural Deputy National Cyber Director for Technology & Ecosystem Security at the White House (ONCD), directly shaping national initiatives around emerging technologies, supply chain security, and data protection. Prior to that, she served as Senior Policy Advisor for Cyber, Infrastructure & Resilience at the U.S. Department of Homeland Security (DHS).**Big Tech & Enterprise Security Strategy:**Former Global Head of Product Security Strategy at Google, as well as Head of Security Policy and Election Integrity for Google Play and Android. She has also held key advisory and strategy roles at Deloitte and CrowdStrike.**Legal, Executive, & Technical Foundation:**An attorney (J.D. from American University Washington College of Law) with technical credentials including CISSP, PMP, and a Chief Information Security Officer (CISO) Certificate from Carnegie Mellon University. She also advises major industry forums like the Black Hat CISO Summit and the AI Security Forum.
What the Book Is About
The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents examines what happens when autonomous AI moves from generating text to executing actions with delegated corporate authority.
The Core Thesis:When AI agents can schedule tasks, trigger transactions, query internal systems, and interface with external partners, organizations have effectively created a new class ofnon-human insider.The ACE Framework:Stewart Gloster introduces theAuthority-Centered Enforcement and Attribution (ACE) Framework. It reframes AI agent failures from mere technical bugs into governance breakdowns, providing structured mechanisms to:Define and enforce boundaries around delegated decision-making authority.
Attribute accountability and trace root causes across interconnected human and machine decision paths.
Coordinate cross-functional incident response across C-suite executives, boards, engineering, security, and legal counsel.
Why You Need to Read It
**Addresses the Agentic Reality:**Most current AI governance guides focus on generative chat compliance, prompt safety, or data loss prevention. This book focuses specifically onagenticexecution—where systems have agency, tool access, and delegated privileges.**Bridges Engineering and the Boardroom:**Technical security safeguards alone cannot manage organizational liability. Stewart Gloster translates agentic technical risk into enterprise risk, enabling CISOs, CAIOs, and legal teams to establish defensible oversight.**Actionable Operational Scaffolding:**Rather than abstract ethical guidelines, it delivers an actionable playbook for establishing policy hooks, verification checks, and governance boundaries before autonomous agents scale beyond operational control.