
Mallina and other members of the AIUC-1 Consortium, a group of technology leaders building AIUC-1, the industry-led certification standard for AI agent security, safety, and reliability, are contributors to the Consortium’s 2026 whitepaper, “After Mythos: Defending at Machine Speed.” The whitepaper examines how organizations must adapt their defenses now that frontier-level offensive cyber capability is becoming widely accessible.
Over the last few years, I've watched our work shift from deploying deterministic machine learning (ML) models to building and orchestrating autonomous agents in some of the most demanding and complex environments. That's a huge shift and it comes with the responsibility to build reliable, dependable agentic AI systems, which requires new standards and evaluation frameworks.
I joined the AIUC-1 Consortium to contribute to the A1UC-1 certification standard, and especially to bring the builder’s lens to the effort.
AIUC-1 is the world’s first independent certification standard specifically designed for agentic AI systems. It verifies that systems can be trusted, giving organizations the confidence to deploy them. It evaluates autonomous AI deployments against more than 50 technical, operational, and legal safeguards across six core domains: data and privacy, security, safety, reliability, accountability, and societal impact.
Agentic systems can carry out a variety of tasks and workflows to free up federal teams for mission-critical work. They can take a single objective, such as “onboard this employee” or “triage this case”, and autonomously work out the steps to get there, adapting as they go instead of stalling the moment they hit something unscripted. That’s a key difference from the robotic process automation agencies have run for years.
Governance is imperative; every single action an agent performs must be traceable to build trust and ensure fairness. Before scaling anything, agencies need clear answers. What can an agent decide on its own, and where does a human have to sign off? Can every action be traced back to the data and rules behind it? Who’s accountable when the agent gets something wrong?
An ungoverned agent puts decisions around cost, quality and access in the hands of a system nobody can fully explain, audit, or defend under machine-speed attack.
A governed agent does the opposite: it gives program owners a defensible, traceable basis for the decisions that determine whether a beneficiary gets timely access to care, whether a payment is accurate, and whether a program can withstand scrutiny. A standard like AIUC-1 makes it possible to bring agentic AI into cost, quality, and access workflows while maintaining the public’s trust.
“After Mythos: Defending at Machine Speed” lays out the three tactical imperatives every CISO and program leader needs to operationalize this year—backed by original survey data from 50+ CISOs and security executives and grounded in best practices already running today at more than 100 security organizations.
This whitepaper is one of the most candid readiness assessments the security community has produced this year, and it comes with a playbook.
For federal leaders, every agentic AI deployment you stand up is also a new surface an adversary can target at machine speed. The Consortium polled more than 50 CISOs and security executives, and on average, they rate their own organization’s preparedness for a Mythos-class threat environment at just 4 out of 10. They expect that to rise to roughly 6.7 out of 10 over the next year—an improvement, but still a concerning gap.
Federal leaders can close that gap by bringing governance into the room from day one. Pick a bounded process where autonomy delivers a real gain, pilot it with human oversight in place, measure the results, and use existing standards. The agencies that build that discipline early will be the ones setting the bar rather than scrambling to catch up to it.
