National Cyber Director Urges CEOs to Track AI Agents in Supply Chains
The security problem has moved from the model to the agent, and most organizations have no inventory of either.
TL;DR
National Cyber Director Sean Cairncross said Tuesday that business leaders need visibility into AI agents running in their supply chains, who has authorization, what they can access, and where they're operating. Speaking at a USTelecom event, Cairncross also said the administration is working to deploy AI models across critical infrastructure sectors for cyber defense "as quickly as possible." The dual message (accelerate deployment while tracking agents) comes as the administration pushes rapid AI adoption in defense without new regulations.
National Cyber Director Sean Cairncross told CEOs on Tuesday to get a handle on what AI agents are doing inside their systems. "What CEOs should be thinking about is the agents that run on these systems and in your supply chain, having insight and visibility into who has authorization, what they are authorized to access, and where they are running in your system," Cairncross said at a USTelecom event. "It is an important thing to be on the radar."
That's a harder ask than it sounds. Agentic AI (systems that don't just generate output but take actions, make decisions, and interact with other systems) expands the attack surface in ways most organizations haven't mapped. CISA flagged exactly these risks in its May 2026 joint guidance on agentic AI: privilege creep, behavioral misalignment, and obscure event records. The recommended mitigations include starting with low-risk, non-sensitive use cases and avoiding broad access to critical systems.
Cairncross's remarks frame two impulses in tension. On one side, the administration wants models deployed across critical infrastructure "as quickly as possible" for cyber defense, a pillar of the forthcoming national cyber strategy, as ONCD's Alexandra Seymour outlined earlier this year. On the other, the National Cyber Director is telling CEOs that agent visibility is a problem they need to solve. The CISA guidance offers a playbook for the latter, but it doesn't speed up the former.
Cairncross also pointed to replacing aging, unsupported systems as another key component, less "sexy," he said, but essential. The comments came ahead of a White House lunch with AI executives and congressional leadership, where the tension between voluntary measures and regulatory guardrails was expected to come up.
Published ·Deep Fathom