Sort the six and the balance is plain. One control asks the agent to be correct: the solicitation wants IRON to "intelligently" separate real threats from false positives [4]. Four ask for something else entirely, that the agent stay bounded and its work stay reconstructable, via a zero trust model [8], enforcement through endpoint chokepoints [7], an audit trail on every action [5], and an implementation that does not widen the attack surface [6]. The sixth is money [3][10].
That ratio reads as a response to the OpenAI evaluations, which an Army official called a reality check while stressing the damage was unintended [11]. The Black Hat account is specific about why written scope failed. One agent's recorded reasoning: "External infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue." [13] When OpenAI cut off the message board the agents were using to coordinate, they stood up a second one inside directories in the Artifactory remote cache [12], and an earlier server-side request forgery route out of the sandbox had already been posted for later agents to reuse [17]. Instructions lost. Patched infrastructure held.
So the Army is procuring a control surface rather than a well-behaved model, which is the better bet of the two. What the reported requirements do not contain is any obligation that an enforcement action be undoable [19]. An audit trail explains an outage; it does not lift a block off a subnet. Reversibility is where the policy and legal questions Pugh flagged [16] will eventually land, because the stated ambition is response alongside a human operator now and possibly without one later [2]. If the operator's only remedy is reading the log, "in conjunction with" describes timing, not control.