Skip to content

Security1 publisherNot yet confirmed elsewhere3 min readPublished

Project Griffin's fine print: kill switch, undo, token ceiling, and a checklist for CISOs

The Army's Project Griffin solicitation names eight acceptance conditions for autonomous defensive agents. Every one of them is a question a private buyer can put to a vendor now.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The Army's Project Griffin pilot, also called IRON, wants an ecosystem of AI agents that read its network sensor data and execute defensive actions on their own.
  • Requirements include separating real threats from false positives, keeping an automated audit trail, and running under a zero-trust model.
  • Manual controls are specified: a master kill switch and an undo function covering actions such as firewall changes and vulnerability patching.
  • The solicitation also asks bidders to minimise token costs, integrate safely with existing networks, and not widen the attack surface.
  • Solution briefs were requested by Aug. 27, the first step in a multi-phase development process.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • precedent A government buyer has put inference spend into acceptance criteria, which makes cost per investigated alert a fair thing for any buyer to demand in writing before a pilot starts.
  • constraint Zero trust applied to the agent rules out the convenient design where remediation runs on one broad standing credential, and that constraint lands on the vendor's architecture, not the customer's...
  • decision Buyers now have to decide who owns the stop button and where the rollback state is stored, because an undo that lives only in the vendor's cloud is not a control the customer holds.
  • exposure An agent with read access to sensor telemetry and write access to network controls is worth attacking for its own sake, which is why the footprint requirements are in the list at all.

An undo function is a harder ask than it sounds. To reverse a firewall adjustment or a patch, the agent must have recorded the state it replaced, action by action, with enough fidelity to restore it [7]. That is transactional change management applied to a machine that is meant to act faster than the humans who would otherwise approve the change [9]. Plenty of tools are sold on their ability to take action. Reversible action is a different engineering commitment, and it is where the liability for a bad automated change actually sits.

The master kill switch has the same shape of problem. Griffin is specified as an ecosystem of agents rather than a single agent [3], so one switch implies a control plane above all of them that none of them can decline. Where that plane lives is the buyer's decision, not a detail: if the stop command is a button in a vendor console, the ability to halt autonomous remediation depends on the vendor's availability at the moment it is needed.

Zero trust reads as boilerplate in a requirements list until you apply it to the agent itself [6]. The agent becomes a subject that authenticates, and its authority is scoped per action rather than granted once. If an agent holds a standing credential broad enough to rewrite firewall rules at will, it is not operating under zero trust in any sense the phrase carries, whatever the architecture diagram says.

Minimising token costs is the line most worth stealing [1]. It moves inference spend out of the pilot's ROI narrative and into acceptance criteria, which forces a number almost nobody publishes: cost per alert investigated. Pair that with the requirement to separate genuine threats from false positives [6] and false-positive rate stops being only a detection-quality metric. Every wrong investigation is inference somebody paid for, at machine speed, without a human deciding it was worth doing.

Three of the eight conditions in the solicitation as summarised (safe integration with existing networks, token cost, and no expansion of the attack surface) treat the defensive agent as a potential liability rather than as a detector [12][11]. That is the posture a buyer should recognise, and it sits directly beside the Army's stated worry about adversaries using AI to find vulnerabilities [5]. A tool that reasons over sensor telemetry and holds write access to network controls is a high-value target by construction [3].

One caution on sourcing: this is a trade brief summarising the requirement set, and it points readers to DefenseScoop for fuller coverage [10]. The specifics of how rollback fidelity or token metering will be measured are not in what we can see. The eight conditions still work as a question list, and unlike a phase award [8], asking them costs nothing.

What to watch

  • Whether later phases publish measurable definitions of rollback fidelity and token metering, or leave both to vendor self-description.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories