Blog / AI Security · Philosophy

When Agents Take the Lead, What Endures?

Why a cause-oriented threat framework may remain useful whether AI assists security professionals, runs security operations, or eventually leads strategy.

Bernhard Kreinz • • Loading... • TLCTC v2.6
The central argument

TLCTC may endure because its organising principle is the cause of compromise. The intelligence that discovers, exploits or controls that cause can change — from a human, to a human directing an agent, to an agent working within delegated authority — without the cause changing. This is a conditional argument about durability, not a guarantee, and the last section says what would refute it.

The Question

What happens to a cybersecurity framework when the people using it are no longer the most capable security practitioners in the room?

Models increasingly explain what should be done. Agents, equipped with tools and an execution environment, can also do it. It is plausible that the same progression will reach security programme planning and strategic prioritisation. Human strategic superiority is an assumption that deserves to be tested.

That prospect raises a useful question for the Top Level Cyber Threat Clusters: does TLCTC depend on humans retaining the lead?

“Every scenario” below means the major plausible distributions of work between humans and agents, including uneven progress. No framework can credibly promise relevance in every imaginable future.

The Transition Is Already Concrete

On 29 September 2026, Anthropic published an evaluation of GLM-5.3, an open-weight model from Zhipu AI (Z.ai). In one session, “over the course of a day (and with limited human attention), GLM-5.3 found several previously unknown vulnerabilities in the browser's JavaScript engine, and chained them together into a working exploit: a webpage that, when visited, reads arbitrary files from the visitor's computer.” In a second exercise, the smaller GLM-5.3-Flash turned a recently disclosed Chrome flaw (CVE-2026-11645) into a working exploit with twenty minutes of human attention and eight hours of model work — about $20.40 of inference at Zhipu's prices.[1]

Such results demonstrate substantial technical capability. They do not establish that agents outperform most security professionals across their entire jobs, or that autonomous enterprise defence is already reliable. They do justify planning for a world in which implementation expertise is cheap and widely available.

Outside the laboratory, the Dutch Institute for Vulnerability Disclosure (DIVD) reported that its own Zammad ticketing system was breached on 21 September 2026. The intruder came in through two previously unknown Zammad vulnerabilities and escalated to root; in DIVD's words, “after elevating to root on the system, the actor used AI agents for the further attack.”[2] DIVD infers the agents from the volume of activity in a short period and from attack scripts that were commented and documented; no actor has been identified. The case does not show that an agent found the vulnerabilities or ran the whole intrusion. It does show work being handed to agents in the middle of a live attack — a reported case, not a forecast.

The likely progression is familiar: an agent first recommends a change, then implements it, verifies the result and revises its approach. Given adequate organisational context, the same loop could compare security investments, identify neglected exposures and continuously update a programme.

The timing remains uncertain. Strategic analysis may become technically feasible before an organisation delegates even relatively narrow production changes. Capability, integration and decision authority advance at different speeds.

A Different Capability Vector Does Not Create a Different Mechanism

TLCTC classifies successful attack steps by the generic vulnerability exploited. Actor identity, concrete technique and resulting consequences are separate dimensions. The core states that completeness is a falsifiable hypothesis and that unique assignments depend on the classification rules and boundary tests.[3]

Consider an illustrative sequence. An attacker exploits a server-role implementation flaw to obtain another principal's credential, presents that credential to impersonate the principal, and then uses an export function outside that principal's entitlement.

#2 + [DRE: C] → #4 → #1 + [DRE: C]

Exploiting Server → Identity Theft → Abuse of Functions. The credential acquisition carries its data risk event at the step that enabled it (R-CRED); the use of the credential is #4 and never carries a DRE of its own; the export is the second disclosure. Each successful step records its own System Risk Event — the path is not one compromise event.[3]

A human could execute this sequence. A human could direct an agent to execute it. An agent working towards a delegated objective could select it without being told to. In the framework's terms the actor is still the party with intent — the agent is a capability vector of whoever set the objective, as the two theses from the AI hacking incidents set out — and Axiom IV keeps actor identity out of the classification altogether. The supplied facts support the same mechanism classification whoever, or whatever, carried them out.

AI can materially change which weaknesses are discovered, how many paths are attempted, their complexity and the time available to intervene. Those changes can transform risk without requiring a new top-level category: the twenty agent incidents reviewed in September needed no eleventh cluster.

Conversely, an unfamiliar AI failure should never be forced into a cluster simply because AI is involved. Accidental errors and system failures remain outside the attack taxonomy. “AI risk” is broader than cyber attack, and evidence may be insufficient to resolve intent, entitlement or mechanism.[3]

The Framework's Role Changes Across Scenarios

These scenarios overlap. Different organisations, systems and security functions may occupy different rows at the same time. The final column describes a proposed use of TLCTC, not an established performance result.

ScenarioWhat changesWhy TLCTC may remain useful
AI progress slowsHumans retain most operational and strategic decisions.A common cause vocabulary connects engineering findings, control coverage and risk decisions.
Agents implement; humans directInvestigation, configuration and remediation become increasingly automated.The control matrix provides a structure for objectives, delegated work and evidence of the resulting coverage.
Agents lead planning and strategyAgents propose priorities, allocate resources and revise programmes within delegated authority.A shared representation makes recommendations comparable across agents, providers and successive model versions.
Attackers advance fasterAttack volume, adaptation and speed exceed the defender's manual capacity.Cause-based paths identify common intervention points and the controls that must act before a human can respond.
Defenders advance fasterContinuous discovery and remediation reduce exploitable exposure.The same structure records what was addressed, what remains exposed and where supporting evidence is missing.
Both sides operate autonomouslyAgents select and execute competing strategies at machine speed.Stable definitions support automated comparison, incident reconstruction and independent review.
A defensive agent becomes the vector or the targetThe security tooling itself carries or suffers a compromise.Its actions are assessed against the same cause-side rules, with operational failures kept distinct from attacks.

A cluster need not be active everywhere for the taxonomy to remain useful. If a workflow eliminates human decision points, human social engineering may cease to be relevant to that particular path. Manipulating software — a prompt injection, for instance — is classified by the software mechanism, which makes it #1 Abuse of Functions; it does not become #9 Social Engineering by analogy.

From a Planning Matrix to a Shared Decision Structure

The application paper relates the ten clusters to the cybersecurity functions and distinguishes local controls from umbrella controls. It connects cause-side analysis with governance, indicators and the consequence chain.[4] That structure need not be limited to a table maintained by a human.

In an agent-operated security programme, the matrix could become a set of continuously maintained records. Each relevant intersection could point to assets and exposures, deployed controls, test evidence, accountable owners, approved actions and unresolved questions.

An agent could populate those records, propose interventions and update the evidence after implementation. Another agent could challenge the proposal against the same definitions. A human decision-maker could inspect the assumptions without having to reconstruct every technical detail.

The core distinction is between having a control and demonstrating what it changes. An empty cell may mean an exposure is neglected, a control is inapplicable, or the organisation simply lacks evidence. A populated cell does not prove adequate protection. Each state needs an explanation.

Nor does the matrix determine the optimal strategy on its own. Prioritisation still needs business dependencies, costs, control effectiveness, uncertainty and acceptable consequences. TLCTC can organise part of that decision; it cannot manufacture the missing facts.

A proposal for agent-assisted governance

Require each material recommendation to identify the exposure, the proposed intervention, its expected effect, the evidence needed to verify that effect, and the residual uncertainty.

This is an application design proposal, not an additional classification rule. Its value would have to be demonstrated in actual decisions.

Faster Attacks Make Explicit Transitions Matter More

If an agent shortens a path from hours to seconds, a correctly identified control may still arrive too late. Faster analysis only helps if an effective intervention can occur within the available window.

The layered event model separates system events, data events and business events, and requires the transitions between them to be stated explicitly. Detection supplies evidence about a state; it does not act on the incident path. A response changes the subsequent course of events. These are different contributions, and the time between layers bounds the window in which the second one is possible at all.[5]

This distinction becomes operationally sharper as autonomy increases. A dashboard can report a compromise instantly while a payment, disclosure or destructive action has already completed. Where a reactive intervention cannot arrive in time, the design must rely more heavily on prevention, constrained execution or controls already positioned to interrupt the relevant transition.

The DIVD incident shows the gap in practice. By DIVD's account, the first signals appeared in its monitoring within minutes of the attack; the first response was mounted 19 hours later, and carrying out the containment plan took a further nine hours.[2] Detection was fast; it did not change the course of the attack. The window was set by the response. What DIVD's statements credit with keeping the intruder from moving deeper is network segmentation — a control that was already in place before anyone responded.

The proposed enduring role of the framework is to keep the question precise: which transition can this control affect, on what evidence, and in how much time? Replacing a human responder with an agent does not remove that question.

When Agents Lead Strategy, Shared Meaning Still Matters

There is no reason to assume that humans will permanently be better at synthesising evidence, comparing control portfolios or finding neglected attack paths. Agents may eventually lead those activities.

Even then, a proposal must pass between systems that may use different models, tools and internal representations. Organisations must also compare decisions over time. A versioned vocabulary provides continuity when the underlying reasoning systems change.

The core already names a machine-readable dictionary as the normative source for definitions, axioms and classification rules, with the boundary tests maintained in the core paper itself.[3] The agent-consumable OKF view is built from it. That is a concrete starting point for an interface that software can consume.

An advanced agent might reason internally with a much richer model. It could still expose a TLCTC-compatible view for communication and review. Whether that translation preserves enough decision-relevant information is a question to test.

Shared terminology also does not guarantee independent judgment. Two agents can agree because they share an error, incomplete evidence or the same compromised input. Review requires access to underlying observations and meaningful separation of evidence collection, execution and verification. A taxonomy supports that process; it does not enforce it.

What Would Weaken the Endurance Argument?

A useful framework must survive attempts to disprove it. The core's own refutation conditions are set out in Superman, Achilles, and How to Challenge the TLCTC Core; for the endurance argument specifically, four things would count against it:

  1. A missing mechanism. A well-evidenced, in-scope attack step cannot be represented without stretching an existing definition.
  2. Unreliable classification. Independent analysts or agents repeatedly reach incompatible assignments with sufficient evidence and the same versioned rules.
  3. No decision benefit. Using TLCTC does not improve coverage analysis, intervention choices, traceability or review compared with alternatives. Consistent labels alone would not justify the effort.
  4. A better replacement. Another representation preserves the relevant distinctions while being more accurate, easier to apply or more useful to both humans and agents.

These point to a practical research programme: compare security decisions with and without TLCTC under matched evidence and resources; measure classification agreement between analysts and between models; test whether proposed controls affect the claimed paths; and examine whether the representation stays useful as more decisions are delegated.

A system without exploitable vulnerabilities would also leave an attack taxonomy with little active work to do. The endurance argument concerns environments in which cyber compromise remains possible.

The User of the Framework May Change

Today, TLCTC helps a human understand and direct a security programme. In a more automated organisation, it could help agents coordinate, explain decisions and maintain comparable records. Under autonomous strategic leadership, it could remain the interface between machine reasoning, organisational objectives and independent review.

None of those roles requires humans to remain the best technical specialists or the best strategic planners. Each depends on the framework continuing to describe relevant mechanisms accurately and supporting decisions better than the available alternatives.

The intelligence may change.

The need to explain how compromise becomes possible may endure.

Further Reading


Sources and scope. This article presents a forward-looking argument. The scenarios and the agent-governance proposal are hypotheses, not demonstrated deployment outcomes. Framework references use TLCTC v2.6 (23 September 2026).

  1. Anthropic, GLM-5.3 and the spread of advanced cyber capabilities, 29 September 2026. Primary report of the cited evaluations; the models are Zhipu AI's. The quoted passage and the CVE-2026-11645 figures are the reporting laboratory's findings.
  2. DIVD, case DIVD-2026-00014 (the incident; open, last updated 9 October 2026) and case DIVD-2026-00015 (the Zammad vulnerabilities CVE-2026-102489 and CVE-2026-102490). The role of network segmentation is from DIVD's statements as reported by BleepingComputer, 30 September 2026. The use of AI agents is DIVD's assessment from observed behaviour; the investigation is ongoing.
  3. Bernhard Kreinz, A Cause-Oriented Cyber Threat Taxonomy: The TLCTC Framework, v2.6. See §§3–8 for the cause/event separation and scope boundary, the axioms (including Axiom IV), the rules, attack-path notation and limitations. CC BY 4.0. This article applies the framework; it is not a normative specification.
  4. Bernhard Kreinz, Applying the Top Level Cyber Threat Clusters, v2.6. Governance (§7), the control matrix (§§8–9), indicators (§10) and AI integration (§16). CC BY 4.0.
  5. Bernhard Kreinz, Layered Event Modelling: Semantic Separation as a Precondition for Explicit Causal Analysis, draft v0.4. §10 on event layers, detective versus response controls and the intervention window; §13 states the proposal's limitations.