The new OODA loop didn't remove the risk. It moved it.

A closed-door security conference in DC reframed the OODA loop for the AI era. Half the reframe holds up. The other half is where security programs will get hurt.

At a Summit in Washington last week, one speaker offered a clean update to Boyd's OODA loop for the AI era: sensor, aggregator, command and control, effector. Human functions swapped for machine ones, node by node. The pitch was speed. Compress decision to action, and you win the loop.

Half of that holds up. The other half is where AI-driven security programs will get someone fired, or worse, sued.

This isn't new vocabulary. Sensor, C2, and effector come straight out of military kill-chain doctrine, the sensor-to-shooter pipeline that already runs air defense and precision fires. Applying that architecture to a governance context is a real contribution. Quietly redefining what Orient means while doing it is the problem.

The mapping has a hole in it

Boyd's Orient step was never just data fusion. It was the hardest part of the loop: weighing new information against experience, context, and stakes.

Calling that step "aggregator" quietly swaps interpretation for pipeline hygiene. An aggregator merges feeds. It doesn't judge whether an anomaly matters.

That gap is where the Four Pillars framework earns its keep. The Human Element of Tech pillar says technology reflects the judgment of the people who build it. Skip the judgment step and rename the pipeline, and the system reflects an absence, not a decision.

Fix it by putting the step back, honestly labeled: sensor collects, aggregator fuses, interpreter weighs context and assigns confidence. What comes next is the part boards actually need to understand.

Compression happens at the gate, not at command

The real gain from AI isn't a faster human decision. It's fewer decisions that need to be made live, because most of them got made in advance.

Build an authorization gate that checks incoming actions against a pre-approved envelope: high confidence, reversible, previously seen, small blast radius. Anything inside the envelope goes straight to execution. Anything outside it escalates to a person, on purpose, because that's exactly the traffic that needs one.

This is not new architecture. It's how a badge system already works. A swipe that matches the schedule opens the door.

A swipe at 3 a.m. from a badge that's never been in the building goes to a guard with a camera feed pulled up. That part isn't new either. AI just widens what qualifies as "matches the schedule."

Two ways this breaks

Envelope creep. Every near miss that didn't cause harm creates pressure to widen the boundary. Do that enough times without re-certifying the policy and you get the Challenger pattern: incremental acceptance of risk until the thing that was always outside tolerance finally matters.

The envelope needs an owner and a change log, not a default setting nobody revisits.

Confidence laundering. The gate trusts whatever confidence score the interpreter reports. If that score is wrong, meaning the system says 95 percent and is actually right 70 percent of the time, the gate will wave through actions that never should have cleared.

This failure is invisible in normal operation. It only shows up in an audit, after the fact, because the gate did exactly what it was told.

Where this lands on a board agenda

This is the Chief Agent Officer's actual job, and it sits squarely inside what the Four Pillars call From Doers to Orchestrators. The job was never running the loop by hand. It's defining what the loop is allowed to do without a human in it.

Not reviewing individual actions. That doesn't scale and defeats the purpose of automating the gate. The job is to define the envelope, stress-test its edges before deployment, and re-certify it on a schedule as the threat picture changes.

Whoever owns that envelope owns what happens inside it. That's not a technical statement. It's a liability question wearing an architecture diagram as a disguise, and it's the question boards should ask before approving the budget line for AI-driven security operations, not after the first incident report.

Morning takeaway

Before your organization compresses any decision loop with AI, find the authorization gate. If nobody can show you the envelope it enforces, in writing, with an owner's name on it, you don't have a faster OODA loop.

You have a faster way to find out where your governance was thin.

Reply

Avatar

or to participate