Dados abertos / Versão 1

Delegating Information Security Governance Work to Autonomous Artificial Intelligence Agents: Delegability Criteria, Autonomy Levels, and Accountability

##article.authors##

DOI:

https://doi.org/10.37497/opsbrazil.44

Keywords:

Autonomous Artificial Intelligence Agents, Information Security Governance, InformArtificial Intelligence Governance, Automation, Identity And Access Management, Human Oversight, Accountability, Autonomy Levels

Resumo

The increasing adoption of autonomous artificial intelligence agents in corporate environments is redefining the boundaries between human work and automated execution in information security governance. Activities such as access reviews, request handling, compliance evidence collection, alert triage, and inventory updates involve significant operational components; however, their automation raises a governance question that is not adequately addressed by the binary distinction between manual and automated work: what degree of autonomy is admissible for a given task, and under what conditions can such delegation remain accountable, auditable, and defensible? This article proposes a task-based model for determining the admissible degree of delegation of information security governance activities to autonomous artificial intelligence agents. The model considers five attributes: criterion determinism, outcome verifiability, effect reversibility, regulatory consequence, and the cost of error at scale. These attributes are associated with five delegation levels, ranging from human execution to autonomous execution with exception-based control. Progression between levels is conditioned on measured and stable divergence between agent decisions and human decisions rather than on perceptions of technological maturity. The model is examined through a single case study conducted in a medium-sized Brazilian organization. During calibration, divergence between agent-proposed decisions and human decisions was 14%, decreasing to 3% after the decision criteria stabilized. Average resolution time also decreased from approximately 48 hours to approximately 10 minutes. The findings provide preliminary empirical evidence supporting the proposition that autonomy should be assigned according to task characteristics and demonstrated performance, while accountability remains linked to an identifiable human owner.

Downloads

Não há dados estatísticos.

Biografia do Autor

Mathews Henrique da Cruz, Technology and information security professional

Mathews Henrique da Cruz is a technology and information security professional with an MBA in Information Security from the Catholic University of Brasília. He works on the development and implementation of solutions focused on automation, information security governance, identity and access management, and the use of autonomous artificial intelligence agents in corporate environments. His professional and academic interests include the integration of artificial intelligence, cybersecurity, process automation, and governance frameworks, with particular emphasis on autonomy, control, auditability, and accountability.

Referências

Endsley, M. R. (1997). Designing for situation awareness: An approach to user-centered design. Pro-ceedings of the IEEE International Conference on Systems, Man, and Cybernetics, 1, 272–276.

International Organization for Standardization. (2022). ISO/IEC 27001:2022 information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO.

International Organization for Standardization. (2023). ISO/IEC 42001:2023 information technology — Artificial intelligence — Management system. ISO.

National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53, Rev. 5). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-53r5

National Institute of Standards and Technology. (2020). Zero trust architecture (NIST Special Publica-tion 800-207). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-207

National Institute of Standards and Technology. (2023). Artificial intelligence risk management fra-mework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1

OWASP Foundation. (2025). OWASP Top 10 for large language model applications. OWASP Founda-tion.

Parasuraman, R., Sheridan, T. B., & Wickens, C. D. (2000). A model for types and levels of human interaction with automation. IEEE Transactions on Systems, Man, and Cybernetics — Part A: Systems and Humans, 30(3), 286–297. https://doi.org/10.1109/3468.844354

Downloads

Postado

02-09-2026

Categorias