Innovation

Securing the Probabilistic Future: DevSecOps in the Age of Agentic AI

Written by Fed Gov Today | Aug 5, 2026, 2:24:49 PM

Presented by Carahsoft

Artificial intelligence and autonomous technologies are forcing federal agencies to reconsider conventional approaches to software development, testing and security. Anil Chaudhry, Senior Advisor for AI, Autonomy, and National Security at the Department of Transportation, explains that the challenge is especially consequential when software controls vehicles, aircraft, drones and other physical systems. Unlike applications that manage only digital information, failures involving transportation systems can cause immediate real-world harm.

Chaudhry points to autonomous safety features in commercial vehicles as an example. Automatic braking, lane controls and collision avoidance can improve everyday safety, but those same safeguards may interfere with police vehicles, ambulances or fire trucks responding to emergencies. First responders may need to cross a median, travel against traffic or make contact with another vehicle. Autonomous systems therefore need trusted mechanisms for shifting into a different operating and risk model under clearly defined circumstances.

The growing use of commercial technology for public safety and national security adds another layer of complexity. Drones designed for inspections or firefighting can provide emergency responders with situational awareness before personnel arrive. Similar technologies can also be adapted for military purposes. Government must encourage innovation while preserving accountability for how increasingly autonomous systems behave.

DevSecOps is central to that effort, but Chaudhry says the discipline must evolve for agentic AI. Traditional DevSecOps is largely deterministic, relying on predefined rules, scripted orchestration and linear security scans. Large language models are probabilistic, and agentic systems can pursue an objective without following a fully prescribed sequence of actions. That makes outputs less predictable and complicates conventional validation.

Agencies may need continuous, looping assessments and new forms of human oversight. The central question is whether people can understand and correct systems whose code and decisions may be too complex to review line by line. In this environment, DevSecOps must connect innovation, security and accountability throughout the lifecycle.

Key Takeaways

  • Software controlling physical systems requires a different risk calculus because failures can cause immediate real-world harm.
  • Agentic AI shifts development from deterministic instructions toward probabilistic, goal-oriented behavior.
  • Agencies need continuous assessment and meaningful human oversight as AI-generated code and decisions become more complex.