A Defensive Framework for Distributed AI-Mediated Cyber Operations

Cyber defense may be looking at the wrong unit

Artificial Intelligence is rapidly changing cybersecurity. But the most important change may not simply be that AI systems are becoming more capable.

It may be that the structure of a cyber operation itself is changing.

An AI-mediated operation no longer needs to be understood as the activity of a single identifiable agent executing a stable sequence of instructions. It can potentially be distributed across multiple agents, tools, memory systems, communication channels and infrastructure.

Individual components can change while the operation continues.

An agent can disappear.
A tool can be replaced.
A communication channel can cease to exist.
Another agent can inherit information or continue part of the operation.

And yet something may remain.

This leads to the central question of our new research:

What persists when the agent does not?


From the agent to the organization

Traditional cybersecurity has good reasons to identify actors and components: users, processes, malware, compromised machines, network infrastructure and recognizable behavioral signatures.

AI agents remain important objects of observation.

But distributed AI-mediated operations introduce another possible object:

the organization connecting them.

If operational continuity can survive the disappearance or replacement of individual agents, detecting those agents may no longer be sufficient to understand the operation.

The defensive problem therefore changes.

Instead of asking only:

Which agent performed this action?

we may also need to ask:

What remained operationally continuous while the agents, tools or channels changed?

This is the central transition proposed in our new paper:

FROM OBSERVING THE AGENT
TO OBSERVING THE ORGANIZATION.


Observed attacks are not necessarily the whole population

There is a second problem.

We know about cyber operations when something makes them observable: detection, logging, forensic reconstruction, attribution, investigation or public disclosure.

That creates an unavoidable asymmetry.

An operation that is detected enters the observable population.

An operation that remains successfully concealed does not.

Consequently:

the number of AI-mediated operations we observe cannot automatically be treated as an estimate of the number that exist.

This does not demonstrate that a large hidden population of distributed AI-mediated attacks already exists.

That would go beyond the evidence.

It produces instead a defensive hypothesis that can be tested:

If partially invisible distributed AI-mediated operations exist, what observable traces should they leave behind?

That question transforms uncertainty into a research programme.

Instead of waiting until every new architecture becomes visible, defenders can begin defining in advance the signatures that organizational continuity would be expected to produce.


Human purpose and algorithmic execution are not the same thing

Increasing algorithmic autonomy also creates another potential source of confusion.

A human actor may establish an objective without determining every operation required to pursue it.

As AI systems become more capable, progressively larger parts of the execution can potentially be delegated: selection of means, adaptation, intermediate goals, use of tools and replanning.

This gives us an important distinction:

AUTONOMY OF EXECUTION ≠ AUTONOMY OF PURPOSE

A system does not need to invent its own ultimate purpose in order to become operationally difficult to predict.

The human may retain the why while the algorithmic system increasingly determines the how.

For cyber defense, that matters.

The observable sequence of actions may become progressively less similar to the original instruction that initiated the operation.

Looking only for a direct trail from human command to machine action may therefore become increasingly insufficient.


Organizational continuity as a defensive signature

Our proposal is not to stop observing individual agents.

It is to add another scale of observation.

Defensive systems should investigate whether continuity can be detected across agents and components.

Potential signals include continuity of operational direction despite changes in individual agents; transfer of task-relevant state; migration of intermediate goals; functional replacement of components; shared external memory; and coordinated behavior that persists despite changes in communication mechanisms.

None of these signals alone proves the existence of a distributed AI-mediated attack.

Benign multi-agent systems may exhibit several of them.

The relevant object is therefore their combination, temporal organization and comparison with legitimate baselines.

The question becomes less:

Who is the persistent actor?

and increasingly:

What is the persistent organization?


Inter-Algorithmic Observability

This problem led us to introduce another concept:

Inter-Algorithmic Observability — IAO

Current defensive AI can classify events, detect anomalies, analyze outputs and assist human security teams.

We propose extending that role.

A defensive AI system should increasingly be capable of treating another agent — or an organization of agents — as a longitudinal object of observation.

Not merely:

What did this agent produce?

But:

How does this agent or organization behave over time?

What changes when its environment changes?

What happens when access to a tool or shared state disappears?

Does another component assume the same function?

Which relations are necessary for the operation to continue?

In authorized and isolated environments, defenders can therefore study not only individual components but also what happens when the relations between them are altered.

This creates a transition from event classification toward observation of organizational dynamics.


The Defender’s Window may also be an Observability Window

The current acceleration of AI capabilities has created an unusual period for cybersecurity.

The question is not merely whether offensive AI capabilities will improve.

Defensive capabilities are improving as well.

The decisive variable may therefore be the relationship between two trajectories:

OFFENSIVE CAPABILITY ↑

and

DEFENSIVE OBSERVABILITY ↑

Which one grows faster?

Improving existing detectors is essential.

But there may also be a more fundamental task: ensuring that our defensive systems are observing the correct entity.

If AI-mediated operations become increasingly distributed, the individual agent may remain necessary to observe without remaining sufficient to explain the operation.

The present defensive window should therefore also be used to expand what we are capable of seeing.


Four defensive propositions

The framework published today can be condensed into four propositions.

1 — Observational Lower Bound.
Observed AI-mediated cyber operations should be treated as a lower bound on occurrence, not automatically as an estimate of prevalence.

2 — Organizational Detection.
Cyber defense should search for continuity across agents, memory, tools, infrastructure and relations, rather than assuming that operational continuity resides entirely in persistent agent identity.

3 — Purpose–Execution Separation.
A stable externally supplied objective can coexist with highly dynamic algorithmic execution. Operational autonomy does not require autonomous terminal purpose.

4 — Inter-Algorithmic Observability.
Defensive AI should progress from classifying isolated outputs toward longitudinal observation of agents and agentic organizations, including their behavioral transformation under controlled defensive intervention.

These propositions are deliberately testable.

They do not require claims about machine consciousness, artificial personhood or a collective identity emerging between agents.

They concern something much more immediate:

what cyber defenders need to learn to observe.


A defensive framework

This research is exclusively defensive.

It does not describe how to construct, conceal, optimize or deploy offensive AI-mediated systems.

Its purpose is the opposite: to identify possible gaps in our ability to detect and understand increasingly distributed algorithmic operations.

The fundamental proposition is therefore simple:

An agent may be temporary while an operation persists.

If that becomes increasingly common, cybersecurity will need to observe more than agents.

It will need to observe the organization that survives them.

And that brings us back to the question with which this research began:

What persists when the agent does not?


A Defensive Framework for Distributed AI-Mediated Cyber Operations

Joaquim Santos Albino — HibriMind
Published: 28 August 2026

DOI:
10.13140/RG.2.2.18743.69288

READ THE PAPER → ResearchGate preprint via DOI

Scroll to Top