Session

Stop Pressing 1: Matching Oversight to Autonomy in AI-Assisted DevSecOps

AI-assisted development tools are entering government and defense DevSecOps pipelines at an accelerating pace. Coding agents, automated testing systems, and AI-powered workflow tools promise increased velocity and faster time to deployment. But the oversight model has not kept up. Human review remains the primary security control, and it is based on the assumption that the person approving an AI-generated action has actually read and understood what it does.
AI has accelerated the amount of code that is being shipped, and speed without comprehension is a security failure. An operator who approves an agent's action without understanding it has not performed oversight, and it can cascade onto the QA engineer and the entire team.
I call this the reading problem. I encounter it both as a security practitioner working with AI agents and as an educator who has spent years designing systems around the fact that people do not read before they act. This design has direct implications for any DevSecOps pipeline that relies on human review as a security gate.
This talk proposes a two-part solution. First, a three-level framework of agent autonomy: suggest-and-approve, act-and-monitor, and independent operation--that identifies how the reading problem undermines the security model at every level. Each level demands different controls. Misclassifying the autonomy level means deploying the wrong ones: approval prompts where rate limits were needed, monitoring dashboards where containment boundaries were needed, policies where permission isolation was needed.
Second, a comprehension gate: an oversight mechanism adapted from formative-assessment techniques I have refined with over 100 students. Before a high-risk AI-generated action can be approved, the system analyzes the proposed change and generates targeted questions about what is changing and what the risk is. I will demo a working prototype and walk through where comprehension gates catch genuine oversight gaps versus where they introduce friction without commensurate security benefit. The goal is a practical framework: classify the autonomy level of each AI tool in your pipeline, match it to the right oversight mechanism, and stop relying on human review at stages where nobody is actually reading.

Rita Sabri

Cybersecurity educator and researcher

Washington, District of Columbia, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top