Autonomy
Cyberdroid AI Detection observes and Cyberdroid AI Investigation investigates read-only, the first two of our five autonomy levels. The suite acts only by rules and approvals your team sets, so every action traces to a person’s decision. No ARRTECH product works at the top level.
Principles
Joint guidance from CISA and eight partner agencies says language models almost certainly should not make safety decisions in operational technology. AI Detection and AI Investigation make no decisions for your estate. They read telemetry and change nothing.
Joint guidance on agentic AI from six agencies in the Five Eyes countries asks for human approval before high-impact actions. In ARRTECH SOAR, an Operator node emails a person with up to five color-coded options and waits. Nothing below it runs until the reply arrives.
Australia’s ASD advises limiting autonomous actions to those that are narrowly scoped, preapproved and reversible. ARRTECH SIEM alert actions, SOAR playbooks and DLP policies act only as your team wrote them. Review a change to them as you would any change to production.
The US Nuclear Regulatory Commission publishes notional autonomy levels, from insight to fully autonomous, and notes that higher levels may need more scrutiny. Our five-level scale places each ARRTECH product by the decision a person keeps.
The OT guidance asks that AI-enabled processes can revert to manual or conventional control. Our AI layer controls no process, so nothing reverts. When AI Investigation runs out of budget or evidence, it parks the case incomplete instead of concluding.
The DHS framework asks for meaningful human oversight of consequential decisions, and NERC’s white paper gives the operator the final input. No ARRTECH product lets a model choose an action on its own. Every request to AI Investigation is recorded with a reason.