Walacor and the DIA AI Chief’s Vision for Agent-to-Agent Operations
Artificial intelligence in defense is moving into a new operational phase. AI systems are beginning to retrieve intelligence, communicate with other agents, invoke tools, formulate plans, and participate directly in mission workflows at machine speed. The Defense Intelligence Agency is already describing this future.
In an August 13 DefenseScoop article, “DIA’s artificial intelligence chief envisions ‘agent-to-agents’ interactions that support military operations”, DIA Chief Artificial Intelligence Officer Maj. Gen. Robert Kinney outlined a future in which agents operating across a combatant command communicate directly with one another. DIA is currently undertaking a 90-day sprint to build an enterprise AI platform service while developing a Model Context Protocol, or MCP, capability intended to provide a more universal way for AI systems to access intelligence data. Kinney described agent development and agent-to-agent interaction as the direction DIA wants to pursue over the coming years.
Kinney offered a particularly useful example of what that environment could look like. A collection-management agent could communicate with agents supporting operations and fires, contested logistics, command, control, communications and cyber, and planning. DIA is simultaneously considering the compliance, security, Zero Trust, operational parameters, and guardrails required to support these capabilities responsibly. That architecture creates an important question: When machines begin communicating with machines and contributing to military decisions, how do we prove what happened?
Modern aircraft use flight data recorders to preserve authoritative evidence of what occurred across a complex operating system. As AI agents begin exchanging intelligence, invoking tools, coordinating with other agents, and contributing to military actions, agentic operations need an equivalent evidence layer. Walacor can provide that capability: a persistent, cryptographically verifiable mission record connecting the data an agent received with the processes, interactions, decisions, authorizations, and actions that followed.
From Human-Speed Audit to Machine-Speed Evidence
Traditional systems were built around human actions. People review information, make decisions, approve actions, and leave behind records that investigators can reconstruct later. That process takes time—and that time creates a natural opportunity for oversight.
Agentic AI removes that buffer. AI agents can retrieve, interpret, enrich, share, and act on information across multiple systems in seconds. By the time a human could review one step, an agentic workflow may have already completed dozens.
When decisions move at machine speed, traditional audit practices risk falling behind. Organizations need evidence that moves just as fast, verifying what each agent received, how it was processed, what influenced the outcome, and whether the resulting action remained intact through execution.
This requires a persistent, verifiable chain of evidence across humans, AI agents, models, tools, and mission systems.
Agent-to-Agent Systems Create a Chain-of-Custody Requirement
As Kinney describes, future operational environments may rely on multiple AI agents working together across collection management, fires, logistics, command and control, communications, cyber, and planning. These agents can exchange, transform, and act on information in seconds.
That speed creates a serious risk. Without a trusted chain of custody, operators may have no reliable way to know what information an agent received, how it changed, which model or tool influenced it, or why a particular action was ultimately recommended. If something goes wrong, reconstructing the decision after the fact may be impossible.
Every agent-to-agent handoff therefore needs to become part of the mission record. Walacor provides a cryptographically verifiable evidence layer that preserves immutable history, versioning, encryption, and integrity proofs, creating a trusted record of what each agent received, produced, communicated, and ultimately caused to happen.
The Flight Data Recorder Model
A flight data recorder preserves evidence from the operation of an aircraft so that the sequence of events can later be reconstructed with confidence. Agentic military operations create a similar requirement across a distributed digital environment.
Walacor serves as the flight data recorder for agentic warfare, creating what can also be viewed as a mission data record for autonomous operations. A mission evidence chain could preserve the source data, its integrity and version, agent context, model and configuration, agent output, agent-to-agent message, tool invocation, tool result, policy decision, human authorization, and resulting mission action. Each stage becomes part of an attributable history that follows the decision across participating systems.
Source Data → Integrity and Version → Agent Context → Model and Configuration → Agent Output → Agent-to-Agent Message → Tool Invocation → Tool Result → Policy Decision → Human Authorization → Mission Action
As agent architectures become more decentralized, this capability becomes increasingly important. Agents, models, databases, MCP servers, edge systems, mission applications, and external tools may all contribute to a single operational outcome. Persistent provenance allows that outcome to be traced across the systems that created it while preserving the integrity of the underlying evidence. Trust can travel with the data and the evidence.
MCP as a Natural Trust Boundary
DIA’s focus on Model Context Protocol is particularly significant. MCP provides a technical framework that allows AI tools to connect with external systems and data sources, and DIA is developing an MCP capability as part of the digital foundation for broader intelligence-data access and future agent development.
That standardization creates a natural evidentiary checkpoint. When an agent requests information or invokes an external capability through MCP, the interaction can preserve which agent made the request, what resource or tool it requested, what arguments were supplied, what data was returned, which version of that data was used, what policy governed the interaction, and what action followed.
A data-integrity layer positioned around these interactions can preserve a cryptographically verifiable mission record across the agent ecosystem. The model, MCP server, external tool, data source, and receiving agent each become attributable participants in the same evidence chain.
This creates a powerful architectural opportunity for Walacor. MCP provides a common interaction surface where data access, tool execution, agent behavior, and policy decisions can be tied to persistent provenance and independently verifiable evidence.
Zero Trust at the Data Layer
Kinney also identified Zero Trust as one of the areas DIA expects to address as agent-to-agent capabilities mature. Agentic systems make the data component of Zero Trust increasingly important because autonomous systems depend upon information assembled from growing numbers of sources, services, agents, and transformations.
Identity establishes who acted. Authorization establishes what that identity can access or execute. Policy establishes the conditions governing the action. Data integrity and provenance establish what information the action was based upon. Together, these controls create a more complete trust architecture for autonomous operations.
Walacor provides persistent integrity, history, and provenance for the information flowing through that architecture. Its immutable audit capabilities preserve changes and historical versions, while envelope validation provides a mechanism for verifying the integrity of specific stored records. This creates a stronger foundation for establishing what an autonomous system knew at the moment it made a recommendation, communicated with another agent, or contributed to an operational action.
The Irreversible Action Problem
One of the most consequential parts of Kinney’s comments concerned the distinction between reversible and irreversible effects. He suggested that some mission areas may support greater autonomy or a human operating “on the loop,” while more irreversible mission areas, including fires, require a human in the loop as these capabilities improve. That distinction creates an especially important role for evidentiary integrity.
For consequential actions, the mission record can establish exactly what was being authorized. The evidence chain can preserve the intelligence supporting the recommendation, the agents that contributed, the model versions involved, the transformations that occurred, the tools that were invoked, the policies that were evaluated, the information presented to the operator, the decision that was approved, and the instruction ultimately executed. Cryptographically verifiable evidence can bind those stages together, making the entire loop provable.
A human authorization event gains substantially greater evidentiary value when it is connected to a verifiable record of the intelligence, agent interactions, model outputs, policies, and tool executions that produced the decision. This provides commanders, operators, investigators, and oversight authorities with a durable operational record of how consequential machine-assisted actions developed.
Building Trust as Autonomy Scales
DIA is currently building the digital foundation and “pipes” that will support data access and the development of agents. Officials are also considering the tradecraft, parameters, responsible-use practices, security controls, and guardrails that will govern agents interacting with other agents. This creates an opportunity to establish the evidence architecture alongside the agent architecture itself.
Data can be verifiable from the beginning. Agent interactions can preserve provenance from the beginning. Tool execution can produce persistent evidence from the beginning. Authorization can be bound to the exact information and action being authorized from the beginning. The resulting mission history can remain independently verifiable across the applications, models, agents, services, and data environments that participate in creating it.
Walacor is designed for this type of role. Its architecture provides persistent data integrity, immutable history, encryption, provenance, validation, and audit capabilities that can operate alongside existing data platforms and mission systems.
The emerging agentic environment expands the value of those capabilities across an entire operational chain. Individual integrity proofs become part of a broader mission record, connecting the information used by autonomous systems to the actions and decisions they help produce.
The Trust Layer for Agentic Operations
Agent-to-agent architectures promise significant operational advantages. Specialized agents can work simultaneously, exchange information across organizational functions, interact with enormous datasets, and compress portions of the observe-analyze-plan-act cycle toward machine speed. DIA’s envisioned environment connects collection, operations, fires, logistics, communications, cyber, and planning through increasingly capable AI agents.
As those systems become connected, the integrity of the information moving between them becomes part of mission integrity. One agent can influence another almost instantly. Autonomous processes can invoke tools and affect external systems. Intelligence, cyber operations, targeting, logistics, planning, and fires can become connected through software-mediated decision chains.
The future defense AI architecture requires persistent operational memory, verifiable provenance, independently validated evidence, and a trustworthy chain from data to agent to agent to decision to action. Walacor provides the foundation for that mission record.
As the Department of Defense advances toward agent-to-agent operations, the flight data recorder for agentic warfare can be built into the architecture from the beginning.


