SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Noah Labs AI touts governed software agents for defence

Noah Labs AI touts governed software agents for defence

Mon, 24th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Noah Labs AI has outlined its case for Autonomous Software Operators in secure software development, aimed at government and other highly regulated industries.

The company describes an Autonomous Software Operator, or ASO, as a governed software agent that handles code modernisation, verification, security analysis, documentation and compliance evidence generation inside controlled environments. The model is intended for settings where software changes can affect operational behaviour and therefore require the same oversight applied to other autonomous systems.

Murat Isik, Founder and Chief Executive Officer of Noah Labs AI, argues that software in government and regulated sectors remains constrained by cost, delays and technical risk. Many of the latest AI coding tools, he says, are not suited to those environments because repositories are too large, code is often written in legacy or specialist languages, and leading models are too large to run in secure or air-gapped systems.

His argument centres on treating software as a dynamic asset rather than a task for a coding assistant. Under that approach, an AI system that can modify or deploy code would need bounded scopes of action, approval gates and reproducible logs, rather than operating as an unrestricted tool in a developer environment.

That distinction matters in defence and regulated computing, where code changes can have direct operational consequences. The challenge, Isik argues, is not only to generate working code, but also to show what an agent was allowed to do, what evidence it used and how it reached a conclusion.

Four dimensions

The ASO model is framed around four elements: tempo, assurance, governance and human control. Tempo refers to reducing the lag between a threat emerging in the field and a fix being deployed. Assurance is tied to machine-checkable rules and structured evidence such as tests, proofs and software bills of materials.

Governance means embedding risk management and authorisation logic directly into the development workflow rather than adding compliance checks at the end. Human control is presented as visibility into what an agent proposed, what it executed and how that action related to operational behaviour.

Isik argues that this requires more than a final approval step. Engineers and decision-makers need traceability and observability throughout the process so they can assess the basis for any recommendation or code change before accepting it.

"I use the term Autonomous Software Operator, or ASO, to describe a governed software agent that assists with code modernization, verification, security analysis, documentation, and compliance-evidence generation inside controlled environments. These are mission-aligned agents that implement, oversee, and adapt the lifecycle of software in a secure setting. They are not built to displace the engineer or the commander, but to act as a co-pilot, with formal verification and compliance built into the pipeline," said Isik, Founder and Chief Executive Officer of Noah Labs AI.

Existing review processes, the company argues, were not designed for software agents that can propose and process changes far faster than conventional teams. In that environment, governance has to be built into the workflow itself, including policy constraints, allowable actions, evidence gathering and approval requirements.

Secure settings

The focus on air-gapped and controlled systems reflects a practical limitation in the current AI software market. Many organisations handling sensitive systems cannot use cloud-based coding services or large external models because of security rules, infrastructure constraints and accreditation requirements.

An autonomous software system, Noah Labs argues, must work with the repositories, programming languages, tools and approval structures already in place. That means fitting into existing development and compliance processes rather than assuming they can be replaced wholesale.

Isik's background combines AI systems and hardware. According to biographical information provided alongside the article, he is pursuing a PhD in Electrical Engineering focused on machine learning hardware and previously worked at Intel and Lattice Semiconductor. He also co-founded Type 1 Compute and Chip Interfaces before starting Noah Labs AI.

One practical use for an ASO, the company says, would be modernising mission-critical systems, including moving software from languages such as C++ or Ada into Rust or Java, while linking those changes to safety analysis and vulnerability tracking against standards including NIST and OWASP controls.

"An ASO treats software as a dynamic asset, not merely as something handled by an AI coding tool. Once an AI system can modify or deploy code that affects operational behavior, that activity is no longer a developer-environment convenience; it is an instance of autonomy that must satisfy the same verification, validation, safety, and human-judgment constraints that apply to any other autonomous system. ASOs make those constraints explicit in the software lifecycle, with bounded scopes of action, clear approval gates, and reproducible logs for review," said Isik.

Noah Labs' broader claim is that software in sensitive environments should be able to change at operational tempo without losing institutional oversight. "The idea is not to slow down an agent enough for it to look like a conventional software development process, but rather to make sure that its speed is compatible with accountability," Isik said.