
Next week I'll be in Austin for the INMM 67th Annual Meeting, and this year I have an unusually full slate: a lightning talk, a technical presentation, a poster, and a panel, all built around one theme of increasing the focus on people — the human-centric challenge for nuclear security and insider risk.
Despite decades of investment in physical protection, cybersecurity, and material control systems, some of the most consequential nuclear security incidents on record didn't start with a technical failure — they started with a person. From the 1961 SL-1 reactor accident in Idaho, to the 1979 uranium theft at a GE fuel facility, the 2012 sabotage investigation at San Onofre, the 2014 turbine-oil incident at Belgium's Doel-4 plant, and a 2013 espionage attempt by a former NRC employee, the same pattern shows up again and again: grievances, financial pressure, unusual interest in security procedures, and deteriorating performance as precursors. None of these cases were mysteries after the fact. The signals were there — what was missing was a way to see them together, early enough, and to act on them proportionately rather than reactively.

Four Sessions, One Thread
On Monday, August 3, I'm giving a lightning talk on "Trusted AI Decision Intelligence Support for Nuclear Material Accountability and Control." The core argument is straightforward: information theft, material diversion, sabotage, and unintentional error are all human-centric risks, and traditional perimeter defenses aren't built to catch them early. What's needed instead is a behavioral-science-driven approach that treats stress, complacency, and eroding security culture as legitimate signals worth watching, not just technical anomalies.
That same day, in session 12A, I present a paper co-authored by me and Dr. Christine Noonan (from Pacific Northwest National Laboratory) that presents a deeper technical treatment of the same problem: "Behavioral Analytic Modeling for Insider Threat Assessment & Mitigation in the Nuclear Power Industry." This talk gets into the mechanics of building a model like this. Relying on SOFIT, a knowledge base of several hundred sociotechnical and organizational risk indicators, and Cogility’s Hierarchical Complex Event Processing (HCEP), which encodes analyst expertise into layered, inspectable patterns rather than opaque machine-learning scores, this approach implements the design goal of full provenance (transparency): explainability by construction. When the system flags a case, an analyst should be able to see exactly which indicators and events drove that assessment, not just trust a number.

Later that day, in Poster Session 17, I'll have a poster based on the lightning talk topic, with room for the kind of one-on-one conversation that a 15-minute stage slot doesn't allow.
Then on Wednesday, August 5, I'm a featured panelist on "Catch Me If You Can: A Panel on Insider Threat Detection and Mitigation Lessons for Advanced Nuclear Facilities." Among my contributions to this panel discussion, I will introduce three key ideas or challenges…
First, the whole-person approach: technical activity monitoring, psychosocial indicators, and organizational factors all need to be fused into one picture, because looking at any one in isolation misses too much.
Second, how you actually evaluate competing modeling approaches — qualitative judgment, quantitative/probabilistic models, machine learning, and expert AI — against the criteria that matter for this domain: can it model expert tradecraft, does it scale, and is it transparent? In our validation work, an expert-AI approach built on HCEP was the only one of these approaches that met all three criteria at once, and in a knowledge-elicitation study it outperformed both a simple counting model and a probabilistic sum-of-risk model on precision, recall, and false-positive rate.
The third idea is one that I'm most eager to discuss, because it's genuinely new: the insider risk landscape itself is changing. As AI agents get embedded into enterprise and mission systems, they become a new category of insider — a "digital insider" with its own privileges, memory, and behavior over time, capable of anomalous delegation or opaque reasoning that quietly degrades human oversight. Managing this well means thinking in terms of a human-agent-system triad, where sponsorship and accountability sit with a person, but the agent's actions, tools, and permissions need their own monitoring, and the surrounding system's policy constraints need to be enforced automatically. It's a genuinely different governance problem than classic insider threat, and I don't think our field has caught up to it yet.

The Takeaway
If there's one thing I hope people take away from all four sessions, it's this: technical controls and compliance checklists are necessary but not sufficient. Insider risk is a socio-technical problem, and addressing it requires combining behavioral science with data fusion and expert AI, in a way that keeps a human accountable for every consequential decision. The goal isn't to automate judgment out of the loop. It's to help the people already doing this hard work see risk earlier, with better evidence, and respond in a way that's proportionate rather than purely punitive.
If you're going to be at INMM in Austin, I'd love to connect — whether at the poster, after the panel, or just in the hallway. And if you're working on insider risk, nuclear security culture, or trustworthy AI for high-consequence decisions, I'm always glad to compare notes.