The Army Wants AI Agents Fighting Back Against Cyberattacks

Original Broadcast Date: 10/04/2026

The Army is exploring how artificial intelligence agents can help defend its networks as cyber threats become increasingly automated.

Brandon Pugh, the Army’s principal cyber advisor, says one of his biggest priorities is figuring out how the Army can use AI specifically for cyber defense.

Much of the conversation around AI and cybersecurity focuses on how adversaries could use the technology. Pugh says he is focused on the other side of that equation: using AI to make Army cyber operators and defenders more capable.

That effort helps lead to Project Griffin, one part of a broader push to explore agentic capabilities for Army cyber defense.

The Army brings 14 C-suite leaders to the Pentagon for a tabletop exercise built around a challenging scenario: an adversary launching thousands of cyberattacks autonomously at the same time.

The question for the Army is what technology already exists that could help counter those attacks, either autonomously or alongside human operators.

The exercise identifies roughly 17 to 20 capabilities the Army could potentially bring into its environment. Pugh says trying to pursue all of them simultaneously would make it difficult to execute any of them well.

Instead, the Army narrows its initial focus to three lines of effort.

Pugh wants those capabilities to move through quick sprints rather than becoming multiyear projects. That requires funding, Army units willing to pilot and field the technology, and close coordination with the acquisition community.

The exercise also raises policy questions.

The Army has to determine what could prevent agentic capabilities from being introduced quickly onto its networks and how human operators should interact with those systems. That includes questions about when a human should remain involved and when an AI agent could potentially respond on its own.

Pugh says another major lesson comes from industry.

No single organization has all the answers, he says, making collaboration between the Army and companies important. The 14 leaders involved in the exercise include both Army vendors and large multinational companies that do not currently sell to the Army.

Those companies operate their own complex networks and can provide insight into how advanced AI agents might work in large environments.

That industry interest becomes clear when the Army opens a commercial solutions opportunity connected to Project Griffin.

The Army is looking for a capability that can take the next step after a potential cyber incident is detected and respond agentically. Companies have only seven days to submit proposals.

The Army receives 108 submissions.PughFrame1

Pugh says the responses come from organizations of different sizes, ranging from small companies to multinational firms.

The Army’s three initial focus areas are selected in part to complement, rather than duplicate, other cyber and AI work underway across the military.

One line of effort focuses on agentic response to detected incidents. Another explores an AI agent capable of deceiving an adversary. The third focuses on purple teams and how the Army assesses its cybersecurity posture and responds to what it finds.

Pugh hopes those three efforts are only the beginning. Rather than completing one before beginning another, he wants all three to advance roughly in parallel. If they succeed, he sees an opportunity to add more capabilities.

AI is only part of Pugh’s cyber portfolio.

His office also serves as the secretariat lead for the Army’s critical infrastructure work, covering cyber and physical risks across 288 camps, posts and stations.

Pugh says protecting that infrastructure is essential because an adversary could try to disrupt the Army’s ability to move troops and equipment when they are needed.

A defense critical infrastructure summit at Fort Bragg reinforces one central lesson: the Army cannot address that challenge by itself.

Pugh says partners including the Department of Homeland Security, FBI and Department of Energy bring authorities and resources that can help the Army address infrastructure risks collectively.

Inside the Army, his office also works to harmonize efforts involving organizations responsible for installations, operational technology, cyber and IT.

The Army has already conducted a 14-site pilot examining vulnerabilities and gaps at installations and aligning funding to address them. Pugh says the goal is to take lessons from those sites and scale the approach to more installations.

The Army is also developing a guidebook with interagency partners to help garrison commanders work with their communities.

Private utilities are an important part of that effort because much of the infrastructure the Army depends on is privately owned.

Across both Project Griffin and critical infrastructure protection, Pugh’s approach centers on the same idea: bringing government and industry together, focusing resources on manageable problems and moving promising capabilities into use quickly.