Innovation

Building Agentic Cyber Defense at Mission Speed

Written by Fed Gov Today | Sep 18, 2026, 3:30:46 PM

Presented by Carahsoft

Artificial intelligence gives adversaries the ability to launch large numbers of cyberattacks simultaneously. The U.S. Army is examining how autonomous agents can help its defenders respond at comparable speed without losing the judgment and oversight provided by human operators.

Brandon Pugh, Principal Cyber Advisor for the U.S. Army, says this effort grew from a central question: How can the Army use AI specifically for cyber defense?

Speaking at the Billington Cybersecurity Summit 2026, Pugh describes an exercise that brought 14 senior private-sector leaders to the Pentagon. Participants considered a scenario in which an adversary launched thousands of autonomous cyberattacks against the Army at the same time.

The discussion focused on the capabilities that could help the Army respond agentically or in partnership with human defenders. The group identified approximately 17 to 20 possible applications.

The Army recognized that it could not pursue all of them simultaneously and still move quickly. Leaders narrowed the initial work to three areas where a concentrated effort could produce operational capabilities within months rather than years.

Three Initial Lines of Effort

One priority is using AI agents to respond to detected incidents. Existing tools can identify suspicious activity, but the next step is enabling an autonomous capability to act on that detection within approved boundaries.

A second area involves agentic deception. A defensive agent could create misleading information or environments that complicate an adversary’s operation and reveal more about its techniques.

The third priority supports purple teams, which combine offensive and defensive perspectives to assess an organization’s security posture. AI could help identify weaknesses, test defenses and recommend or initiate corrective action.

These projects are intended as rapid sprints rather than multiyear development efforts. Pugh says that requires more than selecting promising technology.

Funding must be aligned with each effort. Army units must be prepared to pilot and field the capabilities, and acquisition professionals must be involved from the beginning. Policy questions also need to be resolved, including when an AI agent may respond autonomously and when a human must approve the action.

Learning Through Government-Industry Collaboration

The exercise also demonstrated the value of bringing several companies into the same room, even when they compete in the marketplace.

No single organization has every answer for agentic cyber defense. Each participant brought experience with different networks, security challenges and uses of AI.

Only about half of the participating organizations were current Army vendors. The others included large multinational companies operating complicated technology environments. Those companies could share lessons from deploying AI agents without an immediate expectation of selling a product to the Army.

Pugh says that willingness to collaborate reflected a shared interest in protecting the country.

The Army subsequently opened a commercial solutions opportunity seeking a capability that could respond agentically after a potential cyber incident was detected. The government received 108 submissions in seven days.

The proposals came from both small businesses and large multinational companies, demonstrating significant industry interest in supporting the mission.

Starting With Focused Sprints

The Army chose the initial three priorities by looking for areas where commercial capabilities could address gaps without duplicating work underway elsewhere in the military.

Army Cyber Command and other defense organizations already have AI and cybersecurity initiatives. The objective was to find capabilities that did not currently exist within those programs and determine whether an available industry solution could be piloted quickly.

Pugh hopes success with the first three projects will create a path for additional capabilities. The initial efforts can proceed in parallel, and the Army can add more once the model proves effective.

Demand for agentic cyber defense is unlikely to decline. The challenge is establishing a repeatable process for identifying needs, bringing the right partners together and moving a capability into operational use.

Protecting Defense Critical Infrastructure

Pugh also connects AI-enabled defense with the broader security of Army critical infrastructure.

The Army is responsible for hundreds of camps, posts and stations. An adversary could attack the infrastructure supporting those locations to disrupt the movement of forces and equipment during a crisis.

A recent critical-infrastructure exercise brought interagency partners together to examine a scenario involving simultaneous disruptions. One conclusion was clear: The Army cannot solve the problem alone.

The Department of Homeland Security, FBI, Department of Energy and other organizations have authorities, capabilities and resources that must be coordinated. Agentic tools may increase the speed of defense, but collaboration remains essential to protecting the infrastructure that supports military operations.

Key Takeaways

  • The Army is initially focusing its agentic cyber effort on incident response, autonomous deception and purple-team assessments.
  • Moving at mission speed requires coordinated funding, acquisition support, operational pilots and policies governing human oversight.
  • The strong response from industry demonstrates broad interest in helping the Army develop autonomous cyber defenses.