WASHINGTON, D.C. — Lt. Gen. Paul Stanton stated that AI-enabled cyber agents pose an unacceptable risk to military networks and declared a new era of cyber readiness for the Pentagon during remarks at the Billington CyberSecurity Summit. The commander of the Pentagon’s cyber defense command and director of the Defense Information Systems Agency stated that static defenses will not work in an era of AI-enabled cyberspace warfare.
Stanton spoke at the annual summit in Washington, D.C. where he outlined the complexities adversaries face when employing cyber agents. He said the ways in which an adversary could employ cyber agents is mind-boggling in terms of the complexity. He noted that the number of zero-day vulnerabilities has increased by a factor of ten.
The general argued that the military has historically failed to treat its digital infrastructure with the same rigor as kinetic weapon systems. He stated, “But for some reason, over the past three decades, we have not treated our network and our data in the context of a weapon system, and we have postponed and deferred the sustainment and maintenance of our systems to our potential peril.” He added, “No more.”
Stanton said the military used to focus on critical vulnerabilities and critical networks. He added, “But now, with the advent of AI, you can take relatively seemingly benign capabilities and combine them in ways that are unpredictable.”
He asked, “Do you know what the agent’s doing? Can you code? Do you understand the agent?” He continued, “And if you don’t know what the agent’s doing, you’re not understanding the risk.”
Stanton described a scenario involving an infantryman with a software-defined radio in contact with command. He said, “There’s an infantryman with a software-defined radio in contact, and the AI agent decides to update the firmware.”
He emphasized the need for updated training and qualification. “We’ve got to build the qualification concept such that as you rise in rank, you’re also rising in your understanding of the systems that you’re commanding,” he said.
Kirsten Davies, the Department of Defense Chief Information Officer, spoke at the summit regarding the integration of technology and workforce development. Davies said the department must shift its resource allocation to leverage automation. She stated, “We can't continue to throw people at the cyber problem; we have to throw technology at the cyber problem.”
She asked, “As we embrace AI and leverage massive, massive quantities of agentic AI, how do we do that in a way that's supportive of our workforce and provides innovation across that?”
William Wilburn spoke at the Billington Cybersecurity Summit. He said, “We often hear about offense versus defense … but defense in itself is not the outcome; it’s not the goal. It is to allow us to go on offense with something big, something muscular, and something that will drive the outcomes. Our strategy attempts to do that.”
Wilburn said, “The takeaway is, it’s about driving big outcomes and giving the secretary and the president options, more options.” He added, “What we’re trying to do is drive those outcomes in a way that we haven’t seen done before.” He stated, “The outcomes that we want to achieve [are] very clear. We want to ensure the US is safe, the homeland is safe, that adversaries aren’t able to challenge us, and if so, we’re able to deliver the outcomes that again the department and the nation need.”
The Department of Defense has taken several administrative steps to adjust its cyber posture. The department suspended the second-phase requirements for third-party assessments under the Cybersecurity Maturity Model Certification program. Also, the Department of Defense began accepting applications for a Cyber Registered Apprenticeship Program.
The department received more than 15,000 applications for the program and closed the first listing four days early. Internal reviews identified policies and mandates to cut, equating to more than 60% of relevant guidance. Additionally, the department tested a platform that shortened the capability approval timeline from six to 18 months to 17 seconds. The U.S. Army Cyber Command established an artificial intelligence task force to develop agents for the Department of Defense information network. The forthcoming Pentagon cyber strategy will be the first released since the Biden administration’s strategy in 2023, and it follows the national cyber strategy released in March 2026.
Timeline
The Pentagon’s cyber strategy follows the national cyber strategy released in March 2026. In July, the Department of Defense suspended the second-phase requirements for third-party assessments under the Cybersecurity Maturity Model Certification program. Also in July, the Department of Defense began accepting applications for a Cyber Registered Apprenticeship Program.
During his remarks, he said, “We often hear about offense versus defense … but defense in itself is not the outcome; it’s not the goal. Our strategy attempts to do that.” He added, “The takeaway is, it’s about driving big outcomes and giving the secretary and the president options, more options. We want to move away from things that look like persistent engagement. We want to go to higher impact options.” Wilburn further noted, “What we’re trying to do is drive those outcomes in a way that we haven’t seen done before,” and said, “The outcomes that we want to achieve [are] very clear.
What's New
Additional reporting from the summit includes remarks by William Wilburn and Kirsten Davies. Wilburn spoke at the Billington Cybersecurity Summit and said, “We often hear about offense versus defense … but defense in itself is not the outcome; it’s not the goal. Our strategy attempts to do that.” He also said, “The takeaway is, it’s about driving big outcomes and giving the secretary and the president options, more options. We want to go to higher impact options.” Wilburn added, “What we’re trying to do is drive those outcomes in a way that we haven’t seen done before,” and stated, “The outcomes that we want to achieve [are] very clear.
Kirsten Davies spoke at the Billington Cybersecurity Summit in Washington, D.C. The Pentagon’s cyber strategy follows the national cyber strategy released in March 2026. The Pentagon's network and data are directly affected, with the potential risk impacting warfighters and critical military operations.
Why It Matters
The statements by senior defense officials reflect a shift in how the Pentagon views cyber readiness in the age of artificial intelligence. By treating network maintenance and data integrity as critical components of weapon systems, the department aims to mitigate risks that could sever communications with troops in contact. The increase in zero-day vulnerabilities by a factor of ten reflects the urgency of moving beyond static defenses.
The establishment of an artificial intelligence task force by U.S. Army Cyber Command and the high demand for the Cyber Registered Apprenticeship Program indicate a broader institutional effort to integrate advanced technology with skilled personnel. The suspension of certain certification requirements and the reduction of policy guidance suggest an attempt to streamline processes and accelerate capability deployment. These actions align with a strategy focused on delivering high-impact outcomes and providing national leadership with robust options for cyber operations.
forum Comments (0)
No comments yet. Be the first to comment.