About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



1 [1] (February 3, 2026)

handle is hein.crs/govetns0001 and id is 1 raw text is: 











Agentic Artificial Intelligence and Cyberattacks


Introduct Ion
Agentic means autonomous, or independent. Agentic
artificial intelligence (AI) capabilities are of increasing
interest to the U.S. military and to Congress. According to
an IBM  definition, Agentic Al is an artificial intelligence
system that can accomplish a specific goal with limited
supervision. It consists of Al agents-machine learning
models that mimic human decision-making to solve
problems in real time.... Unlike traditional Al models,
which operate within predefined constraints and require
human  intervention, agentic Al exhibits autonomy, goal-
driven behavior and adaptability. For an explanation of
Al- and machine learning-related terms, see CRS
Infographic IG10077, Artificial Intelligence (AI) Taxonomy,
by Laurie Harris and Nora Wells. According to the
Department of Defense (DOD)-which is   using a
secondary Department of War designation under
Executive Order 14347 dated September 5, 2025-
Cybersecurity and Information Systems Information
Analysis Center, there are no known official government
guidance or policies yet specifically on agentic Al.

Agentc   cA and Defense
Advanced  militaries are exploring a number of potential
defense applications for agentic Al. These applications
    might  include Al agents performing autonomous
    decision-making     (independently    analyzing
    intelligence, suggesting tactical and  strategic
    moves, carrying out battlefield tasks, etc.), initiating
    and conducting operations (especially in the digital
    realm)  at a  speed  and  scale beyond  human
    capabilities, and  executing  rapid   Al-agent-
    organized  cyberattacks to include friendly and
    enemy   cyberattacks that target the  Al-agents
    themselves.
Several components of DOD  have been analyzing the
military applications of agentic Al.

Defense  Advanced   Research   Projects Agency
(DARPA)
DARPA   is actively involved in developing and
utilizing agentic Al for a variety of defense applications,
including through its Al Cyber Challenge (AIxCC),
the Artificial Intelligence Reinforcements (AIR) program,
and Thunderforge. These programs endeavor to create
autonomous  systems that can perceive their environment,
make  decisions, and act with minimal human intervention.

DARPA's   AIxCC  competition is focused on developing Al
systems capable of autonomously identifying, exploiting,
and patching software vulnerabilities at machine speed. The
goal of the two-year challenge is to harden critical
infrastructure by enabling proactive, autonomous cyber


Updated February 3, 2026


defense. According to DARPA, the 2024-2025 challenge
successfully demonstrated that Al agents can find and fix
real-world, open-source vulnerabilities faster than human
teams in some cases.

The AIR  program aims to develop dominant Al agents for
live beyond-visual-range (BVR) air combat missions. This
involves creating advanced modeling and simulation
environments to train Al pilots (or robotic wingmen) to
perform complex maneuvers  and make autonomous
decisions in high-stakes environments.

Thunderforge is intended to integrate [Al] into military
operational and theater-level planning, and fusing cutting-
edge modeling and simulation tools. The initiative could
serve as a decision-support tool, synthesizing information
drawn from a variety of sensors and data streams, and
proposing optimal courses of action to military planners.

Defense   nformation  Analysis  Centers  (DODIAC)
Established in 1946, the DODIAC is a research and analysis
organization chartered by DOD. It helps researchers,
engineers, scientists, and program managers use existing
science and technical information (STI) to drive
innovation across DOD with technical analysis and
development of material solutions to advance DOD's
warfighting capabilities.

Specialized centers such as the Defense Systems
Information and Analysis Center (DSIAC) and the
Cybersecurity & Information Systems Information Analysis
Center (CSIAC) collect, analyze, and disseminate STI in
specific technical domains for DOD researchers. DSIAC
has the task of seeking out and collecting STI generated
from research paid for by DOD or the U.S. government and
then uploading it to the Defense Technical Information
Center's Research & Engineering Gateway in order to
increase the body of knowledge available to DOD
researchers and engineers. CSIAC published a study,
Agentic Artificial Intelligence: Strategic Adoption in the
U.S. Department of Defense, in June 2025, that provides an
overview of DOD  agentic Al use cases and cybersecurity
concerns.

   Agentc  Al  and   C  brtak
Some  researchers point to agentic Al as creating new
opportunities for attackers to find and exploit a backdoor,
a hidden entry point into a computer system, network, or
application that bypasses normal security, allowing
unauthorized access for malicious purposes such data theft,
system control, or surveillance. Once inside a network,
attackers can imbed malicious code, create hidden accounts,
or exploit system software vulnerabilities that give