News
US Air Force Builds Defense Plan Against AI-Driven Cyberattacks

The commander of 16th Air Force/Air Forces Cyber has announced a new defensive cyber operations plan responding to the threat of autonomous, agentic AI attacks, which he says are already possible today.
Contents
The commander of US cyber forces has announced a new plan to defend military networks against attacks carried out autonomously by artificial intelligence systems. Lieutenant General Thomas Hensley, head of 16th Air Force and Air Forces Cyber, outlined the plan on Wednesday, August 26, 2026, at the Department of the Air Force Information Technology and Cyberpower conference in Montgomery, Alabama.
Four Pillars of Defense
The new document, referred to by military officials as a campaign plan, divides Air Force cyber defense into four elements. The first is basic network hardening: continuous monitoring by personnel in security operations centers and network operations centers, incident response, and proactive threat hunting by specialized cyber protection teams.
The second pillar, deliberate defense, focuses on prioritizing protection for the most critical networks, including nuclear command and control communications systems, along with critical infrastructure and global logistics. The third element, proactive cost imposition, aims to raise the cost of an adversary's actions rather than simply absorbing attacks. The fourth pillar is defensive architecture design built on zero trust principles, identity and access management, and network microsegmentation.
A Threat That Emerged Within a Year
Hensley stressed that the scale and speed at which the threat emerged surprised even specialists who work in cybersecurity every day. As recently as a year ago, he noted, the topic of AI models capable of independently carrying out attacks barely existed in military discussions.
At the end of the day, autonomous, agentic AI orchestrated attacks are possible today. So we've got to harden our networks - Lt. Gen. Thomas Hensley, commander of 16th Air Force/Air Forces Cyber
Last year was anybody talking about frontier AI models? Was anybody really talking about this kind of capability? No - Lt. Gen. Thomas Hensley, commander of 16th Air Force/Air Forces Cyber
Frontier Models as a New Attack Vector
The general pointed directly to the most advanced language models, referred to in the industry as frontier AI models, as the source of concern. These are systems capable not only of analyzing data but of independently planning and executing multi-step actions on a network without ongoing human oversight, setting them apart from the tools that have previously supported hackers.
Hensley said his unit is already taking concrete steps to guard against this kind of threat, though he did not disclose technical details of the safeguards in use. Earlier reports indicated that Air Forces Cyber had begun the first phase of a network hardening program and plans to roll out a second phase built on AI-automated software.
Geopolitical Context
Behind the strategy lies ongoing rivalry with China, which US military officials say is aggressively developing AI applications in command and control, logistics, cyber operations, and missile guidance. Access by Chinese entities to data on US citizens, including military personnel, is cited as an additional risk that opens new avenues for AI-assisted attacks.
The defensive plan is part of the Department of the Air Force's broader data and AI strategy, announced earlier in 2026, which aims to move the service from isolated pilot projects toward an integrated AI ecosystem prepared for operations in a contested environment.
This has implications beyond the US military itself. NATO and allied cybersecurity services, including Polish institutions responsible for protecting critical infrastructure, are tracking similar threats, and doctrines developed by the largest ally often set the direction later followed in Europe, including in Poland.
Hensley himself acknowledged that the military is at a turning point, comparing the current situation to a moment when existing assumptions about network defense must be reassessed in light of the pace of development of offensive AI-based technologies.


