14 September 2026

Decades of delayed maintenance has left Pentagon networks in ‘potential peril’ for the AI age, cyber defense commander says: ‘no more.’

DefenseScoop | DREW F. LAWRENCE

Lt. Gen. Paul Stanton, commander of the Pentagon’s cyber defense command, warned at the Billington CyberSecurity Summit that decades of delayed maintenance have left military networks highly vulnerable to machine-speed, agentic AI attacks. These automated threats can chain minor vulnerabilities together to achieve devastating effects, multiplying zero-day exploits by a factor of ten.

Historically, the Department of Defense has failed to treat its data and networks as active weapon systems, frequently postponing critical software patches and system upgrades over the past three decades. Such neglect creates severe operational risks. To counter this, the Army is developing agents for the DOD’s information network and has recently asked industry to build rapid defensive capabilities under Project Griffin. While automation is necessary, human operators must thoroughly understand these autonomous tools before deployment, using digital twins to forecast third-order impacts and prevent accidental communications disruptions for forward-deployed troops.

Comment

The transition from static network defence to active, machine-speed manoeuvring represents a fundamental shift in Pentagon cyber doctrine. By framing digital infrastructure as an active weapon system rather than administrative utility, the Defense Information Systems Agency is aligning cyber operations with traditional combat arms principles. This doctrinal evolution demands continuous, automated patching cycles that mirror physical maintenance regimes for armoured vehicles.

This doctrinal shift introduces severe friction at the tactical edge, where autonomous agents operating under Project Griffin could inadvertently disrupt critical communications. If automated defensive actions sever software-defined radio links during active combat, tactical commanders face unprecedented command-and-control vulnerabilities. Rigorous validation of Project Griffin's autonomous agents on DISA cyber ranges remains essential to prevent catastrophic self-inflicted outages for forward-deployed infantry units.

Strategic Question for Discussion
If Project Griffin successfully deploys autonomous defensive agents across military networks, how can tactical commanders maintain positive control over automated configuration changes that risk severing critical frontline communications?
The current trajectory indicates that resolving this tension requires implementing strict policy-based guardrails within the autonomous agents' decision-making engines. My assessment is that DISA will likely employ digital twins to simulate agent behaviour in real-time, allowing commanders to pre-approve operational parameters before deployment. This approach balances machine-speed defence with the absolute necessity of maintaining uninterrupted tactical communications.
Share your assessment in the comments below.