Key Takeaways
- The US Army conducted its second AI-focused tabletop exercise to prepare for adaptive cyber threats in an Indo-Pacific crisis scenario projected for 2027.
- Fourteen leading AI and tech companies (including Google, OpenAI, Microsoft, AWS, and Palo Alto Networks) participated, alongside Army and DoD officials.
- The simulated adversary used AI to launch continuously adapting cyber attacks that learned from Army defenses in real-time, outpacing human reaction speeds.
- The exercise revealed previously unknown vulnerabilities in Army systems and highlighted AI’s potential for deception tactics to waste enemy resources.
- A central debate emerged regarding the appropriate level of autonomy for AI agents in cyber defense, specifically when machines should be allowed to accept risk independently of human oversight.
- Army leadership is moving beyond viewing AI merely as a human augment and is actively exploring how to grant AI meaningful autonomy in cyberspace operations to counter future threats.
Exercise Context and Objectives
The US Army’s principle cyber advisor, Brandon Pugh, described the recent tabletop exercise as focused on preparing for "an Indo-Pacific crisis and a hypothetical September 2027," building upon an inaugural exercise held the previous September. This iteration specifically honed in on AI-enabled cyber defense, moving beyond general AI applications in warfare to address a critical emerging threat: adversaries leveraging artificial intelligence not for a single, decisive cyber blow, but for relentless, adaptive salvo attacks. The core premise was that an enemy AI could continuously learn and evolve its tactics faster than human defenders could manually adjust defenses, creating a dynamic where traditional human-centric cyber responses would be perpetually lagging. Army leaders, including Secretary Dan Driscoll, have consistently emphasized that defending networks, data, and software is now as vital as protecting physical terrain and assets in modern conflict, making this exercise a crucial step in validating defensive strategies against next-generation threats.
Participating Organizations and Structure
Fourteen companies with significant expertise in artificial intelligence and cybersecurity were brought to the table for this exercise, underscoring the Army’s reliance on private-sector innovation for cutting-edge defense capabilities. Participants included C-suite representatives from Google, OpenAI, Microsoft, Amazon Web Services (AWS), Palo Alto Networks, and other major players in the AI and cybersecurity domains. Senior officials from the US Army and the broader Department of Defense were also actively involved, ensuring that the insights generated would directly inform military policy and strategy. The exercise was designed as a collaborative problem-solving forum, moving beyond theoretical discussions to simulate concrete challenges and evaluate potential AI-driven solutions within a realistic, high-stakes geopolitical context framed by the anticipated Indo-Pacific contingency.
The Simulated Adversary AI Threat
The heart of the exercise centered on simulating a sophisticated enemy cyber threat powered by artificial intelligence. Unlike conventional attacks, this adversary AI was programmed to analyze the Army’s defensive posture in real time during the simulation. It meticulously observed what specific actions or network behaviors triggered human intervention, what slowed down response times, and how defenders adapted to initial probes. Crucially, the enemy AI learned from each interaction, continuously refining its attack vectors to exploit newly discovered weaknesses or evade countermeasures. This capability to dynamically adapt during the attack sequence meant the threat could launch wave after wave of cyber offensives, each iteration more effective than the last, creating a pressure scenario where human analysts and defenders would struggle to keep pace with the speed and evolution of the assault—a stark illustration of the "faster than a human adversary" challenge highlighted by Army leadership.
Key Insights: Vulnerabilities and Deception Tactics
Participation in the exercise yielded significant operational insights for the Army. Beyond validating the threat posed by adaptive enemy AI, the simulation actively uncovered previously unknown vulnerabilities within the Army’s own cyber infrastructure and data networks. These were not theoretical weaknesses but specific points of exposure revealed when the adversary AI systematically probed and learned from defensive responses. Concurrently, the exercise generated robust discussions on potential AI-driven countermeasures, with recurring ideas focusing on leveraging AI agents for advanced deception tactics. Concepts included using friendly AI to detect adversary presence within US systems, analyze the enemy’s behavioral patterns and attack methodologies, and then deliberately engage the threat with decoys, false information, or complex obstacles designed to consume the adversary AI’s computational resources and time—effectively turning the enemy’s adaptive strength against it by forcing it down costly, unproductive paths.
The Autonomy Debate: Risk Acceptance and AI Agency
A pivotal and recurring theme throughout the exercise was the fundamental question of autonomy for AI agents in cyber defense operations. General Chris Eubank, head of Army Cyber Command, articulated this dilemma directly: "At what stage are machines, [AI] agents, allowed to accept risk versus a human accepting risk?" This question cuts to the heart of future warfighting doctrine. Participants grappled with determining which specific cybersecurity functions AI could reliably and safely perform independently—such as real-time threat detection, initial containment of low-level intrusions, or automated patching of known vulnerabilities—versus those requiring indispensable human judgment, like authorizing significant network isolations, attributing attacks to specific state actors, or deciding on proportional cyber counter-responses. The exercise forced a confrontation with the reality that in an environment where threats operate at machine speed, insisting on human approval for every defensive action could guarantee defeat, yet granting excessive autonomy risks unintended escalation or catastrophic errors due to AI misinterpretation or brittleness.
Current Policy and Future Direction
Currently, Army leadership maintains a clear policy requiring a "human in the loop" for all AI applications, ranging from administrative tasks like paperwork automation to more technical functions such as coding assistance. This cautious approach reflects valid concerns about AI reliability, bias, and the potential for uncontrolled decision-making in high-stakes scenarios. However, the insights from this tabletop exercise are actively pushing the Army to reevaluate this boundary. General Eubank’s statement—"If we believe the end state is, we’re going to use AI to augment humans, we’re going to be way behind. We have to get to a place where we’re not just augmenting humans. Where does AI have autonomy to do things in the cyberspace defense environment?"—signals a significant strategic shift. The Army now recognizes that merely using AI to speed up human processes will be insufficient against adversaries employing fully autonomous, adaptive AI cyber weapons. Consequently, the service intends to closely examine the appropriate scope and safeguards for granting AI agents greater operational autonomy in cyber defense, balancing the imperative for speed and adaptability against the need for control, accountability, and risk management in the face of evolving machine-speed threats. This exercise marks a critical step in defining that future operating concept.

