Why It Matters
A recent Congressional Research Service (CRS) report, updated in July, details how agentic artificial intelligence, or systems that accomplish goals with limited human supervision, allow threat actors to perform tasks that normally require teams of sophisticated hackers; this includes analyzing target systems, producing exploitable code, and examining large swaths of stolen data. Both state-sponsored actors and less sophisticated criminal groups could now conduct large-scale attacks using agentic AI. Autonomous agents can execute cyberattack tasks quicker and more efficiently than human operators, and targets of cyber espionage include government entities and corporations.
In mid-September 2025, Anthropic detected a highly sophisticated cyber espionage operation attributed to a Chinese state-sponsored group labeled GTG-1002, marking the first documented case of an AI-orchestrated cyberattack. The GTG-1002 operation automated 80–90 percent of a large-scale cyber espionage campaign targeting approximately 30 organizations worldwide, with human operators involved only in strategic decisions like target selection and data exfiltration approval.
The Big Picture
The Defense Department is already moving to integrate agentic AI into military operations. The AIR program involves creation of advanced modeling and simulation environments to train AI pilots or robotic wingmen to perform complex maneuvers and make autonomous decisions in high-stakes environments. Initiatives, like this, reflect recognition that advanced militaries are exploring potential defense applications for agentic AI, including AI agents performing autonomous decision-making and initiating operations at speeds beyond human capabilities.
Congress has begun establishing guardrails. The fiscal year 2026 National Defense Authorization Act directs the Secretary of Defense to develop counter-artificial intelligence strategies to defend against adversary use of AI. The AI Futures Steering Committee was tasked with formulating proactive AI governance policy, analyzing AGI trajectories including agentic AI, assessing adversary AI development, and developing counter-AI strategies, with a report due to congressional defense committees by Jan. 31, 2027.
Worth Noting
On the defensive side, agentic AI can bolster cybersecurity by providing rapid reactive and adaptive threat detection that traditional, rules-based cybersecurity technology is unable to provide. Machine learning models could train on cybersecurity datasets to anticipate future threats, assess risks, and recommend preventive policies and actions.
Access the Legis1 platform for comprehensive political news, data, and insights.
Spot something wrong? Report an issue with this article