Cyber defence in the age of agentic AI requires a combined arms approach

Created by: Keith Tarrier Grunge style image of modern helicopters in battle.

Grunge style image of modern helicopters in battle. Created by: Keith Tarrier

 

 

31 July 2026

Emerging debates on cyber defence – civilian or military – amidst the proliferation of agentic AI risk falling into an ‘AI-first trap’: the tendency to treat AI-enabled cybersecurity tools as decisive enablers. Although AI is valuable in cyber defence, the trend risks promoting an AI-enabled offence-defence race, a logic that often results in complicated accuracy-robustness tradeoffs and may further deepen the offence’s systemic advantage.

For cyber defence to succeed in the age of agentic AI, defenders must adopt a different doctrinal ethos: one that treats AI capabilities as contributing arms to a ‘cyber combined arms’ doctrine, integrating technical, operational, and institutional defences to generate effects that no individual arm could achieve.

The performance attraction 

The AI-first trap is mostly triggered by the performance attraction of autonomous AI conducting cyber tasks at a speed and scale that traditionally disadvantaged defenders. Prior to the release of frontier capabilities such as Mythos Preview, adversaries were already using AI tools such as Claude Code to carry out real-world cyberattacks. The arrival of Mythos Preview and GPT-5.5 has heightened this performance signal further – these agents are now capable of analysing vulnerabilities and crafting full exploits that achieve unauthorised code execution even against standard security defences.

Consequently, practitioners and security researchers have been exploring opportunities to shift the offence-defence balance towards defenders. For example, a Pentagon competition resulted in the development of cyber reasoning systems that discovered 86% of synthetic vulnerabilities across complex C and Java codebases and successfully patched 68% of them autonomously. These results, while experimental, demonstrate that autonomous AI-enabled cyber defence is no longer hypothetical. Emerging research even suggests that AI may already confer structural advantages to the defence. 

Cyber defence researchers and practitioners have also advocated for a new craft of deception, shifting away from static honeypots to AI-enabled adaptive deception. These defensive innovations are not misplaced, but they are insufficient to shift the offence-defence gap in favour of defenders. 

Treating AI tools as defensive strategies in themselves means becoming vulnerable to the innovation-countermeasure cycle where every advance in AI-enabled defence invites offensive adaptation. To avoid this spiral, defenders must integrate distinct defensive capabilities whose strengths compensate for one another’s vulnerabilities. 

The combined arms approach 

‘Combined arms’ is a tactical innovation that moves from simple arms coordination to arms cooperation and combination, maximising combat effects. In combat, infantry, for instance, offers accuracy and high sensory awareness, but its armour and firepower are limited compared to artillery, and its mobility is limited compared to tanks. But together, the strengths of some cover the weaknesses of others in a synergistic interaction. While cyberspace is not a garrison domain in the conventional sense, cyber defence can learn from the core tenets of the combined arms theory. 

Although cybersecurity has traditionally embraced concepts such as ‘people, process, technology’, or ‘holistic/sociotechnical cybersecurity’, these models tend to treat technology as the primary defensive asset, with people and processes called in to ensure oversight and create a conducive environment for technological solutions. 

This is fundamentally different from the core idea of cyber combined arms. Cyber combined arms reconceptualises cybersecurity from a static tech shield where non-technical elements act as passive enablers into an active manoeuvre ecosystem. Through the coordinated integration and employment of complementary defensive layers, the combined arms approach synchronises every layer of defence – technical, operational, and institutional – to maximise systemic defensive effects.

The technical defence layer contributes scale, persistence, and immediate defensive action across complex digital environments. This is achieved by combining defensive architectures such as zero-trust design, network segmentation, and adaptive deception with enabling technologies. As such, the technical arm can provide network cover and concealment and a terrain shaping effect. 

But technical defences alone, such as AI-enabled solutions, are vulnerable to persistent engagements, such as agents that learn to evade the very signatures and behavioural baselines on which technical defences depend.

The operational arm refers to the coordination of independent actors, converting dispersed defensive architecture into a collective defence network. At its core is the coordination of defence activities such as cyber threat intelligence sharing, capability transfer, and coordinated response operations. While it cannot provide perimeter defence on its own,  it enables  a proactive, intelligence-driven, and collective cyber defence ecosystem. 

Anthropic’s Project Glasswing provides a recent example of this operational approach, although the current design is not without limitation. By putting frontier capabilities into the hands of a limited group of defenders, it risks creating cyber infrastructure chokepoints, excluding some organisations, while others struggle to turn access into defensive capability. Because evolving AI threats are organisation and geography agnostic, effective defence requires operational coordination as a systemic intervention.

The institutional arm refers to the top-down governance structures, rules, and coordination mechanisms that sustain cybersecurity over time and diffuse defensive innovations across organisations and jurisdictions. Such measures are particularly important because cybersecurity is characterised by collective-action and market-failure problems. Among its effects, institutional defence can restrict adversaries’ access to advanced capability through mechanisms such as export controls. 

However, such measures are not without tradeoffs. The US government’s recent directive restricting foreign national access to Anthropic’s Fable 5 model illustrates this tension well. While such restrictions may raise the cost of acquisition for malicious actors, they can also reduce the defensive capacity of friendly networks outside the United States and incentivise the development of alternative AI ecosystems beyond the reach of US influence. Institutional intervention is, therefore, most effective when it aligns private incentives with collective security objectives.

What this means for defenders

Because AI and cybersecurity are characterised by a tight feedback loop, the AI offence-defence debate in cybersecurity will continue, and the trajectory of agentic AI will keep shifting its terms. Whereas the traditional ‘people, process, technology’ and ‘whole-of-organisation’ approaches to cybersecurity advocate for improving technical defences by establishing human-in-the-loop and creating an enabling policy and regulatory environment for technologies to bolster cyber defence, the cyber combined arms doctrine calls for a paradigm shift from defensive coordination to cooperation and combination. 

In cyber combined arms doctrine, distinct defensive capabilities are employed together to compensate for one another’s vulnerabilities and generate effects greater than the sum of their individual contributions. Technical defence may strengthen a local perimeter, but it cannot provide theatre-wide protection on its own. That wider effect depends on institutional defence, like restricting frontier AI access to known adversaries. In turn, institutional defence can only target restrictions accurately when operational defence supplies the system-wide intelligence needed to identify adversaries.  Rather than relying on increasingly capable AI models and agents for a defensive advantage, effective cyber defence requires the deliberate integration of complementary functions that collectively generate system-wide effects.