Army Wants AI Cyber Agents to Act at Machine Speed—With an Undo Button

Project Griffin is still a pilot, not a fielded autonomous defense system. Its procurement shows the Army wants faster network action while treating auditability, operator control, agent security and operating costs as core constraints.

By 3 min read
Army Wants AI Cyber Agents to Act at Machine Speed—With an Undo Button
Army Wants AI Cyber Agents to Act at Machine Speed—With an Undo Button

Listen to this story

The audio brief

About 1:31
0:001:31
Read transcript
The Army is soliciting proposals for Project Griffin, a pilot designed to let AI agents turn network alerts into defensive action at machine speed. The system would use an agent ecosystem called IRON—short for Intelligent Response and Orchestration Node—to ingest sensor feeds and route commands through existing tools, including Microsoft Defender. Its initial scope covers seven defensive functions, with examples such as temporarily blocking a firewall connection and patching a vulnerability. The goal is to close the gap between detecting a threat and stopping it, because Army officials say sensors generate more information than human analysts can track and handle at human speed. But Griffin is explicitly an experiment in controllable autonomy, not a fielded system with unlimited authority. Vendors must provide a complete audit trail, distinguish real threats from false positives, and let Army and Pentagon administrators set and adjust confidence thresholds. A master kill switch must stop pending, higher-tier actions, while command reversal must undo actions already issued. The Army also wants low token costs and security for the agents themselves, so the defense system does not create a new attack surface. Solution briefs are due August 27, and phase two could be limited to seven companies. Griffin is one of three efforts following a cyber exercise that identified 17 to 20 capabilities for attention. The immediate constraint is funding: Army Cyber Command says dedicated money is needed beyond its operating budget.

Story brief

3 key points

The U.S. Army is soliciting proposals for Project Griffin, a pilot that would let the IRON agent ecosystem turn sensor alerts into defensive actions through existing tools such as Microsoft Defender. The test is structured around controllable autonomy: vendors must provide audit trails, adjustable confidence thresholds, a master stop function, command reversal, low token costs and agent security. Briefs are due...

  1. 01

    IRON would cover seven defensive functions, including temporary firewall blocks and vulnerability patching.

  2. 02

    Army and Pentagon administrators must control confidence thresholds and halt or reverse autonomous commands.

  3. 03

    The Army says its cyber AI work needs dedicated funding beyond Army Cyber Command’s operating budget.

The Army wants AI agents that can move from network alerts to defensive action faster than human analysts can. But Project Griffin is not a promise of unrestricted autonomy: the pilot pairs machine-speed response with requirements for audit trails, confidence thresholds, a kill switch and a way to reverse commands after they are sent.

A pilot meant to act on what it sees

Project Griffin is a pilot program to develop an ecosystem of AI agents called the Intelligent Response and Orchestration Node, or IRON. The proposed system would ingest network-sensor feeds and automatically execute defensive actions against cyber threats, rather than only passively monitor activity. Its initial actions span seven functions, including temporary firewall blocks and vulnerability patching, through policy-enforcement points such as endpoint-management systems and Microsoft Defender.

The operational aim is to shorten the gap between detection and a defensive command. Army officials say their sensors produce more data than human analysts can readily track and respond to, and that the service now analyzes and responds to threats at human speed. IRON would instead turn detection into a command routed through existing enforcement tools.

The safeguards define the experiment

Autonomy is a design condition, not an unrestricted operating mandate. The solicitation requires IRON to distinguish actual threats from false positives and create a complete automated audit trail for each action. It is expected to use a zero-trust model, which assumes the network is compromised by default, and open API standards.

Army and Pentagon administrators are to be able to set, adjust and audit confidence thresholds that govern response levels. They must also be able to stop pending higher-tier autonomous actions with a master kill switch and undo commands agents have already issued. Those controls leave room for responses alongside a human operator while preserving a route toward more autonomous operation in the future.

The Army is also asking vendors to minimize token costs and secure the agents themselves, so the system does not introduce vulnerable new points of attack. That makes Griffin’s test broader than whether a model can identify suspicious activity: the agents must be affordable to run and must not become targets that expose the network they are meant to defend.

Three paths from a larger cyber exercise

Project Griffin emerged from the Army’s Rapid Defense Cyber Systems initiative, launched after an April tabletop exercise with technology-industry executives. The exercise identified 17 to 20 capabilities or efforts for Army attention; leaders are initially pursuing three lines of effort. Pugh said an earlier exercise brought 15 technology companies to the Pentagon to game out a scenario involving thousands of simultaneous autonomous cyberattacks on the military.

Alongside Griffin, the Army is exploring agentic deception agents and AI-based audits of vendor security posture and its own network. The deception effort’s intended methods have not been detailed. Pugh said the program will seek monthly updates on each line of effort, including roadblocks, with decision-makers gathered to resolve them.

The budget is part of the deployment question

Brandon Pugh, the Army’s principal cyber advisor, said AI will be a budget priority for Army Cyber Command through at least the next fiscal year and likely beyond. He said the work needs dedicated funding because the command cannot pay for it from its operational budget alone; joint military resources could contribute. Whether that funding materializes will help determine how far the pilot can progress beyond its solicitation.

Sources

  1. defensescoop.comArmy wants fast AI cybersecurity agents that won’t run up token costs or create new vulnerabilities
  2. breakingdefense.comArmy cyber defenses need 'dedicated funding' for AI, top official says - Breaking Defense

Loading discussion...