WASHINGTON — In the face of emerging cyber threats posed by artificial intelligence, the Air Force’s cyber organization has developed what it calls a defensive cyber operations “campaign plan” to ensure networks are hardened, its commander said this week.
“At the end of the day, autonomous, agentic AI orchestrated attacks are possible today. So we’ve got to harden our networks. When people say, ‘Hey, we’re at an inflection point,’ we are absolutely at an inflection point,” Lt. Gen. Thomas Hensley, commander of 16th Air Force/Air Forces Cyber, said during a presentation at the annual Department of the Air Force Information Technology and Cyberpower conference in Montgomery, Ala., on Wednesday. “Frontier AI models, they are a concern. We are doing things to secure ourselves against those.”
Hensley said the framework follows the development of an offensive cyber operations campaign plan last year, though he did not describe that plan. For the defensive plan, there are four lines of effort, according to Hensley’s presentation:
First is to “harden [systems and networks and] blunt the attack” of the adversary, which he referred to as the “bread and butter” and “basics of what it is that we do.” That involves persistent monitoring of the network by airmen in security operations centers and network operations centers as well as cyber protection teams responding to incidents. It also means proactively hunting for threats with specialized equipment.
Next is “deliberate defense,” which focuses on and prioritizes key networks to include nuclear command control communication networks, global logistics and critical infrastructure.
Third, Hensley said is “proactive cost imposition.”
“We’re not just going to sit here and let the adversaries attack us without imposing some sort of cost against them,” he said. “What is it that we can do to message them? What is it that we can do to confuse them? What is it that we can do to divert them to cause them to waste their time? What is it that we can do to attack them for attacking us?”
Last is “defensive architecture design.” This is a whole-of-Air Force effort spurred on by the chief information officer to put in place concepts and architectures for better defense all around, such as zero trust, Identity, Credential, and Access Management, multi-factor authentication and microsegmentation, to name a few.
The goal of these efforts is to properly verify users and, even if an adversary gets into the network, to prevent them from getting to where they want to go or accessing the information they seek — even if it’s an AI agent.
“Last year was anybody talking about frontier AI models? Was anybody really talking about this kind of capability? No. Was anybody talking about frontier AI models six months ago? No. So this is a rather recent development and capability,” Hensley said. “These are the first movers, right? So who are the fast followers? They’re the folks that have the second mover advantage because they can glean off of the work that the first movers have done. What more powerful capabilities and tools are they developing to do more and faster?”
