AI as the Cyber Defender’s Wingman

By SGT Jermaine S. Sayers

| Gray Space, 2026 E-Edition

Read Time: < 12 mins

A developer wearing Sony headphones works at a dark desk with multiple monitors displaying code.

This article was edited with the assistance of artificial intelligence (AI) tools. Final review and editing were conducted by authorized DoW personnel to ensure accuracy, clarity, and compliance with DoW policies and guidance.

At 0200, an alert is displayed on a Security Operations Center (SOC) dashboard, signifying anomalous outbound network traffic from a mission-critical server. Within moments, supplementary alerts commence, inundating the console. A compromised identity is utilized for authentication across various systems. PowerShell commands are executed across endpoints, resulting in suspicious traffic traversing laterally through the network. While logs and alerts are analyzed and examined, the adversary has already executed multiple phases of the attack. This situation exemplifies the operational dynamics of contemporary cyberspace.

Nation-state and Advanced Persistent Threat (APT) actors are increasingly utilizing artificial intelligence (AI) to automate reconnaissance, expedite exploitation, enhance phishing campaigns, generate malicious code, and scale operations against multiple targets concurrently (Palo Alto Networks Unit 42, 2026). The velocity of contemporary cyber warfare has transitioned from hours to minutes, and in certain instances, seconds.

Defenders can no longer depend exclusively on manual analysis and conventional workflows to combat machine-speed assaults (Palo Alto Networks Unit 42, 2026).

The solution, however, does not involve substituting cyber professionals with AI. Human discernment remains essential in military operations. The U.S. Army Cyber Command (ARCYBER) should utilize AI as a reliable partner—an astute collaborator that enhances defenders by alleviating cognitive load, expediting analysis, and facilitating swifter operational decisions. Like how mission command enables subordinate leaders to make prompt decisions aligned with the commander’s intent, AI should facilitate cyber defenders in making informed decisions more rapidly while maintaining human oversight over crucial actions (Anastasiades et al., 2026). The future of ARCYBER superiority will not rely on AI supplanting analysts. The outcome will hinge on the efficacy of the collaboration between AI and human expertise.

The Speed of the Modern Cyber Battlefield

Throughout military history, technological advancements have consistently reduced the time available for commanders to observe, decide, and act. Precision-guided munitions reduced targeting durations. Satellite communications expedited command and control. Autonomous systems are consistently enhancing operational tempo in all warfighting domains. Cyberspace adheres to a similar pattern. In contrast to conventional battlefields where distance imposes physical constraints, cyber operations transpire at machine speed. Upon gaining initial access, attackers utilize automated tools to swiftly conduct reconnaissance, identify susceptible systems, extract credentials, establish persistence, and navigate laterally within the network. Numerous activities transpire concurrently with minimal or no direct human involvement.

Artificial intelligence has enhanced the capabilities of threat actors by streamlining every stage of the attack lifecycle. Artificial intelligence facilitates expedited vulnerability research, enhances malware development, optimizes social-engineering campaigns, and bolsters automated exploitation on an unparalleled scale (Palo Alto Networks Unit 42, 2026). Attackers promptly examine newly-revealed vulnerabilities within 15 minutes of public announcement. Moreover, AI-enhanced assaults diminish the simulated time to exfiltration to roughly 25 minutes. Empirical studies indicate that the swiftest 25% of intrusions achieve data exfiltration in roughly 1.2 hours, which quadruples the speed of earlier reporting intervals (Palo Alto Networks Unit 42, 2026).

This acceleration fundamentally alters defensive cyber operations. Historically, analysts were able to manually examine alerts, correlate logs, and formulate response strategies while preserving operational efficiency. The current threat landscape no longer permits such indulgence. Each minute dedicated to examining false positives or manually querying various security platforms grants adversaries further chances to maintain persistence, elevate privileges, or infiltrate essential systems. Even though the theater of war has transformed, numerous defensive workflows have not been implemented.

Human Latency: The Defender’s Greatest Limitation

The primary challenge confronting defensive cyber operations is not inadequate technology but rather human latency. Human analysts exhibit remarkable intuition, extensive experience, and sound operational judgment. They identify patterns, comprehend mission priorities, and evaluate operational risk in ways that AI cannot emulate. Nevertheless, humans are still limited by biological factors. A cyber analyst is unable to manually assess thousands of alerts each hour. A defender cannot simultaneously correlate telemetry generated from cloud infrastructure, endpoint detection systems, network sensors, identity providers, and threat-intelligence feeds. Similarly, an incident responder cannot manually generate scripts, analyze malware behavior, correlate adversary techniques with the MITRE ATT&CK framework, compose reports, and liaise with leadership as swiftly as attackers execute automated attack sequences.

The difficulty intensifies as enterprise networks persist in their expansion. The primary reasons organizations are swiftly incorporating AI into cybersecurity operations include the escalating complexity of attack surfaces, alert fatigue, staffing shortages, and operational burdens. Attackers need to exploit only one successful attack vector, whereas defenders must safeguard every conceivable vulnerability. Artificial intelligence presents an opportunity to rectify this by enhancing human defenders instead of seeking to supplant them (Anastasiades et al., 2026).

Alert fatigue exacerbates the issue. Security teams often waste precious time examining innocuous events while authentic threats are obscured within vast amounts of telemetry. Artificial intelligence markedly diminishes monotonous analytical tasks by sifting through alerts, ranking incidents according to risk, and automating standard investigative procedures. This essential filtering enables analysts to concentrate on operational decisions rather than expending hours on administrative tasks (Fortinet, 2026). Human latency thus signifies more than a mere inconvenience; it has evolved into an operational vulnerability.

The AI Wingman

Military aviation provides a pertinent analogy for comprehending AI’s appropriate function in cyber defense. A wingman does not supplant the flight lead. The wingman enhances situational awareness, recognizes threats, and offers reciprocal support. Crucially, the wingman facilitates the formation’s ability to execute the mission more efficiently than either pilot could independently. Artificial intelligence ought to fulfill a comparable function in ARCYBER operations. Instead of acting as an independent decision-maker, AI should serve as a collaborative partner that consistently assists analysts during defensive cyberspace operations.

An effectively integrated AI wingman revolutionizes analytical workflows through the implementation of machine-speed preparation. Rather than compelling analysts to extract raw data through manual queries, the AI provides synthesized, pertinent information instantaneously, saving precious minutes otherwise spent composing redundant scripts. This way, analysts can promptly assess succinctly summarized findings and context. Instead of manually correlating numerous isolated alerts, defenders observe a cohesive, synthesized operational overview.

The outcome is not automation for its own merit; it is a strategic advantage in decision making. In contrast to conventional automation, the AI wingman is designed to function as an adaptive collaborator, capable of reasoning across diverse information sources instead of merely following fixed, predetermined scripts. Emerging agentic-AI architectures exhibit this capability by utilizing specialized AI agents that execute specific functions—such as log analysis, threat hunting, intelligence correlation, and report generation—while remaining under human oversight (Anastasiades et al., 2026). Such capabilities enable defenders to focus on operational analysis rather than monotonous technical tasks. This transition signifies the genuine worth of AI: enhancing human efficiency rather than supplanting individuals.

Decision Advantage Through Human-Machine Teaming

The objective of an AI wingman is not to exclude the analyst from the decision-making process. Instead, the objective is to eradicate the latency between threat detection and informed decision making. Military commanders have historically recognized that operational success is achieved by the force that can observe, orient, decide, and act more swiftly than its opponent. This principle is equally applicable in cyberspace. Each minute dedicated to the manual investigation of alerts constitutes an opportunity for an adversary to enhance persistence, infiltrate additional systems, or exfiltrate confidential information.

Artificial intelligence allows cyber defenders to expedite this decision-making process. Instead of examining thousands of alerts individually, AI can swiftly discern patterns across network telemetry, endpoint data, identity logs, cloud infrastructure, and threat-intelligence feeds. By providing analysts with prioritized incidents instead of unprocessed data, AI enables defenders to focus on operational decision making instead of engaging in monotonous administrative duties.

A vital distinction exists that automation executes predetermined tasks, whereas AI offers comprehension. An automated security platform may quarantine a workstation upon detecting malware. An AI wingman can elucidate the reasons for the activity’s suspicious nature, identify associated systems impacted by the same indicators of compromise, recommend containment measures, summarize established adversary techniques, and produce an initial incident report prior to the analyst commencing a thorough investigation. The enhancement of human expertise rather than independent decision making constitutes the primary benefit that AI offers to contemporary cybersecurity organizations that effectively incorporate AI into cyber operations consistently to observe enhancements in detection, incident response, and overall operational efficiency, all while ensuring human oversight during the decision-making process (World Economic Forum, 2026). Industry reports indicate that organizations that extensively implement AI decrease average breach costs by about $1.9 million and reduce breach lifecycles by nearly 80 days, showcasing tangible operational enhancements other than merely theoretical advantages (World Economic Forum, 2026). The benefit offered by AI is not solely computational power; it is operational tempo.

Human Judgment Remains Decisive

Notwithstanding swift progress in AI, no model embodies the commander’s intent. Artificial intelligence can detect anomalies, discern behavioral patterns, and propose defensive measures. It cannot entirely comprehend mission priorities, operational risks, political factors, or secondary consequences associated with military decision-making (Anastasiades et al., 2026).

Evaluate an AI system’s recommendation for the prompt isolation of a compromised subnet that supports a deployed brigade headquarters. From a technical perspective, severing the network inhibits further lateral movement. Implementing this recommendation mechanically, however, may impede mission command, disrupt fire synchronization, diminish intelligence sharing, and significantly impair overall combat effectiveness. Only human leaders possess the operational acumen required to assess these conflicting tactical priorities. Therefore, ARCYBER should adopt a rigorous human-in-the-loop framework for the utilization of AI. Routine, low-risk tasks such as log aggregation, malware classification, phishing analysis, script generation, or alert prioritization can be executed automatically with suitable system supervision. Conversely, actions with operational or strategic implications—such as enterprise-routing modifications, mission-critical network isolation, or defensive measures impacting operational forces—must invariably necessitate explicit human authorization (Anastasiades et al., 2026).

This equilibrium maintains the advantages of both collaborators, guaranteeing that AI enhances efficiency while humans provide discernment. Organizations must mitigate excessive dependence on AI by prioritizing governance, human oversight, and robust processes that remain operational in the event of AI-system unavailability. Effective cybersecurity necessitates not only the deployment of AI but also its responsible integration into current command structures and operational workflows (Anastasiades et al., 2026). The aim is not autonomous defense but rather augmented defense.

Recommendations for ARCYBER

ARCYBER should initiate the integration of AI into defensive cyberspace operations through a methodical and gradual approach rather than a complete overhaul of current processes. Organizations should first identify repetitive analytical tasks that are amenable to enhance AI. These encompass alert triage, log correlation, vulnerability summarization, report generation, malware classification, and intelligence synthesis. Automating these tasks promptly alleviates analyst burden while maintaining human supervision (Anastasiades et al., 2026).

Secondly, leaders must implement governance frameworks that delineate the suitable degree of AI autonomy. Each organization must ascertain at all times the actions that AI may suggest, those it may autonomously execute, and those that necessitate human approval. Effective governance mitigates superfluous operational risk while preserving confidence in AI-facilitated decision making (Anastasiades et al., 2026). Third, AI literacy ought to be integrated into the professional military education of ARCYBER personnel. Future analysts will need skills beyond mere technical expertise. They must comprehend the mechanisms by which AI models produce recommendations, acknowledge their limitations, assess confidence levels, and detect potential biases or hallucinations. Artificial intelligence ought to be regarded as an additional professional instrument, akin to network analyzers, intrusion detection systems, or forensic platforms (PricewaterhouseCoopers, 2026; Anastasiades et al., 2026).

The ARCYBER should consistently integrate AI-enabled systems into cyber exercises and training activities. Soldiers must acquire experience utilizing AI in operational settings prior to depending on these capabilities in real-world situations. Training must encompass compromised scenarios in which AI recommendations are deliberately erroneous or inaccessible, thereby emphasizing the significance of autonomous human judgment (Anastasiades et al., 2026).

Ultimately, commanders ought to assess AI based on operational results rather than technological innovation. The efficacy of an AI wingman should not be gauged by the quantity of alerts handled or reports produced. It ought to be evaluated based on the promptness of cyber teams in threat detection, the expediency of decision making, the diminishment of adversary maneuverability, and the enhancement of mission assurance. Technology itself does not generate operational superiority. Leaders do.

Operational Framework and Division of Labor

The operational workflow progresses directly from the edge to leadership, transitioning from network telemetry, through processing by the AI wingman, to evaluation by the human cyber analyst, culminating with the commander, and ultimately concluding in decisive defensive action.

The technical division of labor is distinctly defined within this architecture. The AI wingman manages data-intensive computational tasks such as alert prioritization, lateral threat correlation, mapping observed behavior to the MITRE ATT&CK framework, real-time script generation, threat-intelligence summarization, and initial-incident report drafting (Anastasiades et al., 2026).

Human operators maintain sole control over cognitive and authoritative duties. This entails exercising operational judgment, conducting thorough risk assessments, evaluating mission prioritization, ensuring compliance with the rules of engagement (ROE), and granting final tactical authorization for significant network actions (Anastasiades et al., 2026).

[Network Telemetry] » [AI Wingman] » [Human Cyber Analyst] » [Commander] » [Defensive Action]

Conclusion

Cyberspace has transformed into a battleground quantified in milliseconds rather than minutes. Artificial intelligence has fundamentally transformed the nature of cyber conflict. Malicious actors are progressively utilizing AI to automate reconnaissance, expedite exploitation, enhance social engineering, and conduct attacks at machine speed (Palo Alto Networks Unit 42, 2026). Defenders cannot effectively counter these capabilities with workflows intended for a slower operational environment. The ARCYBER Command confronts a pivotal decision. It may persist in requiring analysts to manually process escalating volumes of information, thereby acknowledging that human latency will increasingly provide advantage to the adversary. Alternatively, it can adopt AI as a reliable ally that eliminates repetitive tasks, enhances analysis, and reinstates decision-making superiority while maintaining human control over operational decisions (Anastasiades et al., 2026).

The future of defensive cyberspace operations will not be dictated solely by AI, nor will it be ascertained by human expertise functioning independently of technological support. Success will be attained by organizations that effectively integrate machine-speed execution with human discernment. Artificial intelligence must not supplant the cyber defender; it should guarantee that the cyber defender is never engaged in combat independently.

References

Fortinet. (2026). How artificial intelligence (AI) can help in Discovering unknown cybersecurity threats. InFortinet. Fortinet. https://www.fortinet.com/resources/cyberglossary/artificial-intelligence-in-cybersecurity

Palo Alto Networks Unit 42. (2026, February). 2026 Unit 42 global incident response report. Palo Alto Networks Unit 42. https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report?utm_source=google-jg-amer-unit42-unrc-unpt&utm_medium=paid_search&utm_campaign=google-unit42-unit42_port-amer-multi-lead_gen-en-brand&utm_content=701ki000000h65biaq&utm_term=palo%20alto%20threat%20intelligence&cq_plac=&cq_net=g&gclsrc=aw.ds&&utm_campaign=google-unit42-unit42_port-amer-multi-lead_gen-en-brand&utm_term=palo%20alto%20threat%20intelligence&utm_source=google-display&utm_medium=display&hsa_kw=palo%20alto%20threat%20intelligence&hsa_grp=170861209909&hsa_ver=3&hsa_net=adwords&hsa_mt=b&hsa_src=g&hsa_cam=20369915902&hsa_acc=6389245886&hsa_ad=723303665743&hsa_tgt=kwd-355280616147&gad_source=1&gad_campaignid=20369915902&gbraid=0aaaaadhvekk9yxzg6aiv3dbawtgk3-8bj&gclid=cjwkcajw1ihtbhaaeiwa4aynfibe-qgqavcqezozimawdd85yu1e86rqemzph6tz2865qikn6phy4hoc7u4qavd_bwepricewaterhousecoopers. (2026). AI jobs barometer | PwC. PwC. https://www.pwc.com/gx/en/services/ai/ai-jobs-barometer.html#title

Anastasiades, C., Barbeschi, C., Bossardt, M., Gheri, L., Joshi, A., Perućica, N., & Tuteja, A. (2026, May). Empowering defenders: AI for Cybersecurity. World Economic Forum. https://reports.weforum.org/docs/wef_empowering_defenders_ai_for_cybersecurity_2026.pdf

World Economic Forum. (2026). New report shows how AI gives cybersecurity competitive advantage. In World Economic Forum. World Economic Forum. https://www.weforum.org/press/2026/05/new-report-shows-how-ai-gives-cybersecurity-competitive-advantage/