Powered by Policy

How the Current Policy Landscape Promotes Partnership with Industry for Agentic AI Implementation

By CPT Desmond C. Varner Jr., JD, Esq.

| Gray Space, 2026 E-Edition

Read Time: < 13 mins

A person in military uniform is holding a microphone and speaking in front of a large screen displaying partially visible text related to data-driven decisions and a welcome message.Description generated by AI

Col. Edward Kendall, chief information officer with U.S. Army Europe and Africa, delivers opening remarks during Cyber Summit 25 in Wiesbaden, Germany, July 22, 2025. The three-day summit brought together military leaders, industry experts, and Allied partners to enhance cyber readiness through collaboration, innovation, and shared cybersecurity strategies. (Photo by Samuel Kim)

Introduction

State-sponsored cyber threats increasingly target U.S. private industry, exploiting the vast repositories of personal and commercial data held by consumer-facing businesses. While defense contractors maintain robust cybersecurity due to federal requirements, most private companies lack comparable protections, making them attractive targets for spear phishing, zero-day exploits, supply-chain attacks, ransomware, and disinformation campaigns. As adversaries leverage generative artificial intelligence (GenAI) to enhance the sophistication and scale of these operations, the United States must modernize its approach to public–private cyber collaboration. This commentary argues that existing legal mechanisms—particularly the Cybersecurity Information Sharing Act of 2015 (CISA of 2015)—combined with emerging Agentic Artificial Intelligence (AI) capabilities create a unique opportunity to strengthen national cyber resilience. Agentic AI systems can automate threat detection, accelerate information sharing, and enhance intelligence production across both government and industry. When integrated into federal reporting structures and aligned with recent executive actions prioritizing AI innovation, these systems can meaningfully augment U.S. Cyber Command’s defensive, operational, and offensive missions. This piece offers a practice-oriented reflection on how Agentic AI can serve as a force multiplier for national cyber defense and outlines implications for policymakers, industry leaders, and military cyber practitioners.

Cyberspace is a constantly evolving operational domain that shapes nearly every aspect of modern life. As defined in U.S. doctrine, it is “a global domain within the information environment consisting of the interdependent network of information technology infrastructures and resident data” (Joint Chiefs of Staff Washington United States, 2017). Yet this definition understates the degree to which state-sponsored adversaries exploit vulnerabilities in the private sector, particularly among consumer-facing businesses that lack the cybersecurity rigor of traditional defense contractors.

The threat is amplified by the anonymity afforded by pseudonyms, proxy servers, virtual private networks, and other obfuscation tools (Whitson, 2024). In today’s environment, foreign adversaries increasingly target private companies not for classified information but for the most valuable commodity in cyberspace: personal data.

Drawing on operational experience and current policy developments, this commentary examines how Agentic Artificial Intelligence (AI) can enhance public–private collaboration to counter state-sponsored cyber threats. It argues that the United States already possesses the legal and strategic foundation necessary to integrate Agentic AI into national cyber defense and that doing so is essential to shaping adversary behavior in accordance with the 2026 Presidential Cyber Strategy (The White House, 2026).

The Private Sector as a Target of State-Sponsored Cyber Operations

Defense contractors such as Lockheed Martin and Raytheon appear to be obvious targets for foreign intelligence services. However, these firms benefit from stringent federal cybersecurity requirements including background checks, reporting mandates, and compliance with the Defense Federal Acquisition Regulation Supplement (DFARS) (Defense Federal Acquisition Regulation Supplement, 2025). As a result, adversaries increasingly pivot toward consumer-facing companies that collect, store, and monetize vast amounts of personal data.

“Data” in the cyberspace context can be understood as information—especially facts or numbers—collected to be examined and considered and used to help decision making, or information in an electronic form that can be stored and used by a computer (Cambridge University Press & Assessment, 2026). It has become the cornerstone of modern business models. Every click, purchase, and interaction generates data that is tracked, aggregated, and often sold. These repositories represent a lucrative target for state-sponsored actors seeking intelligence, leverage, or disruption.

Evolving Cyber Threats Against Private Industry

There are a variety of cyberattacks used by these state-sponsored adversaries to specifically target the data of private business. Cyber attacks like spear phishing, zero-day exploits, supply-chain attacks, ransomware, and disinformation operations are just a few examples that have specifically been leveraged against private industries. With the widespread adoption of generative artificial intelligence (GenAI), these threats have not only persisted, but their frequency and effectiveness have increased significantly.

Spear Phishing and Deepfakes

Spear phishing remains one of the most common vectors for initial access. The advancement in GenAI now enables any of its users to craft highly convincing messages, images, audio, and video. The realism of GenAI’s longform writing can be highlighted by an active class-action lawsuit against Grammarly, the language editing software company, by a collection of investigative journalists for its expert review feature that can recreate a user input to reflect the style, tone, and diction of a particularly named journalist (Klee, 2026).

“Deepfakes,” images or recordings created by GenAI that have been convincingly altered and manipulated to misrepresent someone or something, have been used for more elaborate schemes (Merriam-Webster, 2026). In one case, scammers used deepfake video to impersonate a Hong Kong firm’s CFO and fraudulently authorize a $25 million transfer (Chen & Magramo, 2024). This demonstrates how publicly available information—such as LinkedIn profiles or corporate bios—can be weaponized to deceive even experienced professionals.

Zero-Day Exploits and AI Jailbreaking

Zero-day vulnerabilities allow adversaries to exploit software flaws unknown to vendors. These vulnerabilities are often latent and quickly circulate once the exposed vulnerability becomes public knowledge to its users. Cybersecurity professionals are then racing to patch vulnerability and provide system updates to mitigate any lingering effects from that attack. State-backed groups often have the resources to discover and use zero-day vulnerabilities. North Korean actors used such an exploit against Google Chrome in 2022, affecting 3.5 million users (Winder, 2026). Similar vulnerabilities exist in commercial AI chatbots, where “jailbreaking” can bypass safety controls using plain language prompts (O’Regan, 2025).

Supply-Chain Attacks

Supply-chain attacks are a cyber tactic where attackers compromise a trusted third-party vendor or software to gain access to a wide range of targets. These hackers inject malicious code into unsecure digital infrastructure of smaller businesses, typically some type of subcontractor, to target a larger business. The 2019 SolarWinds incident remains a defining example of a state-sponsored supply-chain compromise. Russian-backed hackers inserted malicious code into Orion software updates, enabling widespread infiltration across government and industry (Fortinet, 2026).

A person aiming a rifle in an urban environment with augmented reality overlays showing distances, targets, and tactical information on buildings and people.Description generated by AI

Though the Army has fought in urban areas before, it’s not just the density of a city that challenges scientists designing the sensor equipment to help Soldiers navigate future operating environments. The electromagnetic spectrum, where communications and navigation information flow, is also more crowded, and jamming, denial, and disinformation campaigns will clog and obscure the battlespace. (U.S. Army graphic by Sonya Beckett, CERDEC NVESD)

Ransomware and Wiper Malware

Ransomware is a type of malicious software that prevents the end user or custodian from accessing their computer files, systems, networks, and/or data in exchange for a ransom payment. Ransomware is no longer limited to criminal groups. During Operation Epic Fury, Handala, an Iranian-sponsored hacker group, targeted and gained access to Stryker’s internal network and deployed a sophisticated form of ransomware called wiper malware, which is designed to permanently delete data from targeted IT systems, rendering critical information unrecoverable. The cyberattack resulted in the erasure of data across internal network devices, operational shutdown of servers and applications, and remote wiping of company-linked mobile devices (Baran, 2026). This is an example that highlights the range and reach of our adversaries’ cyber capabilities to attack American industry.

Disinformation and Influence Operations

Social media platforms enable adversaries to spread propaganda, sow discord, and impersonate real individuals. These open forums have become a free-for-all for disinformation and negative influence by foreign adversaries. These websites allow for bad actors to maintain anonymity by creating fake accounts and online aliases. A deepfake video of Ukrainian President Volodymyr Zelenskyy urging surrender circulated widely in 2022, illustrating the potential for AI-generated disinformation to influence public perception and decision making (Allyn, 2022). Disinformation campaigns not only source large amounts of personal data broadcast on social media but also use that information to create aliases and pose as real individuals.

Framework for Private-Public Partnerships

Collaboration between commercial industry and national-defense agencies must be more than a loose paternal relationship. Securing the cyber domain requires more than regulatory oversight; it demands genuine collaboration between private industry and national-defense agencies. Existing legal mechanisms and emerging AI capabilities, particularly Agentic AI, offer opportunities to strengthen this partnership and better posture U.S. presence in the cyber domain.

Leveraging Legal Mechanisms

The information age requires swift action when dealing with cyber threats. Fortunately, the U.S. has developed a strong legal foundation through reporting mechanisms and legislation to deal with cyberattacks from bad actors. This is seen through federal-agency reporting avenues and laws. Federal agencies maintain distinct reporting structures for cyber incidents. For example:

  • The Department of Health and Human Services Office for Civil Rights enforces HIPAA violations (U.S. Department of Health and Human Services, Office for Civil Rights, 2024).

  • The FBI’s Internet Crime Complaint Center (IC3) aggregates public cybercrime reports (Internet Crime Complaint Center, n.d.).

  • The Cybersecurity and Infrastructure Security Agency, under DHS, leads national cyber-threat response and coordinates the Cyber National Mission Force (Home page, n.d.) which includes the FBI, National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), and United States Cyber Command.

These mechanisms highlight the complexity of the cyber domain and the need for streamlined private-sector engagement. With private business becoming a target, there is an opportunity to create swift and accurate reports and have steady-state monitoring for cyberattacks. These objectives can be furthered through existing legislation like CISA of 2015.

Agentic Artificial Intelligence and CISA of 2015

CISA of 2015 encourages voluntary sharing of cyber-threat indicators between private industry and the federal government. It provides liability protections, FOIA exemptions, antitrust exemptions, and regulatory use limitations (CISA, 2015). The primary goal of the legislation was to break down legal and structural silos that previously prevented pressing and pivotal communications about active cyber-threat warnings between both government and industry.

Agentic AI are autonomous systems capable of perceiving, reasoning, and acting within digital environments, and they can enhance CISA of 2015’s objectives. These systems automate monitoring, detection, and communication across networks, enabling real-time information sharing and threat mitigation (Stackpole, 2026; Son, 2025). Agentic AI has already been utilized for cybersecurity by private banks, like JP Morgan Chase, to monitor and detect financial fraud across their banking network. This technology can counter some of the most common forms of cyber-attacks by:

  • Detecting deepfake solicitations

  • Identifying supply-chain anomalies

  • Neutralizing ransomware indicators

  • Locating and patching zero-day vulnerabilities

  • Communicating findings to human analysts in real time

It can also assist in threat analysis by identifying the type of cyber-attack, archiving the incident for record keeping, and threat monitoring for further refinement of the software.

Bolstering the Intelligence Network

The deployment of Agentic AI in tandem by both private industry and the federal government can bolster the accuracy and precision of the U.S. intelligence network in an expansive and dynamic cyber domain. It is important to know the distinction between information and intelligence. Information is raw, unanalyzed data. Intelligence is created only after that information has been subjected to rigorous analysis and interpretation. Agentic AI’s ability to collect, label, and synthesize large amounts of digital information can only assist in the bolstering of the U.S. intelligence network. This is achieved by identifying the cyber-attacks, seeking the origin, and diagnosing the components. This strengthens U.S. Cyber Command’s operational capabilities.

Supporting Military Cyber Operations

10 U.S.C. § 167b establishes U.S. Cyber Command (USCYBERCOM) and outlines its responsibilities, including combat readiness, cyberspace operations, and strategy development. USCYBERCOM’s core functions include defensive operations, network monitoring and maintenance, and offensive cyber operations.

Recent executive actions underscore the importance of private-sector collaboration:

  • Executive Order 14265— Modernizing defense acquisitions and emphasizing domestic-IT supply chains. This executive order tasked a major administrative redesign with the overarching goals of streamlining the procurement processes and updating equipment necessary to improve the warfighter, especially when it comes to information technology. Specifically, the implementation of Defense Federal Acquisition Regulation Supplement (DFARS) Part 240, Information Security and Supply Chain Security, emphasizes the importance of utilizing American private industry instead of those by near-peer adversaries like the People’s Republic of China, implicitly pushing the DoW agencies to prioritize partnership with American industry in the information-technology space (The White House, 2025b).

  • Executive Order 14179— Removing barriers to American AI leadership, which is a major attitude shift in policy toward AI. Section 2 of this executive order clearly states that the goal of AI implementation is to promote human flourishing, economic competitiveness, and national security. This shows an intent to maximize U.S. AI capabilities to bolster every tenet of the warfighting functions: Mission Command, Movement and Maneuver, Fires, Intelligence, Sustainment, and Protection (The White House, 2025a).

  • Executive Order 14365— Establishing a national AI-policy framework. It is an attempt to emphasize the previous goals laid out in EO 14179 by consolidating AI governance at the federal level to further promote innovation in the sector. These executive orders show a strategic desire to engage with commercial industry and leverage AI capabilities to bolster the U.S. advantage in the cyber domain (The White House, 2025c).

These directives encourage innovation and public–private cooperation in the cyber domain.

Conclusion

State-sponsored cyber threats increasingly target private businesses, bringing the cyber battlefield to the front doors of everyday Americans. The 2026 Presidential Cyber Strategy emphasizes “shaping adversary behavior” through collective defense. Strengthening public–private partnerships—supported by existing legal frameworks and emerging technologies like Agentic AI—is essential to securing the cyber domain and enhancing national-defense capabilities.

References

10 USC 167b: Unified combatant command for cyber operations. (2018). House.gov. https://uscode.house.gov/view.xhtml?req=10+usc+167b&f=treesort&fq=true&num=1&hl=true&edition=prelim&granuleid=USC-prelim-title10-section167b

Allyn, B. (2022, March 16). Deepfake video of Zelenskyy could be ‘tip of the iceberg’ in info war, experts warn. NPR. https://www.npr.org/2022/03/16/1087062648/deepfake-video-zelenskyy-experts-war-manipulation-ukraine-russia

Baran, G. (2026, March 11). Stryker cyber attack - hackers claim system breach and device wipe. Cyber Security News. https://cybersecuritynews.com/stryker-cyber-attack/

Cambridge University Press & Assessment. (2026). data. Dictionary.cambridge.org. https://dictionary.cambridge.org/dictionary/english/data

Chen, H., & Magrano, K. (2024, February 4). Finance worker pays out $25 million after video call with deepfake ‘chief financial officer.’ CNN. https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk

Cybersecurity & Infrastructure Security Agency [CISA]. (2015). Cybersecurity Information Sharing Act of 2015. Cisa.gov. https://www.cisa.gov/sites/default/files/publications/

Defense Federal Acquisition Regulation Supplement. (2025, November 10). Subpart 204.73: Safeguarding covered defense information and cyber incident reporting. Acquisition.gov. Retrieved May 20, 2026, from https://www.acquisition.gov/dfars/subpart-204.73-safeguarding-covered-defense-information-and-cyber-incident-reporting

Fortinet. (2026). SolarWinds supply chain attack. Fortinet. https://www.fortinet.com/resources/cyberglossary/solarwinds-cyber-attack

Home page. (n.d.). Cisa.gov. https://www.cisa.gov/

Internet Crime Complaint Center. (n.d.). Home page - internet crime complaint center (IC3). Ic3.gov. https://www.ic3.gov/

Joint Chiefs of Staff Washington United States. (2017, February 1). DOD dictionary of military and associated terms. Dtic.Mil. https://apps.dtic.mil/sti/pdfs/ad1029823.pdf

Klee, M. (2026, March 11). Grammarly is facing a class action lawsuit over its AI ‘expert review’ feature. Wired. https://www.wired.com/story/grammarly-is-facing-a-class-action-lawsuit-over-its-ai-expert-review-feature/

Merriam-Webster. (2026). Definition of DEEPFAKE. www.merriam-Webster.com. https://www.merriam-webster.com/dictionary/deepfake

O’Regan, A. (2025, May 14). Why it’s so easy to jailbreak AI chatbots, and how to fix them. Princeton Engineering | Princeton University. https://engineering.princeton.edu/news/2025/05/14/why-its-so-easy-jailbreak-ai-chatbots-and-how-fix-them

Son, H. (2025, September 30). Here’s JPMorgan Chase’s blueprint to become the world’s first fully AI-powered megabank. CNBC. https://www.cnbc.com/2025/09/30/jpmorgan-chase-fully-ai-connected-megabank.html?msockid=0de134e8d1cd6369233c2295d04362cb

Stackpole, B. (2026, February 18). Agentic AI, explained. MIT Sloan; MIT Sloan School of Management. https://mitsloan.mit.edu/ideas-made-to-matter/agentic-ai-explained

The White House. (2025a, January 23). Removing barriers to American leadership in artificial intelligence. The White House. https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/

The White House. (2025b, April 9). Modernizing defense acquisitions and spurring innovation in the defense industrial base. The White House. https://www.whitehouse.gov/presidential-actions/2025/04/modernizing-defense-acquisitions-and-spurring-innovation-in-the-defense-industrial-base/

The White House. (2025c, December 11). Ensuring a national policy framework for artificial intelligence. The White House. https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/

The White House. (2026, March). President Trump’s cyber strategy for America. Whitehouse.gov. https://www.whitehouse.gov/wp-content/uploads/2026/03/president-trumps-cyber-strategy-for-america.pdf

U.S. Department of Health and Human Services, Office for Civil Rights. (2024, December 17). About us. HHS.gov. Retrieved May 20, 2026, from https://www.hhs.gov/ocr/about-us/index.html

Whitson, G. (2024). Cybercrime. EBSCO Research Starters. https://www.ebsco.com/research-starters/computer-science/cybercrime

Winder, D. (2026, March 15). Google zero-day alert for 3.5 billion Chrome users—attacks underway. Forbes. https://www.forbes.com/sites/daveywinder/2026/03/15/google-zero-day-alert-for-35-billion-chrome-users-attacks-underway/

Author

Desmond C. Varner Jr. is a judge advocate currently stationed at the 1st Theater Sustainment Command at Fort Knox, Kentucky. He currently serves as the Trial Counsel and Artificial Intelligence Attorney. He has previously published works in the National Security Law Quarterly about Generative AI’s content creation capabilities. He has been trained on different AI systems such as Maven, Vantage, and Google’s Vertex Suite. CPT Varner attended the inaugural Government Rights and Intellectual Property Course at The Judge Advocate General’s Leadership Center and School. He has also completed Trial Counsel 101, Judge Advocate Officer Basic Course, and Direct Commission Course. He obtained his Juris Doctorate from the University of Kentucky J. David Rosenberg College of Law and his Bachelor of Science in Health Services Administration from Xavier University.