Powered by Policy
How the Current Policy Landscape Promotes Partnership with Industry for Agentic AI Implementation
By CPT Desmond C. Varner Jr., JD, Esq.
| Gray Space, 2026 E-Edition
Read Time: < 13 mins
Col. Edward Kendall, chief information officer with U.S. Army Europe and Africa,
delivers opening remarks during Cyber Summit 25 in Wiesbaden, Germany, July 22, 2025. The
three-day summit brought together military leaders, industry experts, and Allied partners to
enhance cyber readiness through collaboration, innovation, and shared cybersecurity strategies.
(Photo by Samuel Kim)
Introduction
State-sponsored cyber threats increasingly target U.S. private industry, exploiting the vast repositories of
personal and commercial data held by consumer-facing businesses. While defense contractors maintain
robust cybersecurity due to federal requirements, most private companies lack comparable protections,
making them attractive targets for spear phishing, zero-day exploits, supply-chain attacks, ransomware,
and disinformation campaigns. As adversaries leverage generative artificial intelligence (GenAI) to
enhance the sophistication and scale of these operations, the United States must modernize its approach
to public–private cyber collaboration. This commentary argues that existing legal
mechanisms—particularly the Cybersecurity Information Sharing Act of 2015 (CISA of 2015)—combined with
emerging Agentic Artificial Intelligence (AI) capabilities create a unique opportunity to strengthen
national cyber resilience. Agentic AI systems can automate threat detection, accelerate information
sharing, and enhance intelligence production across both government and industry. When integrated into
federal reporting structures and aligned with recent executive actions prioritizing AI innovation, these
systems can meaningfully augment U.S. Cyber Command’s defensive, operational, and offensive missions.
This piece offers a practice-oriented reflection on how Agentic AI can serve as a force multiplier for
national cyber defense and outlines implications for policymakers, industry leaders, and military cyber
practitioners.
Cyberspace is a constantly evolving operational domain that shapes nearly every aspect of modern life. As
defined in U.S. doctrine, it is “a global domain within the information environment consisting of the
interdependent network of information technology infrastructures and resident data” (Joint Chiefs of
Staff Washington United States, 2017). Yet this definition understates the degree to which
state-sponsored adversaries exploit vulnerabilities in the private sector, particularly among
consumer-facing businesses that lack the cybersecurity rigor of traditional defense contractors.
The threat is amplified by the anonymity afforded by pseudonyms, proxy servers, virtual private networks,
and other obfuscation tools (Whitson, 2024). In today’s environment, foreign adversaries increasingly
target private companies not for classified information but for the most valuable commodity in
cyberspace: personal data.
Drawing on operational experience and current policy developments, this commentary examines how Agentic
Artificial Intelligence (AI) can enhance public–private collaboration to counter state-sponsored cyber
threats. It argues that the United States already possesses the legal and strategic foundation necessary
to integrate Agentic AI into national cyber defense and that doing so is essential to shaping adversary
behavior in accordance with the 2026 Presidential Cyber Strategy (The White House, 2026).
The Private Sector as a Target of State-Sponsored Cyber Operations
Defense contractors such as Lockheed Martin and Raytheon appear to be obvious targets for foreign
intelligence services. However, these firms benefit from stringent federal cybersecurity requirements
including background checks, reporting mandates, and compliance with the Defense Federal Acquisition
Regulation Supplement (DFARS) (Defense Federal Acquisition Regulation Supplement, 2025). As a result,
adversaries increasingly pivot toward consumer-facing companies that collect, store, and monetize vast
amounts of personal data.
“Data” in the cyberspace context can be understood as information—especially facts or numbers—collected to
be examined and considered and used to help decision making, or information in an electronic form that
can be stored and used by a computer (Cambridge University Press & Assessment, 2026). It has become
the cornerstone of modern business models. Every click, purchase, and interaction generates data that is
tracked, aggregated, and often sold. These repositories represent a lucrative target for state-sponsored
actors seeking intelligence, leverage, or disruption.
Evolving Cyber Threats Against Private Industry
There are a variety of cyberattacks used by these state-sponsored adversaries to specifically target the
data of private business. Cyber attacks like spear phishing, zero-day exploits, supply-chain attacks,
ransomware, and disinformation operations are just a few examples that have specifically been leveraged
against private industries. With the widespread adoption of generative artificial intelligence (GenAI),
these threats have not only persisted, but their frequency and effectiveness have increased
significantly.
Spear Phishing and Deepfakes
Spear phishing remains one of the most common vectors for initial access. The advancement in GenAI now
enables any of its users to craft highly convincing messages, images, audio, and video. The realism of
GenAI’s longform writing can be highlighted by an active class-action lawsuit against Grammarly, the
language editing software company, by a collection of investigative journalists for its expert review
feature that can recreate a user input to reflect the style, tone, and diction of a particularly named
journalist (Klee, 2026).
“Deepfakes,” images or recordings created by GenAI that have been convincingly altered and manipulated to
misrepresent someone or something, have been used for more elaborate schemes (Merriam-Webster, 2026). In
one case, scammers used deepfake video to impersonate a Hong Kong firm’s CFO and fraudulently authorize
a $25 million transfer (Chen & Magramo, 2024). This demonstrates how publicly available
information—such as LinkedIn profiles or corporate bios—can be weaponized to deceive even experienced
professionals.
Zero-Day Exploits and AI Jailbreaking
Zero-day vulnerabilities allow adversaries to exploit software flaws unknown to vendors. These
vulnerabilities are often latent and quickly circulate once the exposed vulnerability becomes public
knowledge to its users. Cybersecurity professionals are then racing to patch vulnerability and provide
system updates to mitigate any lingering effects from that attack. State-backed groups often have the
resources to discover and use zero-day vulnerabilities. North Korean actors used such an exploit against
Google Chrome in 2022, affecting 3.5 million users (Winder, 2026). Similar vulnerabilities exist in
commercial AI chatbots, where “jailbreaking” can bypass safety controls using plain language prompts
(O’Regan, 2025).
Supply-Chain Attacks
Supply-chain attacks are a cyber tactic where attackers compromise a trusted third-party vendor or software
to gain access to a wide range of targets. These hackers inject malicious code into unsecure digital
infrastructure of smaller businesses, typically some type of subcontractor, to target a larger business.
The 2019 SolarWinds incident remains a defining example of a state-sponsored supply-chain compromise.
Russian-backed hackers inserted malicious code into Orion software updates, enabling widespread
infiltration across government and industry (Fortinet, 2026).
Though the Army has fought in urban areas before, it’s not just the density of a
city that challenges scientists designing the sensor equipment to help Soldiers navigate future
operating environments. The electromagnetic spectrum, where communications and navigation
information flow, is also more crowded, and jamming, denial, and disinformation campaigns will
clog and obscure the battlespace. (U.S. Army graphic by Sonya Beckett, CERDEC NVESD)
Ransomware and Wiper Malware
Ransomware is a type of malicious software that prevents the end user or custodian from accessing their
computer files, systems, networks, and/or data in exchange for a ransom payment. Ransomware is no longer
limited to criminal groups. During Operation Epic Fury, Handala, an Iranian-sponsored hacker group,
targeted and gained access to Stryker’s internal network and deployed a sophisticated form of ransomware
called wiper malware, which is designed to permanently delete data from targeted IT systems, rendering
critical information unrecoverable. The cyberattack resulted in the erasure of data across internal
network devices, operational shutdown of servers and applications, and remote wiping of company-linked
mobile devices (Baran, 2026). This is an example that highlights the range and reach of our adversaries’
cyber capabilities to attack American industry.
Disinformation and Influence Operations
Social media platforms enable adversaries to spread propaganda, sow discord, and impersonate real
individuals. These open forums have become a free-for-all for disinformation and negative influence by
foreign adversaries. These websites allow for bad actors to maintain anonymity by creating fake accounts
and online aliases. A deepfake video of Ukrainian President Volodymyr Zelenskyy urging surrender
circulated widely in 2022, illustrating the potential for AI-generated disinformation to influence
public perception and decision making (Allyn, 2022). Disinformation campaigns not only source large
amounts of personal data broadcast on social media but also use that information to create aliases and
pose as real individuals.
Framework for Private-Public Partnerships
Collaboration between commercial industry and national-defense agencies must be more than a loose paternal
relationship. Securing the cyber domain requires more than regulatory oversight; it demands genuine
collaboration between private industry and national-defense agencies. Existing legal mechanisms and
emerging AI capabilities, particularly Agentic AI, offer opportunities to strengthen this partnership
and better posture U.S. presence in the cyber domain.
Leveraging Legal Mechanisms
The information age requires swift action when dealing with cyber threats. Fortunately, the U.S. has
developed a strong legal foundation through reporting mechanisms and legislation to deal with
cyberattacks from bad actors. This is seen through federal-agency reporting avenues and laws. Federal
agencies maintain distinct reporting structures for cyber incidents. For example:
-
The Department of Health and Human Services Office for Civil Rights enforces HIPAA
violations (U.S. Department of Health and Human Services, Office for Civil Rights,
2024).
-
The FBI’s Internet Crime Complaint Center (IC3) aggregates public cybercrime reports
(Internet Crime Complaint Center, n.d.).
-
The Cybersecurity and Infrastructure Security Agency, under DHS, leads national cyber-threat
response and coordinates the Cyber National Mission Force (Home page, n.d.) which
includes the FBI, National Security Agency (NSA), Environmental Protection Agency (EPA),
Department of Energy (DOE), and United States Cyber Command.
These mechanisms highlight the complexity of the cyber domain and the need for streamlined private-sector
engagement. With private business becoming a target, there is an opportunity to create swift and
accurate reports and have steady-state monitoring for cyberattacks. These objectives can be furthered
through existing legislation like CISA of 2015.
Agentic Artificial Intelligence and CISA of 2015
CISA of 2015 encourages voluntary sharing of cyber-threat indicators between private industry and the
federal government. It provides liability protections, FOIA exemptions, antitrust exemptions, and
regulatory use limitations (CISA, 2015). The primary goal of the legislation was to break down legal and
structural silos that previously prevented pressing and pivotal communications about active cyber-threat
warnings between both government and industry.
Agentic AI are autonomous systems capable of perceiving, reasoning, and acting within digital environments,
and they can enhance CISA of 2015’s objectives. These systems automate monitoring, detection, and
communication across networks, enabling real-time information sharing and threat mitigation (Stackpole,
2026; Son, 2025). Agentic AI has already been utilized for cybersecurity by private banks, like JP
Morgan Chase, to monitor and detect financial fraud across their banking network. This technology can
counter some of the most common forms of cyber-attacks by:
-
Detecting deepfake solicitations
-
Identifying supply-chain anomalies
-
Neutralizing ransomware indicators
-
Locating and patching zero-day vulnerabilities
-
Communicating findings to human analysts in real time
It can also assist in threat analysis by identifying the type of cyber-attack, archiving the incident for
record keeping, and threat monitoring for further refinement of the software.
Bolstering the Intelligence Network
The deployment of Agentic AI in tandem by both private industry and the federal government can bolster the
accuracy and precision of the U.S. intelligence network in an expansive and dynamic cyber domain. It is
important to know the distinction between information and intelligence. Information is raw, unanalyzed
data. Intelligence is created only after that information has been subjected to rigorous analysis and
interpretation. Agentic AI’s ability to collect, label, and synthesize large amounts of digital
information can only assist in the bolstering of the U.S. intelligence network. This is achieved by
identifying the cyber-attacks, seeking the origin, and diagnosing the components. This strengthens U.S.
Cyber Command’s operational capabilities.
Supporting Military Cyber Operations
10 U.S.C. § 167b establishes U.S. Cyber Command (USCYBERCOM) and outlines its responsibilities, including
combat readiness, cyberspace operations, and strategy development. USCYBERCOM’s core functions include
defensive operations, network monitoring and maintenance, and offensive cyber operations.
Recent executive actions underscore the importance of private-sector collaboration:
-
Executive Order 14265— Modernizing defense acquisitions and emphasizing domestic-IT supply
chains. This executive order tasked a major administrative redesign with the overarching
goals of streamlining the procurement processes and updating equipment necessary to
improve the warfighter, especially when it comes to information technology.
Specifically, the implementation of Defense Federal Acquisition Regulation
Supplement (DFARS) Part 240, Information Security and Supply Chain
Security, emphasizes the importance of utilizing American private industry
instead of those by near-peer adversaries like the People’s Republic of China,
implicitly pushing the DoW agencies to prioritize partnership with American industry in
the information-technology space (The White House, 2025b).
-
Executive Order 14179— Removing barriers to American AI leadership, which is a major
attitude shift in policy toward AI. Section 2 of this executive order clearly states
that the goal of AI implementation is to promote human flourishing, economic
competitiveness, and national security. This shows an intent to maximize U.S. AI
capabilities to bolster every tenet of the warfighting functions: Mission Command,
Movement and Maneuver, Fires, Intelligence, Sustainment, and Protection (The White
House, 2025a).
-
Executive Order 14365— Establishing a national AI-policy framework. It is an attempt to
emphasize the previous goals laid out in EO 14179 by consolidating AI governance at the
federal level to further promote innovation in the sector. These executive orders show a
strategic desire to engage with commercial industry and leverage AI capabilities to
bolster the U.S. advantage in the cyber domain (The White House, 2025c).
These directives encourage innovation and public–private cooperation in the cyber domain.
Conclusion
State-sponsored cyber threats increasingly target private businesses, bringing the cyber battlefield to the
front doors of everyday Americans. The 2026 Presidential Cyber Strategy emphasizes “shaping adversary
behavior” through collective defense. Strengthening public–private partnerships—supported by existing
legal frameworks and emerging technologies like Agentic AI—is essential to securing the cyber domain and
enhancing national-defense capabilities.
References
10 USC 167b: Unified combatant command for cyber operations. (2018). House.gov. https://uscode.house.gov/view.xhtml?req=10+usc+167b&f=treesort&fq=true&num=1&hl=true&edition=prelim&granuleid=USC-prelim-title10-section167b
Allyn, B. (2022, March 16). Deepfake video of Zelenskyy could be ‘tip of the iceberg’ in info war,
experts warn. NPR. https://www.npr.org/2022/03/16/1087062648/deepfake-video-zelenskyy-experts-war-manipulation-ukraine-russia
Baran, G. (2026, March 11). Stryker cyber attack - hackers claim system breach and device wipe.
Cyber Security News. https://cybersecuritynews.com/stryker-cyber-attack/
Cambridge University Press & Assessment. (2026). data. Dictionary.cambridge.org. https://dictionary.cambridge.org/dictionary/english/data
Chen, H., & Magrano, K. (2024, February 4). Finance worker pays out $25 million after video call
with deepfake ‘chief financial officer.’ CNN. https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk
Cybersecurity & Infrastructure Security Agency [CISA]. (2015). Cybersecurity Information
Sharing Act of 2015. Cisa.gov. https://www.cisa.gov/sites/default/files/publications/
Defense Federal Acquisition Regulation Supplement. (2025, November 10). Subpart 204.73:
Safeguarding covered defense information and cyber incident reporting.
Acquisition.gov. Retrieved May 20, 2026, from https://www.acquisition.gov/dfars/subpart-204.73-safeguarding-covered-defense-information-and-cyber-incident-reporting
Fortinet. (2026). SolarWinds supply chain attack. Fortinet. https://www.fortinet.com/resources/cyberglossary/solarwinds-cyber-attack
Home page. (n.d.). Cisa.gov. https://www.cisa.gov/
Internet Crime Complaint Center. (n.d.). Home page - internet crime complaint center (IC3).
Ic3.gov. https://www.ic3.gov/
Joint Chiefs of Staff Washington United States. (2017, February 1). DOD dictionary of military
and associated terms. Dtic.Mil. https://apps.dtic.mil/sti/pdfs/ad1029823.pdf
Klee, M. (2026, March 11). Grammarly is facing a class action lawsuit over its AI ‘expert review’
feature. Wired. https://www.wired.com/story/grammarly-is-facing-a-class-action-lawsuit-over-its-ai-expert-review-feature/
Merriam-Webster. (2026). Definition of DEEPFAKE. www.merriam-Webster.com. https://www.merriam-webster.com/dictionary/deepfake
O’Regan, A. (2025, May 14). Why it’s so easy to jailbreak AI chatbots, and how to fix them.
Princeton Engineering | Princeton University. https://engineering.princeton.edu/news/2025/05/14/why-its-so-easy-jailbreak-ai-chatbots-and-how-fix-them
Son, H. (2025, September 30). Here’s JPMorgan Chase’s blueprint to become the world’s first
fully AI-powered megabank. CNBC. https://www.cnbc.com/2025/09/30/jpmorgan-chase-fully-ai-connected-megabank.html?msockid=0de134e8d1cd6369233c2295d04362cb
Stackpole, B. (2026, February 18). Agentic AI, explained. MIT Sloan; MIT Sloan School of
Management. https://mitsloan.mit.edu/ideas-made-to-matter/agentic-ai-explained
The White House. (2025a, January 23). Removing barriers to American leadership in artificial
intelligence. The White House. https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/
The White House. (2025b, April 9). Modernizing defense acquisitions and spurring innovation in
the defense industrial base. The White House. https://www.whitehouse.gov/presidential-actions/2025/04/modernizing-defense-acquisitions-and-spurring-innovation-in-the-defense-industrial-base/
The White House. (2025c, December 11). Ensuring a national policy framework for artificial
intelligence. The White House. https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/
The White House. (2026, March). President Trump’s cyber strategy for America.
Whitehouse.gov. https://www.whitehouse.gov/wp-content/uploads/2026/03/president-trumps-cyber-strategy-for-america.pdf
U.S. Department of Health and Human Services, Office for Civil Rights. (2024, December 17).
About us. HHS.gov. Retrieved May 20, 2026, from https://www.hhs.gov/ocr/about-us/index.html
Whitson, G. (2024). Cybercrime. EBSCO Research Starters. https://www.ebsco.com/research-starters/computer-science/cybercrime
Winder, D. (2026, March 15). Google zero-day alert for 3.5 billion Chrome users—attacks
underway. Forbes. https://www.forbes.com/sites/daveywinder/2026/03/15/google-zero-day-alert-for-35-billion-chrome-users-attacks-underway/
Author
Desmond C. Varner Jr. is a judge advocate currently stationed at the 1st Theater
Sustainment Command at Fort Knox, Kentucky. He currently serves as the Trial Counsel and
Artificial Intelligence Attorney. He has previously published works in the National Security Law
Quarterly about Generative AI’s content creation capabilities. He has been trained on different
AI systems such as Maven, Vantage, and Google’s Vertex Suite. CPT Varner attended the inaugural
Government Rights and Intellectual Property Course at The Judge Advocate General’s Leadership
Center and School. He has also completed Trial Counsel 101, Judge Advocate Officer Basic Course,
and Direct Commission Course. He obtained his Juris Doctorate from the University of Kentucky J.
David Rosenberg College of Law and his Bachelor of Science in Health Services Administration
from Xavier University.