The Standing Army
Live
Equipamiento

Air Forces Cyber crafts AI defense plan

The Air Force's cyber command has created a four-part defensive plan against AI-powered cyber threats to harden networks and impose costs on adversaries.

The Air Force's cyber command has created a four-part defensive plan against AI-powered cyber threats to harden networks...

The Air Force's cyber organization has developed a defensive cyber operations "campaign plan" to counter emerging threats from artificial intelligence. Lt. Gen. Thomas Hensley, commander of 16th Air Force/Air Forces Cyber, announced the framework this week at a Department of the Air Force IT and Cyberpower conference in Montgomery, Alabama.

Hensley stated that autonomous, agentic AI-orchestrated attacks are now possible, creating an inflection point for cybersecurity. He identified frontier AI models as a specific concern, prompting the need for network hardening. This defensive plan follows the development of an offensive cyber operations campaign plan last year, though details of that offensive plan were not provided.

The Four Lines of Effort

The defensive campaign plan is built around four key lines of effort, as outlined by Hensley in his presentation.

The first is to harden systems and networks to blunt adversary attacks. Hensley called this the "bread and butter" of cyber operations. It involves persistent monitoring by airmen in security and network operations centers, incident response by cyber protection teams, and proactive threat hunting with specialized equipment.

Next is "deliberate defense," which focuses on prioritizing and protecting key networks. These include nuclear command, control, and communication networks, global logistics systems, and critical infrastructure.

The third effort is "proactive cost imposition." Hensley emphasized that the force will not passively accept attacks. The strategy involves messaging, confusing, and diverting adversaries to waste their time, and potentially attacking them in response to their incursions.

Last is "defensive architecture design." This is a service-wide initiative led by the chief information officer to implement modern security concepts. Examples include zero trust architecture, Identity, Credential, and Access Management (ICAM), multi-factor authentication, and network microsegmentation.

Goal and Emerging Threats

The overarching goal is to properly verify all users and contain any adversary that breaches the network. The aim is to prevent access to target information or systems, even if the attack is conducted by an AI agent.

Hensley highlighted the rapid emergence of this threat, noting that frontier AI models were not a topic of discussion just six months ago. He described current developers of such AI as "first movers" and raised questions about the more powerful capabilities "fast followers" might be developing. These followers could gain a second-mover advantage by building on the work of pioneers.

The commander's remarks were reported by Breaking Defense from the conference. The plan represents a structured response to a rapidly evolving digital battlefield where AI tools can accelerate and scale attacks. The service is now implementing architectures designed to verify every access attempt and limit lateral movement inside its networks.

Related coverage

More from Equipamiento