THE AUTONOMOUS CYBER WAR

"Prevention is cheaper than a breach"

Back to Blog

THE AUTONOMOUS CYBER WAR
THE AUTONOMOUS CYBER WAR — Visual Research Framework

When operational decision-making becomes executable, speed becomes the new security boundary.

In July 2026, Taiwan detected cyberattacks against government institutions that combined manual operations with AI agents. What matters more than the target itself is what the investigation revealed about the operating model: the human operator had not disappeared. The objective was still human-defined. But between that objective and its execution, part of the operational workload had shifted to agents capable of investigating, assessing and adapting actions in parallel. Taiwan officially confirmed the incident, which Reuters documented on 13 August.

Only a few months earlier, Google Threat Intelligence Group reported the first case in which it had identified a threat actor using a zero-day exploit that GTIG assessed with high confidence had been developed with AI assistance. In the same research, GTIG documented PROMPTSPY, malware in which a model interprets the state of a compromised system and dynamically generates commands. Google described this as part of a maturing transition from early AI-enabled activity towards industrialised use of generative models within adversarial workflows.

Neither case demonstrates that humans have left cyber operations.

That is the wrong question.

The relevant boundary is no longer between human and machine, nor between manual and automated attacks. Cyber operations have been automated for decades. The boundary is shifting from the automation of execution to the delegation of operational decision-making.

Authority
"Authority"

That is where The Autonomous Cyber War begins.

Not when a machine independently chooses which state, company or system to attack, but when, once given an objective and a defined degree of authority, it can observe the environment, interpret an outcome, select the next action, execute it and adapt its subsequent move without requiring a new human decision at every stage. That is a qualitatively different operational dynamic.

The problem is no longer automation alone. It is authority

Verizon’s 2026 Data Breach Investigations Report gives this discussion important context. Exploitation of software vulnerabilities became the leading initial-access vector for the first time, accounting for 31% of breaches in its dataset, while Verizon also recorded the growing use of generative AI across different stages of the attack process.

Its message is not that an entirely new category of attack has suddenly emerged. It is that AI is increasing the speed of existing capabilities. That may be more consequential than it sounds. An attacker does not need a new technique to alter the balance of power. It may be enough to compress the time between reconnaissance, vulnerability discovery, exploit development, validation and the next operational action. Once those stages begin to form an adaptive loop, traditional defensive metrics capture only part of the problem.

For years, cybersecurity has worked to reduce detection latency.

We may now need to pay far greater attention to another variable:

Decision Latency

By decision latency, we mean the interval between the moment a system possesses sufficiently reliable information and the moment an appropriate defensive action is authorised and executed.

Decision Latency
Decision Latency

Those are not the same moment. A SOC may detect an anomaly within seconds, while validation, correlation, escalation, authorisation and response still take minutes. In a human-speed threat environment, that gap was an operational weakness. In a machine-speed threat environment, it may become part of the attack surface itself. If an adversary can alter the trajectory of an operation before the defender has completed its own decision cycle, the issue is no longer simply which side has better detection. It becomes an asymmetry in decision speed.

This is why ENISA’s July 2026 work on Cybersecurity in the Frontier AI Era is particularly significant. It calls for the development of operational capabilities suitable for a new generation of AI-driven threats. On the same day, the European Commission presented its EU Action Plan on Cybersecurity and Artificial Intelligence, explicitly recognising that AI can automate attacks, identify weaknesses and enable cyber operations at previously unseen speed and scale. This is no longer a fringe discussion.

The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 87% of respondents considered AI-related vulnerabilities the fastest-growing cyber risk during 2025, while the proportion of organisations with processes for assessing the security of AI tools increased from 37% to 64%. That is not evidence of autonomous cyber warfare. It is evidence that the risk agenda has already moved.

Europe is defining responsibility as machines acquire authority

This is where the direction of European regulation becomes particularly interesting.

NIS2, DORA, the Cyber Resilience Act, the AI Act and the Cyber Solidarity Act emerged from different regulatory needs, but together they reveal a clear convergence: resilience, accountability, lifecycle responsibility, traceability, supply-chain security and governance are no longer peripheral cybersecurity concerns. The EU Action Plan on Cybersecurity and Artificial Intelligence now links AI capabilities directly to this broader framework.

At the same time, agentic architectures introduce something that this regulatory environment will increasingly have to confront in practice: delegated authority.

Europe is defining responsibility as machines acquire authority
Europe is defining responsibility as machines acquire authority

In February, NIST launched its AI Agent Standards Initiative, focused on agents capable of autonomous actions, with particular attention to authentication, identity infrastructure and secure human-agent and multi-agent interaction. Related NIST and NCCoE work goes further into the identification, authorisation, auditing and non-repudiation of actions performed by software and AI agents.

This creates a problem that extends beyond conventional AI governance:

Responsibility may remain human even when operational authority no longer is. That asymmetry will not be easy to resolve. Over the past several years, Europe has become increasingly precise in defining who is responsible for cyber risk. The next phase will have to become equally precise in defining how that responsibility is preserved when the right to act is partly delegated to systems operating at a speed humans cannot supervise action by action. The Cyber Resilience Act is particularly interesting in this context.

From 11 September 2026, mandatory reporting begins for actively exploited vulnerabilities and severe incidents affecting products with digital elements. Initial notification must be submitted within 24 hours of awareness, followed by a more detailed report within a total of 72 hours. Current NCSC Ireland implementation guidance explicitly warns manufacturers not to delay the initial report while waiting for deep technical analysis to be completed. The obligation can also extend to affected third-party components integrated into the final product.

This is more than a compliance deadline. It signals a shift in the level of operational maturity expected from organisations. An organisation must know, quickly enough, what happened, what is affected, where the relevant component sits within the product chain, what the impact is and what action is required. At the same time, ENISA has published its SME Cyber Resilience Maturity Assessment Model, followed by the Secure by Design and Default Playbook, moving the CRA discussion from regulation directly into European product-security practice.

And this leads to a question that may soon become unavoidable:

Is Secure by Design enough when a system is designed to act autonomously?

From Secure by Design to Secure Autonomy

An agent capable of affecting a real environment is no longer merely a model.

It has identity. Privileges. Context. Memory. Tools. APIs. The ability to initiate actions.

Its value derives precisely from being allowed to do something.

A blanket prohibition on autonomy is therefore as unrealistic as unconstrained autonomy.

The real security problem becomes different:

How do we make autonomy bounded, attributable and reversible?

For this requirement, we propose the term:

Secure Autonomy

Secure Autonomy does not mean “safe AI” in a generic sense. It describes an architectural principle under which every form of delegated machine authority has a defined boundary, identity, scope, decision evidence, audit trail, escalation condition and a controlled means of reversal when an action is wrong or when context moves beyond permitted limits.

Because autonomy without attribution is not resilience. Autonomy without boundaries is not efficiency. And autonomy without the possibility of intervention is not governance. This also changes the familiar debate around Human-in-the-Loop.

In machine-speed cyber operations, a human cannot realistically remain inside every micro-loop of decision-making. If every defensive action requires individual human approval, the requirement for that approval may itself become an exploitable source of latency. But the alternative is not to remove the human. It is to reposition the human.

From being present inside every loop to defining the rules of the loop: authority boundaries, escalation thresholds, acceptable risk, evidence requirements, reversibility and the precise conditions under which the machine no longer has the right to decide. We might describe this as Strategic Human-in-the-Loop. Not symbolic human presence.

An architecture of control.


This is why The Autonomous Cyber War is not a claim that we have already entered a world in which machines independently conduct cyber warfare. We have not. But enough has changed that it is no longer serious to debate only whether AI will be used in cyberattacks.

The relevant questions are now different:

How much of the attack cycle can be executed without a new human decision? How much authority has been delegated? How quickly can the system adapt after receiving a new signal? And how long does the defender need to do the same?

That is where the new boundary is forming. Not between AI and humans, but between two capabilities to observe, decide and act — under different rules and different time constraints.

Europe is simultaneously building one of the world’s most comprehensive architectures of cyber accountability. Technology, however, is introducing the possibility of separating operational decision-making from human tempo. Those two developments cannot remain parallel indefinitely, they will have to meet, and when they do, the central question of autonomous cybersecurity may not be:

How much intelligence can we give the machine?

How much authority can we delegate to it without losing control of the consequences?
How much authority can we delegate to it without losing control of the consequences?

It will be:

How much authority can we delegate to it without losing control of the consequences?

Because autonomous cyber warfare may not begin when humans leave the loop.

It may begin when waiting for one becomes the vulnerability.


Advanced Cyber Security | Research & Analysis

Further reading: Google Threat Intelligence Group — AI Threat Tracker · European Commission — EU Action Plan on Cybersecurity and Artificial Intelligence · NIST — AI Agent Standards Initiative · Verizon — 2026 DBIR · NCSC Ireland — Cyber Resilience Act · ENISA — SME Cyber Resilience Maturity Assessment Model


Originally published by Advanced Cyber Security on LinkedIn, 18 August 2026. Read this article on LinkedIn ↗.

Back to Blog

Scroll to top