# Military AI Agents Under Cyberthreat: The Route Forward

> Source: <https://www.eetimes.com/military-ai-agents-under-cyberthreat-the-route-forward/>
> Published: 2026-07-31 07:30:00+00:00

AI technology and AI agents have evolved at a rapid pace over the last few years and are being used as strategic tools in military operations by many nations around the world. [A report from the Brennan Center](https://www.brennancenter.org/media/15340/download/bcj-167_business_of_military_ai_final.pdf?inline=1) stated that U.S. AI-driven military programs could surpass $75 billion in the coming years (not including secret programs). Other military powers, including Russia and China, are also investing heavily in autonomous and AI-driven military technology.

The Russia-Ukraine war was the first occurrence in an international conflict where both sides used AI for military purposes. In more recently started conflicts, the U.S. has used AI to help identify and prioritize targets in Iran based on factors such as strategic importance and legality, drawing on data from satellites, social media, and U.S. military drones and sensors.

Success on the battlefield with AI includes improved geospatial intelligence and surveillance to identify threats, logistics, unmanned operations, and autonomous weapons that can take lethal actions on a target (but this does have varying degrees of human involvement). The expanded usage of AI on the battlefield (and warfare in general) has also been implemented alongside the increasing use of drones in modern-day warfare.

Despite their benefits for military operations, AI agents come with a lot of risks, both operationally and from a cybersecurity perspective. “AI agents can help with logistics, intelligence, surveillance, and battlefield decisions,” Mahmoud Javadi, a Ph.D. researcher at the Centre for Security, Diplomacy, and Strategy at Vrije Universiteit Brussel, told EE Times. “But the problem is that war is messy, and data is incomplete. Enemies are trying to deceive their counterparts, and AI systems can still make very strange mistakes.”

[View All](https://www.eetimes.com/category/sponsored-content/)

Operationally, AI agents frequently make mistakes. This has been well-documented over the last few years, since AI technology became mainstream, and AI used in the military is not exempt from these issues. The only difference is that if an AI military agent makes a mistake, it could mean that innocent people die.

“If an adversary can hack the system, poison the data, manipulate the model, or confuse the sensors, then the AI agent may become dangerous very quickly,” Javadi said. “In a military situation, even a small error can become very serious.”

This is an extreme case, but when military targeting is involved, as well as surveillance for threats, the wrong identifier or operation has the potential to be disastrous. The fact that most AI systems are a black box as well, without accountability or explainability, puts more pressure on militaries and governments to get it right.

“My concern [about military AI] is less about some Hollywood-style machine taking over,” Javadi said. “My concern is more practical. A commander may rely too much on a system, the system may wrongly identify something, or it may push one option as the best option; and under pressure, humans may follow it without questioning it enough.”

However, even when governments and militaries do get it right, there is always the threat of outside interference and nefarious attacks from malicious actors and rogue states in the form of cyberattacks targeting these AI agents. AI agents are much more vulnerable to cyberattacks than traditional military platforms, as there are multiple entry points in the digitally connected networks that can be exploited.

“I would say the main risks are over-trust, cyber manipulation, unclear responsibility, faster escalation, and humans slowly losing real control while still being formally in the loop,” Javadi said. There is, however, still a lack of robustness and governance for protecting against continually expanding cyberthreats.

**How military AI agents are at risk from cyberthreats**

The robustness and reliability of AI systems in the military are not yet advanced enough to guarantee they will be infallible during operation or when attacked. Militaries need to be aware that their AI is going to be highly susceptible to failure and provide more potential entry points for nefarious state actors to exploit. This can take the form of disrupting the data at the core of AI agents, gaining access to confidential military information, and hackers’ ability to take over military systems.

The decentralized and cloud-connected nature of AI agents and the digital networks they interact with provides more potential entry points for hackers to exploit. While digital architecture typically incorporates multiple layers of security, gaining access through a less protected entry point can make it easier to reach more critical areas. Compromised systems can also become a part of bot networks that overload other systems.

The other key issue is that no matter how careful governments are about implementing AI, they are not typically the developers of AI technology—private companies are. Governments and militaries function as end users alongside other clients. For example, it’s been well-documented that Israel has been using Palantir for attacks on Gaza and Lebanon.

Private companies have driven AI innovation beyond what government agencies have achieved, leaving militaries dependent on commercial technologies. However, each company configures and protects its AI systems differently, resulting in a lack of standardization. This requires governments to place a significant level of trust in the private companies whose AI they deploy—especially when those same technologies are made available to multiple customers, potentially increasing opportunities for adversaries to identify vulnerabilities or backdoor access points.

So what are the potential attacks that military AI agents are vulnerable to? There are several.

Integrity attacks, including evasion and data poisoning, deceive AI agents and cause them to make incorrect decisions. They represent the most common class of cyberattacks against AI military systems. Evasion attacks exploit imperfections in AI algorithms, leading detection systems to misidentify targets. For example, a visual image captured by a drone could be manipulated to conceal threats in an area, such as a military facility or a mobile missile launcher.

Data-poisoning attacks happen at the data level and require hackers to manipulate training data. This manipulation causes AI to learn the wrong patterns, which means it makes wrong decisions. In military operations, having such erroneous data and decision-making capabilities can lead AI agents to fail to identify the correct target or misidentify friendly forces (or civilians) as hostile forces. Data poisoning can also result in the unintended disclosure of sensitive military information through the extrapolation of the data on which the AI was trained.

If governments were to develop their own AI systems using exclusively internal datasets, this concern would be less pronounced. It again points to the broader public-private dependency that defines much of today’s AI ecosystem. Data needs to be trusted that it has not been “poisoned,” which can be difficult with commercial partnerships, especially when AI algorithms have been known to scrape information from the internet. If during this scraping—or through the AI company using open datasets, shared corpus, or user-generated inputs—the model is trained on malicious data, it can end up with the agent not only doing the wrong thing but also doing what the attacker wants it to. If this were a chatbot, the potential damage would be minimal. For the military, it’s a lot more serious.

Beyond system hijacking and data theft, another approach is disruption by overloading AI agents so that they don’t work properly or shut down. Availability attacks, such as ransomware and denial-of-service attacks, can easily shut down military logistics and supply chains. While not as dangerous in some cases compared with rogue weapons, cutting off military supplies can cause a lot of issues in times of war.

The threats can come from all over the world, especially as geopolitical tensions continue to strain. The U.S., Russia, and China all have advanced cyber capabilities, and countries such as North Korea regularly utilize cyberwarfare because they lack traditional military capabilities and firepower compared with the countries they misalign with. In the U.S., the threats and lack of preparedness for them led to the Defense Advanced Research Projects Agency (DARPA) launching the Securing Artificial Intelligence for Battlefield Effective Robustness (SABER) project in 2025 that will run for a few years and aims to protect AI-enabled autonomous ground and air systems against both physical and cyberattacks.

##### Read also:

[Ukraine Eyes Interceptor Drones for the Battlefield](https://www.eetimes.com/ukraine-eyes-interceptor-drones-for-the-battlefield/)

[How Drones Are Helping to Better Monitor the Grid ](https://www.eetimes.com/how-drones-are-helping-to-better-monitor-the-grid/)

[Where is AI Being Used to Improve AMRs?](https://www.eetimes.com/where-is-ai-being-used-to-improve-amrs/)
