U.S. Army Cyber Command has disclosed Task Force Lexington, a unit created in April to operationalize artificial intelligence across cyber operations. Army cyber chief Lt. Gen. Christopher Eubank said the task force is building AI agents that mirror human roles including developers, data engineers, host analysts, exploitation analysts, and red team personnel, with uses spanning staff work and active threat hunting.
Eubank said 17 agentic mission and cyber protection elements are already scanning the Department of Defense Information Network daily, but human operators still make risk decisions and no AI agent is allowed to assume risk autonomously. Army officials said the effort is deliberately avoiding commercial frontier models because of token-cost and governance concerns, while emphasizing internally built capabilities supported by collaboration with the Defense Innovation Unit and industry engineers.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
The U.S. Army established Task Force Lexington in April to explore and operationalize artificial intelligence across cyber command functions. The unit was formed as a small dedicated group after studying industry best practices for integrating AI into cyber operations.
The U.S. Army is pursuing Project Griffin, a pilot effort to build AI-driven cyber defense agents that ingest network sensor data and autonomously execute defensive actions through tools such as Tychon and Microsoft Defender. The planned IRON capability is designed to operate with human oversight and safeguards including confidence thresholds, audit trails, a kill switch, and an undo function.
Army Cyber Command disclosed the existence of Task Force Lexington and described its work building AI agents for developers, data engineers, analysts, and red team roles. Officials also said the effort avoids commercial frontier models because of token-cost and governance concerns.
Lt. Gen. Christopher Eubank said Army Cyber Command now has 17 agentic mission and cyber protection elements scouring the Department of Defense Information Network every day. He said the agents support roles including threat hunting and red team functions, while humans retain responsibility for risk decisions.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedefensescoop.com
Open sourcescworld.com
Open sourcedefensescoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.