{
  "architecture": "multi-sensor telemetry; asset and identity graph; ensemble analysis; policy-constrained actions; reversible containment; deterministic safety interlocks; human command visibility; signed audit records; recovery verification",
  "canonicalUrl": "https://xn--mwe.com/knowledge/autonomous-cyber-defense/",
  "claimStatus": "PROJECT DOCTRINE",
  "contradictionIds": [
    "CON-K04-STRAT-013"
  ],
  "correctionStatus": "CURRENT K05 RELEASE",
  "doctrine": "Project doctrine favors high-speed autonomous defense inside owned or expressly authorized environments, with progressive action tiers, fail-safe defaults, independent verification, and no implied authority to enter third-party systems.",
  "evidenceLimitationIds": [
    "LIM-K04-STRAT-018"
  ],
  "focus": "defensive autonomy, agentic security operations, cyber reasoning, containment, restoration, deception, and evidence-preserving response",
  "id": "K01-TOPIC-019",
  "knowledgeEdgeIds": [
    "EDGE-K04-STRAT-003"
  ],
  "lastReviewed": "2026-08-16",
  "law": "Internal defensive automation is bounded by ownership, contract, privacy, sector regulation, labor obligations, safety duties, and any restrictions on interception, monitoring, or external access.",
  "name": "Autonomous Cyber Defense",
  "relatedQuestionUrls": [
    "https://xn--mwe.com/questions/what-makes-autonomous-defense-safe-enough-for-ot/",
    "https://xn--mwe.com/questions/can-an-autonomous-defender-act-without-human-approval/",
    "https://xn--mwe.com/questions/what-must-be-tested-before-autonomous-containment/"
  ],
  "relatedReportIds": [
    "REP-K04-055",
    "REP-K04-047"
  ],
  "relatedTermIds": [
    "K01-TERM-145",
    "K01-TERM-146",
    "K01-TERM-147",
    "K01-TERM-148",
    "K01-TERM-149",
    "K01-TERM-150",
    "K01-TERM-151"
  ],
  "releaseId": "K12-2026-08-16",
  "researchCutoff": "2026-08-16",
  "risk": "an unconstrained defensive agent can become a new privileged attack surface, propagate false positives, disable critical services, or confuse technical capability with authority",
  "short": "Autonomous cyber defense uses machine-speed systems to observe, correlate, prioritize, contain, reconfigure, restore, and learn within pre-authorized defensive boundaries.",
  "slug": "autonomous-cyber-defense",
  "sourceRevalidatedAt": "2026-08-15T23:00:00Z",
  "sources": [
    "SRC-WH-EO-14409",
    "SRC-WH-GOLD-EAGLE-2026",
    "SRC-USAASC-CYBER-WARFARE-2026",
    "SRC-NIST-800-207",
    "SRC-NIST-800-82R3"
  ],
  "type": "Topic"
}
