This week’s defence AI landscape is defined by three converging pressures: the first confirmed AI-generated zero-day exploit signals a new era of automated cyber offence; the Pentagon’s FY27 autonomous warfare budget has ballooned to an unprecedented $54 billion while governance frameworks lag dangerously behind; and both the UK and EU are accelerating agentic AI defence architecture, though critics warn policy is outpacing real capability.

Top story: Google’s Threat Intelligence Group confirmed the first-ever AI-developed zero-day exploit in the wild, intercepting a cybercrime group’s planned mass exploitation campaign — a watershed moment for defence cybersecurity teams globally.


Google Intercepts First AI-Crafted Zero-Day Before Mass Attack

CyberScoop · Risk

Google’s Threat Intelligence Group (GTIG) confirmed the first verified instance of a threat actor using an AI-developed zero-day exploit designed to bypass two-factor authentication, intercepting a prominent cybercrime group’s planned mass exploitation campaign before it could be executed. GTIG chief analyst John Hultquist warned this is ‘probably the tip of the iceberg,’ with AI leaving forensic fingerprints in the exploit code — including hallucinated severity ratings and over-annotated Python scripts — that tipped off researchers. For defence and security practitioners, the finding marks a fundamental shift: AI-assisted vulnerability development is no longer theoretical, and the attack cycle is compressing fast.

https://cyberscoop.com/google-threat-intelligence-group-ai-developed-zero-day-exploit/

Pentagon’s Autonomous Warfare Budget Rockets to $54 Billion for FY27

Defense One · Strategy

The Trump administration’s FY27 budget request proposes a staggering 24,000% funding increase for the Defense Autonomous Warfare Group — from $226 million to $54.6 billion — making it a military-branch-scale institution almost overnight. Lawmakers are raising red flags that DoD Directive 3000.09, which mandates ‘appropriate levels of human judgement,’ is completely unequipped for orchestrating thousands of autonomous systems simultaneously, making human-in-the-loop oversight a mathematical impossibility at scale. The Pentagon is effectively committing to autonomous swarm warfare before settling the rules of engagement, a governance gap with profound implications for allied interoperability and international law.

https://www.defenseone.com/ideas/2026/05/pentagons-54-billion-bet-autonomous-warfare/413735/

GCHQ’s Agentic ‘Cyber Shield’ Blueprint Draws Industry Collaboration Call

SecurityWeek · Regulation

The UK’s NCSC fleshed out GCHQ Director Anne Keast-Butler’s vision to ‘hardwire cutting-edge agentic AI into machine speed cyber defence,’ formally launching the Cyber Shield programme and calling on academia, critical national infrastructure operators, frontier AI labs, and the cyber defence sector to collaborate on a national-scale agentic AI defence architecture. Analysts note the initiative arrives alongside the Cyber Security and Resilience Bill, and should be read as the soft edge of a hardening policy position — with voluntary norms likely to be formalised into regulation. For security practitioners, the programme signals significant upcoming procurement and partnership opportunities in AI-native defensive tooling.

https://www.securityweek.com/uk-government-rolls-out-agentic-ai-defense-plan-alongside-industry-pledge/

China’s Top Cybersecurity Firms Hit by US Military Procurement Bans

SecurityWeek · Regulation

Several of China’s leading cybersecurity firms have been struck by mounting military procurement bans, escalating the technology decoupling between Washington and Beijing in the security sector. The move signals a tightening of supply chain controls around AI and cybersecurity tools, with direct implications for allied nations — including UK and EU partners — that rely on shared procurement standards. Defence security teams should expect heightened scrutiny of vendor provenance across the Five Eyes alliance as AI-enabled security tools become strategically sensitive assets.

https://www.securityweek.com/chinas-top-cybersecurity-firms-hit-by-mounting-military-procurement-bans/