A new RAND analysis by former Pentagon cyber policy chief Michael Sulmeyer argues agentic AI — systems that can plan and act with some autonomy — targets the constraint that has kept cyber operations tactical: a shortage of expert operators.
Twenty years of warnings about strategic cyberwar have collided with a stubborn record. The operations have stayed tactical.
A new RAND Corporation analysis argues the gap is not a failure of prediction. It is structural. Three constraints have confined most public cyber activity to the tactical side, and the paper's wager is that AI has real purchase on one of them.
The analysis, Perspective PE-A4901-1 by Michael Sulmeyer, was published July 14, 2026. Sulmeyer directed cyber policy in the Office of the Secretary of Defense before moving to lead the Center for the Geopolitics of Artificial General Intelligence within RAND Global and Emerging Risks. The 23-page paper, available in full as a PDF, focuses on a specific question: what does agentic AI do to the strategic-cyber equation?
The argument runs through what Sulmeyer calls the "tactical-strategic divide." Cyber tools have long been described as strategic instruments of statecraft. In practice, they have almost always been tactical in their application: disruptive, costly, but rarely decisive in the way that a destroyed fleet, a captured capital, or a broken alliance would be.
Sulmeyer identifies three characteristics that keep cyber operations tactical. First, the effect of an operation is hard to predict before it runs. Second, the operations themselves are hard to classify, since the same code can be tested publicly, reused privately, and attributed unevenly. Third, executing at strategic scale has required a scarce class of expert-level human operators, the kind who can plan, sequence, and sustain campaigns that outlive a news cycle.
AI will reshape those three constraints unequally, the paper argues. Effect predictability and classification complexity are likely to remain stubborn problems, because they live in physics, intelligence work, and the adversary's defenses as much as in any tool. Expert-level human capacity is the constraint AI is built to relax. An "agentic" system, in the paper's definition, is one capable of pursuing goals with some degree of autonomy. A planner that can ingest target environments, draft a sequence of actions, and execute portions of it without a human keystroke for every move changes the operator math.
That distinction is the paper's load-bearing claim, and it is also the part most likely to be misread. The press cycle around AI and cyberattack has tended to focus on the attack side: smarter malware, faster exploitation, automated reconnaissance. Sulmeyer's wager is that the more consequential change is on the operations side. The bottleneck has not been ideas for cyber tools. It has been the people needed to run them as sustained campaigns.
The U.S. Congressional Research Service has reached a similar theme in Product IF13151, "Agentic Artificial Intelligence and Cyberattacks," which treats agentic AI as a force multiplier for the planning and execution work that human teams now do. Where RAND's piece is a 23-page argument from one analyst, the CRS product is a short, neutral reference for U.S. lawmakers. Read together, they frame the change as one of operator throughput rather than weapon novelty.
There are two honest counters to the argument. The first is that even if AI multiplies the number of capable operators, effect predictability may not improve at the same rate. A campaign that runs longer with less human supervision can also produce more unintended consequences, and the tactical-strategic divide is at least as much about knowing what will happen as it is about being able to do it. The second is that classification complexity could get worse, not better, as AI systems are trained on operational data whose handling rules were written for human teams.
Sulmeyer's three-factor model is the test for whether the strategic-cyber era is actually arriving. If AI lowers only the human-capacity floor, expect longer and more ambitious cyber operations, with most still resolving as disruption rather than decision. If AI also moves the predictability and classification floors, the gap between predicted and observed strategic cyber may finally close.
That is a question, not a forecast. The paper's value is the test it proposes.