The Government's Cyber Force Was Depleted. Private Contractors Are Filling the Gap.
The August directive authorizing private firms to conduct offensive cyber operations converges a year of diminished federal cyber capacity, contractor filtering, and oversight circumvention.
When the administration authorized covert military strikes against drug cartel operations near Venezuela last November, it described the targets as "narco-terrorist networks." When it authorized private U.S. companies to conduct offensive cyber operations this week, it described the targets as "transnational criminal organizations." The framing is the same — criminal networks operating beyond the reach of ordinary law enforcement. So is the congressional checkpoint both operations circumvent. The Venezuela strikes did so through covert military channels; the cyber directive does so by routing operations through the Department of Homeland Security and the Department of Justice rather than the Department of Defense or the intelligence agencies, where congressional oversight of the use of force is more established. [1][2] The August 12 presidential memorandum authorizes vetted private firms to conduct disruption, denial, degradation, or destruction of foreign information systems, overseen by DHS and DOJ, with firms posting $1 million escrow bonds. [2] It is the latest move in a cyber strategy Trump unveiled in March.
We will unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities. — Donald Trump
But the directive is not a sharp turn. It is the visible endpoint of three developments that accumulated across the past year, each one reported separately but never lined up beside the others. The first is the hollowing out of the federal government's own cyber capacity. CISA, the agency responsible for defending civilian government networks, has been steadily depleted. Representative Bennie Thompson, the ranking Democrat on the House Homeland Security Committee, quantified the damage at a March hearing.
Completely lacking is even the most basic blueprint for how the Administration will go about achieving any of its cybersecurity goals — an objective possibly hamstrung by the hemorrhage in cyber talent across all Federal agencies since Trump took office. — Bennie Thompson
At the same hearing, SOCOM officials disclosed the fiscal pressure behind the capacity gap. [3]
purchasing power has been reduced by 14 per cent since 2019, despite increasing demand for support worldwide — Ronny Jackson
And at U.S. Cyber Command, the strain has been lethal: the command is investigating a suicide cluster of up to five personnel between June and July 2026, driven by surging workload from the Iran war and AI implementation. General Joshua Rudd offered a warning that now reads like a premonition.
Without funding, burnout and force degradation will increase. — Joshua Rudd
The private-sector push, as Thompson's critique suggests, may fill a gap the administration's own choices helped create. [4] The second development is the contractor filter. Over the past year, the administration has demonstrated a clear preference for private firms that do not impose ethical guardrails the government has not required. In May, the Pentagon designated Anthropic a supply-chain risk specifically because the company refused to remove AI safeguards regarding domestic surveillance and autonomous weapons — even as it continued deploying Anthropic's Mythos AI, a model that had already penetrated nearly all U.S. classified systems within hours. [5][6] Anthropic had previously been dropped from Project Maven, the Pentagon's AI-assisted targeting program, after setting ethical restrictions against automated strikes. [7] The government did not have to ask any firm to lower its standards. It selected the ones that never imposed them. In February, the Defense Information Systems Agency authorized Palantir to deploy its full AI software stack — Gotham, Foundry, Apollo, and AIP — at the Top Secret level, using a framework with an explicit purpose.
can be deployed across any environment, from enterprise data centers to the tactical edge, on hardware of the customer's choosing. — Palantir
The private infrastructure for offensive operations was already in place before the August directive was signed. [8] The third development is the routing of operations around congressional oversight, and the oversight void that routing enters. The Cybersecurity Information Sharing Act, which provided liability protections for private companies sharing cyber threat intelligence with the government, expired in October 2025 after Senator Rand Paul blocked its renewal during a government shutdown. [9] The AI cybersecurity framework governing the tools these private firms will use is voluntary, not mandatory, and keeps its testing rubrics classified. Senator Kirsten Gillibrand described the approach in plain terms.
The American people and leading AI companies need clear rules, not constantly changing dictates from the White House. — Kirsten Gillibrand
Meanwhile, the Senate has defeated war powers resolutions limiting the administration's Iran campaign at least three times — in March, May, and in subsequent votes. Senator Bill Cassidy identified what was missing.
While I support the administration’s efforts to dismantle Iran’s nuclear program, the White House and Pentagon have left Congress in the dark on Operation Epic Fury. — Bill Cassidy
Then there is the quietest fact in the whole architecture. The Department of Homeland Security — the agency now tasked with overseeing private firms conducting offensive cyber operations — was itself shut down in February 2026 over an internal dispute about ICE surveillance tactics. [10] What is absent from the August directive is as revealing as what is in it. No legislation authorizes it. No congressional vote approved it. The framework governing the AI tools these firms will deploy is voluntary, with classified testing standards. [11] And the agency charged with oversight was closed earlier this year.
- 1. Trump Authorizes Covert Military Strikes Near Venezuela
- 2. Trump Authorizes Private Firms to Conduct Offensive Cyber Operations
- 3. US Military Shifts to AI-Led Warfare Model
- 4. US Cyber Command Investigates Suicide Cluster Among Personnel
- 5. Pentagon Deploys Anthropic's Mythos AI Despite Ongoing Phaseout
- 6. CISA Uses Anthropic AI to Scan Government Software
- 7. U.S. Uses Project Maven AI in Iran Strikes
- 8. DISA Authorizes Palantir Software for Top Secret Edge Deployments
- 9. Cybersecurity Information Sharing Act Expires Amid U.S. Government Shutdown
- 10. DHS Shuts Down Over ICE Surveillance Reform Dispute
- 11. Trump Finalizes Voluntary Cybersecurity Framework for Frontier AI Models