The threat of system breaches has long been a source of sleepless nights for cybersecurity teams. When Anthropic revealed that its frontier AI model Mythos Preview had autonomously found thousands of high- and critical-severity vulnerabilities across major operating systems and browsers,1 it was a wake-up call to both the threat of hidden system vulnerabilities and the potential for AI to empower cyberattackers. Yet the technology works both ways. AI can also be used to defend organizations, and agentic AI could offer the most direct path to closing the risk gap by improving the speed and effectiveness of cyberattack detection, investigation, response, and remediation.
That’s especially critical in the public sector, where cybersecurity teams shoulder the added burden of defending the systems that citizens rely on and that governments simply cannot allow to fail. For public agencies defending expanding digital environments with constrained staffing and budgets, agentic AI could be a game changer (exhibit).
Yet the challenge is safely and effectively deploying, operating, and governing AI agents at scale. First, transformation is hard—period. Second, AI presents specific risks around its potential to alter the nature of ways of working, which is difficult for both employees and organizations. For example, automating routine, repeatable work to free up analysts to focus on higher-value investigations, decisions, and governance not only shifts how people work but also demands several foundational capabilities be in place, such as an inventory of systems and data, model and agent governance, and the emerging skills to support them. Third, needs differ dramatically across agencies, as do available resources. The requirements and available budgets at federal agencies, for instance, may be many times greater than those at a municipality. And last, execution adds another layer of complexity, especially instituting the operating principle of using agents to extend human reach while ensuring humans retain judgment over consequential actions.
What’s required is the scaffolding most organizations must deliberately build. While needs and resources vary, our experience is that four phases are common to agentic AI deployments in federal and state cybersecurity organizations to drive actionable decisions:
- Determining the baseline cybersecurity capability and target state for AI enablement. A baseline maturity assessment should be established or refreshed and a high-level vision and overarching principles defined for the responsible use of AI and agentic AI in cybersecurity, with priority workflows identified for agentic AI potential. Baseline AI readiness should also be determined by evaluating automation maturity, data quality, integration of telemetry (the streams of log, network, and endpoint data that feed monitoring tools), and governance controls.
- Identifying potential domains for AI to enhance cybersecurity and estimating the potential impact of automation for efficiency. With a baseline, guiding principles, and priority domains established, identify where and how those cybersecurity services can be enhanced with AI and agentic AI and estimate the impact. Domains can be scored and prioritized (weighing factors such as automation potential, level of effort, and expected efficiency gains) and agent actions requiring human review or approval specified and validated.
- Selecting, testing, and refining domains for cybersecurity to enhance with AI. Three to five high-impact, high-feasibility domains can be selected, the required enablers defined (such as data pipelines, model governance, infrastructure, and talent), and proofs of concept developed with clear objectives, success criteria, and resource allocation. Each can be implemented and tested in a controlled environment with guardrails built in (such as predefined kill switches and human review of agent actions), with performance assessed and refinements made based on feedback.
- Designing, validating, and executing the implementation road map for deployment of AI within the cybersecurity function. A prioritized deployment road map focuses on reducing risk, improving governance, and strengthening technology resilience, beginning with investment sequencing and a concrete implementation plan. It includes analyzing each domain to pinpoint where agents can assist, where they can execute with human approval, and where full autonomy is not yet appropriate; mapping the “from–to” shift needed to reach the agentic AI target state while reducing risk and improving efficiency; and beginning the rollout in one or two areas chosen for impact, feasibility, and reversibility so early mistakes stay contained and recoverable.
These phases help frame the approach to agentic AI not as a technology exercise but as a risk-reduction, resilience, and workforce-enablement agenda. This approach gives stakeholders a fact base for investment decisions in areas where budgets are often limited, and it helps translate the opportunity into terms that matter to the people who must fund and approve it, including agency heads, CIOs, budget and procurement leaders, and legal and risk officers. These roles will vary across governments, by level and by country, as will budget and procurement realities.
Leaders should also plan any transition as a change management effort—reskilling staff toward supervision, validation, and governance—and be explicit about the caveats. Agentic AI should not automate poorly understood processes or outpace an organization’s risk appetite, controls, and oversight. Data governance is especially critical in government: Agents touching constituent records—tax, health, benefits, and licensing—must operate within privacy obligations, with access scoped and logged. Success is measured by efficiency, reduced risk, better decisions, and sustained trust.
Agentic AI has the potential to reshape public sector cybersecurity, but the path to value begins with readiness: understanding the current baseline, identifying where agents can safely help, testing the highest-value domains, and building a road map that sequences investments in data, platforms, governance, talent, and change management.
Organizations acting with discipline today have an opportunity to build cybersecurity programs that are more resilient, more adaptive, and better able to protect the trust citizens place in digital government.
1 “Project Glasswing,” Anthropic, April 7, 2026.Charlie Lewis is a partner in McKinsey’s Connecticut office; Cameron Shane is an expert in the Washington, DC, office; Daniel Wallance is a senior expert in the New York office; and Parth Jagodara is a consultant in the Carolinas office.
The authors wish to thank Hrishika Vuppala for her contributions to this article.



