Aeris-UK at AMLUCS 2026: agentic cyber defence at the tactical edge


Aeris-UK was at AMLUCS 2026 in London on 23 and 24 September. We gave a talk on agentic cyber defence at the Land tactical edge and had our CEDAR prototype running on the stand. AMLUCS brings together researchers and practitioners from applied machine learning and cyber security, and this year’s programme covered AI security, autonomous cyber operations and agentic AI.
Our talk, “Measured Feasibility of Agentic Cyber Defence at the Land Tactical Edge”, described work undertaken for Dstl under the Cyber Security Programme, with our project partner Actica Consulting. It asks a practical question: how can AI-based cyber defence work on devices at the edge, where compute, power and connectivity are all constrained?

For a phone, a radio or a drone in a contested environment, sending every decision back to a central system may simply not be possible. The device has to spot that something’s wrong and decide what to do about it there and then. It also has to know which actions it is allowed to take on its own, and which have to go up to a higher-echelon node.
We built CEDAR as an instrumented experiment harness so we could measure what different configurations cost and what they catch. For AMLUCS, we put together a live version on our own network. Two NVIDIA Jetson Orin Nanos stood in as edge devices, running the cyber detection models and LLM-based decision agents, with a DGX Spark as headquarters running a larger model and a Samsung Galaxy S23 carrying our cyber TAK plugin.
On the operator’s UI and the CEDAR console, visitors could watch the system detect and respond to an attack, and launch one of their own choosing from the injector. Kelvin, Izzy, Theo and Ben ran it live across both days. The thing most visitors picked up on was the timescale: three months for the whole project, demo system included.
A recurring theme at AMLUCS was how quickly AI is changing both sides of cyber security. Defenders are getting new tools. So are attackers, and the barrier to more sophisticated attacks keeps dropping. That bites hardest at the edge, in defence and well beyond it. Critical national infrastructure, operational technology and communications systems all depend on distributed devices with modest compute and links that cannot always be relied on. More capability is moving onto those devices, and whatever protects them has to work inside the same constraints.
That’s the problem we’re working on at Aeris-UK: giving devices at the edge enough capability to defend themselves, with clear rules on what they may do alone and what has to be escalated. If you’re up against the same thing, in defence or elsewhere, we’d be glad to talk.


Comments