A growing number of defense organizations are deploying AI-powered email assistants for senior executives — systems that screen incoming messages, draft responses, manage calendars, and in some cases communicate with external contacts on behalf of humans who never see the original correspondence.
The trend is driven by a real problem: senior leaders at defense firms receive hundreds of emails daily, and the cognitive load of managing that volume is a genuine productivity drain. AI assistants promise to filter noise, prioritize critical messages, and handle routine communications automatically.
But cybersecurity experts warn that the implementation is outpacing the security analysis. These systems create new attack surfaces that most organizations haven't fully mapped.
"An AI email assistant is, functionally, a trusted insider with access to sensitive communications and the authority to act on them."
Dr. Rafael Torres, Georgia Tech"An AI email assistant is, functionally, a trusted insider with access to sensitive communications and the authority to act on them," said Dr. Rafael Torres, a professor of computer science at Georgia Tech who studies adversarial AI. "If someone can manipulate that system through prompt injection or social engineering, they've bypassed every human judgment layer the organization relies on."
The attack vectors are well-understood in the research community. Prompt injection — embedding malicious instructions in seemingly innocent email content — can cause AI systems to override their intended behavior. Social engineering techniques that would fail against a trained human can succeed against an AI that lacks contextual judgment about trust and relationships.
Several defense organizations contacted by the Signal confirmed they use AI email management tools for senior leadership but declined to discuss specifics. One information security director, speaking on background, described the situation as "a constant negotiation between executives who want efficiency and security teams who see a gaping hole in the perimeter."
"The irony is that the people most likely to have these systems are the people with the most sensitive communications," the source added. "CEOs, CSOs, program managers with classified portfolio access. We're automating the handling of our most valuable information and hoping the AI gets it right."
Industry groups including the Defense Industrial Base Cybersecurity Assessment Center have begun developing best practices for AI assistant deployment, but adoption remains voluntary. No current DOD



