Summary
- Sweden has ordered FRA to begin piloting AI-supported cybersecurity tools for critical public and private organisations.
- The programme will examine international models and consider how a permanent capability could operate through Sweden’s National Cyber Security Centre.
- FRA must provide an interim assessment by 30 October and a final report by 29 January 2027.
Sweden is moving artificial intelligence from cybersecurity policy into operational testing, giving its signals intelligence agency a mandate to develop a pilot service for organisations whose disruption could affect essential public services and infrastructure.
Sweden’s National Defence Radio Establishment (FRA) has been instructed to examine the conditions needed for an AI-supported national cybersecurity capability and begin using AI tools to support societally important organisations in the public and private sectors. The Swedish Armed Forces will contribute expertise, while FRA must also propose how a longer-term capability could be developed through Sweden’s National Cyber Security Centre.
The formal government assignment, published on 4 September, gives the programme a compressed timetable. FRA must submit an interim report by 30 October covering international comparisons and the proposed design of the pilot, followed by a final written report to the Ministry of Defence by 29 January 2027.
The government has not specified which models, vendors, or technical architecture will be used, although it has identified activities including faster vulnerability detection, risk analysis, and defensive measures. Any national service operating against live infrastructure will therefore have to answer questions that extend beyond model accuracy, including where sensitive data is processed, what systems an AI tool can access, and when a human operator must approve its recommendations.
Cyber AI moves towards operational testing
Sweden had already given FRA a coordinating role for national cybersecurity work involving AI, so the new assignment adds an operational layer to that policy. Instead of concentrating solely on guidance or information sharing, the pilot is intended to produce practical experience of AI-supported defence across organisations delivering important functions.
Those environments are rarely tidy. Critical operators can run combinations of cloud services, conventional enterprise IT, industrial systems, legacy software, and bespoke infrastructure, while public bodies may hold information that cannot simply be passed into externally hosted models. The design of a national capability consequently depends on permissions, hosting, audit trails, data boundaries, and responsibility for incorrect automated conclusions as much as the underlying model.
AI can reduce the time required to inspect software, prioritise vulnerabilities, and correlate large amounts of security information, although similar capabilities are available to attackers. Sweden’s government has framed the programme around that dual use, arguing that AI-supported tools could help defenders identify risks more quickly while hostile actors adopt the same technology.
Britain is pursuing a related approach through the National Cyber Security Centre’s Cyber Shield programme, which is exploring how government, industry, and sector-level defenders could cooperate around agentic cyber defence. FRA has been explicitly instructed to study comparable international initiatives as it develops the Swedish pilot.
Authority becomes part of the architecture
The question of what an AI system is permitted to do becomes more important as defensive tools progress from analysis towards action. A model that identifies a suspicious configuration presents one level of risk; a system capable of scanning assets, changing security controls, or coordinating a response presents another.
A national service could concentrate scarce expertise and computing resources for organisations that do not operate large security teams themselves. At the same time, centralising security telemetry or privileged access would create a valuable target, so the eventual design will need clear separation between advisory functions and any actions that affect customer systems.
The UK NCSC has cautioned that current AI systems are stronger at identifying security problems than reliably carrying out responsive actions, leaving human control, access restrictions, and established cyber hygiene as necessary parts of an agentic defence model rather than temporary obstacles on the path to full autonomy.
Sweden’s timetable should provide evidence relatively quickly. The October interim report is expected to set out the pilot design and lessons from other countries, while the January submission will show whether FRA believes an AI-supported capability can become a durable part of national cyber infrastructure. Until then, the programme remains an operational experiment rather than a claim that autonomous defence has arrived.












