Amazon joins CyLab Cyber Autonomy Initiative to advance research on AI-driven cybersecurity

Michael Cunningham

Sep 15, 2026

group photo of Carnegie Mellon University Privacy Engineering and AI Governance students and faculty members posing in front of a vintage trolley on display at the Heinz History Center

As artificial intelligence rapidly changes both the capabilities of cyber attackers and the tools available to defenders, Carnegie Mellon University’s CyLab Security and Privacy Institute is expanding its collaboration with Amazon to help build the scientific foundations for the next generation of autonomous cybersecurity.

Amazon will become a founding sponsor of CyLab’s Cyber Autonomy Initiative, an interdisciplinary research effort focused on developing AI-powered cyber systems that can identify threats, adapt to changing conditions, and help defend digital infrastructure at machine speed. The collaboration builds on a longstanding relationship between Amazon and Carnegie Mellon, including Amazon’s previous support for CyLab research initiatives.

The partnership also represents a renewed emphasis on AI-enabled security and privacy within CMU and Amazon's broader collaborative focus on AI technologies. In October 2025, the university and Amazon launched the CMU-Amazon AI Innovation Hub, which supports collaborative research, doctoral fellowships, workshops, and other activities spanning generative AI, robotics, natural-language processing, cloud computing, and related emerging technologies.

“Amazon has been with us since our very first initiative research program,” said Michael Lisanti, CyLab’s senior director of partnerships. “They were founding sponsors of both CyLab’s IoT Security and Privacy Initiative and our Future Enterprise Security Initiative.”

Amazon’s involvement in the Cyber Autonomy Initiative continues that history at a moment when advances in AI are creating both new cybersecurity risks and new opportunities for defense.

CyLab’s Cyber Autonomy Initiative brings together researchers across computer science, engineering, and human-centered computing to address fundamental questions surrounding autonomous cyber defense.

Its research agenda spans four interconnected areas: foundational autonomous attack and defense capabilities; human-AI collaboration; systems infrastructure for cyber autonomy; and the Cyber Autonomy Arena, a neutral, end-to-end environment for evaluating emerging offensive and defensive capabilities under realistic conditions.

AI is reshaping cybersecurity. With the Cyber Autonomy Initiative we're seeking to foster research that creates new, AI-enabled defenses that are not just fast and effective, but also trustworthy.

Lujo Bauer, co-director, CyLab's Cyber Autonomy Initiative

For Amazon, the collaboration provides opportunities to engage directly with CyLab researchers, contribute industry perspectives to the initiative’s research direction, and participate in its technical advisory activities.

“We’re in the midst of understanding what autonomous cybersecurity systems can do and how they should be evaluated,” said Eli Fisher, product strategist, Search, Security, and Observability business at Amazon Web Services (AWS). “Establishing strong scientific foundations now, including common benchmarks and realistic environments for experimentation, will be important as these technologies continue to mature.”

A central focus of the initiative is the Cyber Autonomy Arena, which is intended to provide a vendor-neutral, scientifically grounded platform where researchers can evaluate complete autonomous attack and defense systems against one another. The goal is to create an open, community-driven resource where researchers and organizations can contribute attacks, defenses, models, datasets, and other capabilities, enabling more meticulous comparisons of what works, under which conditions, and why.

“This is a great opportunity to create a rigorous, shared environment for evaluating autonomous cyber systems,” said Fisher. “Developing better ways to measure the difficulty of environments, compare approaches, and understand how attacks and defenses perform against one another could help move the entire field forward.”

Technology developed through the initiative is expected to be open source, allowing companies, researchers, and other members of the cybersecurity community to build on the work. Organizations can contribute publicly to the shared ecosystem or adapt components privately for use with their own systems and data.

The collaboration comes as CyLab researchers are finding that the accelerating capabilities of AI require cybersecurity defenses to evolve beyond approaches that depend primarily on human response. Attackers can increasingly use AI to automate reconnaissance, vulnerability discovery, exploitation, and other stages of an attack, while defenders are exploring autonomous systems capable of detecting and responding to those threats at comparable speed.

For Vyas Sekar, co-director of the Cyber Autonomy Initiative, the current shift represents one of the most significant changes he has seen in cybersecurity.

“The pace of advancement in AI is extraordinary,” said Sekar. “Capabilities that seemed experimental even a year ago are quickly becoming practical, which means the cybersecurity community has to move just as quickly to understand both the risks these systems introduce and the opportunities they create for defense.”

Despite the rapid pace of technological development, many fundamental questions about how autonomous cyber systems should be designed, evaluated, and deployed remain unresolved.

“AI is reshaping cybersecurity,” said Lujo Bauer, co-director of the Cyber Autonomy Initiative. “With the Cyber Autonomy Initiative we're seeking to foster research that creates new, AI-enabled defenses that are not just fast and effective, but also trustworthy.”

To learn more about partnering with CMU CyLab and the Cyber Autonomy initiative, contact the CyLab Partnerships team at partnerships@cylab.cmu.edu