Booz Allen Hamilton is targeting the decisions an automated attacker makes inside a network with a new product called Vellox Labs Guile.
The company introduced Guile Sept. 2 alongside research on offensive AI capabilities. Booz Allen says the product aims to interfere with what an autonomous attacker observes and trusts, disrupting its progress.
In testing of 18 U.S. and Chinese models, the company reported that a leading model completed a network intrusion without human guidance. It also reported that coordinated counter-AI playbooks reduced attacker success by more than 95% in its tests.
That percentage describes the company’s tested playbooks. It should not be read as an independently verified protection rate for Guile across government networks.
For an agency considering the approach, a useful question is whether disrupting an automated attack creates time that defenders can actually use. A delay has practical value if it enables an analyst to confirm the threat and contain it before a critical service is affected.
A hypothetical agency evaluation could place the technology in a controlled replica of a service environment. An authorized test team could compare attacks with and without the defensive measures, while reviewers record detection time, attacker progress and effects on legitimate activity.
The agency could repeat the exercise with changed configurations and different attacker behavior. A method that works against one predictable sequence may offer less value when the sequence changes.
Reviewers would also need to determine whether the resulting evidence remains clear enough for an incident investigation. Confusing an attacker should not make it harder for authorized staff to understand what happened in their own systems.
Booz Allen’s announcement presents a defense concept and vendor test results. The next question for government buyers is how consistently the approach works in their environment and whether the time it gains translates into a better response.
