AI Will Elevate Near-Term Cybersecurity Risks but — with Investment and Coordination
AI Will Elevate Near-Term Cybersecurity Risks but — with Investment and Coordination — Can Strengthen Cybersecurity in the Long Run
WASHINGTON — To counteract emerging cyberthreats posed by artificial intelligence, the baseline level of cybersecurity across society must rise — including stronger security practices, improved software quality, faster response to threats, and more effective sharing of cyberthreat intelligence, says a new rapid expert consultation from the National Academies of Sciences, Engineering, and Medicine.
Frontier AI systems are rapidly expanding what is possible for both attackers and defenders, the publication says. In the near term, these advances are likely to favor attackers by reducing the time, expertise, and operational effort required for cyberattacks.
“With investment and collaboration, AI could facilitate a stronger approach to cybersecurity that may shift the advantage to the defenders,” said Giovanni Vigna, director of the AI Institute for Agent-based Cyber Threat Intelligence and Operation (ACTION) at the University of California, Santa Barbara, and co-author of the publication. “Cybersecurity will need to improve rapidly to meet this challenge.”
Because AI-enabled cyber capabilities are evolving faster than the ability to evaluate and measure them, risk assessment is further complicated for policymakers and practitioners, the publication says. It provides an overview of how advances in AI are reshaping cybersecurity risks and defenses, including examples and policy considerations for decision-makers in the public and private sectors.
Over longer time horizons, AI may enable fundamentally different and more favorable defensive approaches, allowing for a transition from static, episodic defense to continuous ‘defense-in-depth’ — in which vulnerability discovery and patching, threat detection, intelligence generation, incident response, and other functions operate as ongoing, interconnected processes.
“The short-term outlook is concerning, but the longer-term outlook is cautiously optimistic,” said co-author Paul England, independent consultant and former distinguished engineer at Microsoft Research. “The central task for policymakers and practitioners is to shorten the interval between these two regimes — mitigating near-term risks while speeding the deployment of more adaptive, scalable, and resilient defensive capabilities.”
Security teams that are often stretched thin may be able to leverage AI-enabled tools to improve threat detection, identify and remediate vulnerabilities, support incident response, and facilitate threat intelligence sharing across organizations. More broadly, AI may enable cyber defense activities to be conducted with greater speed, scale, and consistency than has previously been possible through human effort alone, the publication says.
Realizing this promise will require investment across technical, architectural, and institutional dimensions, the publication says. Although measures such as restricted access to the most advanced AI models may help buy time for defenders, long-term security will depend less on limiting access to AI capabilities and more on building resilient systems as those capabilities spread globally.
“A key lesson from the broad adoption of the internet in the late 1990s and early 2000s is that incentives are key to developing a robust security ecosystem,” said co-author Nadya T. Bliss, executive director of the Advanced Capabilities for National Security Institute at Arizona State University. “Without incentives that are aligned to security outcomes, security will continue to receive less attention than capability deployment.”
The rapid expert consultation was funded by the Philip and Sima Needleman Family Legacy Fund. The National Academies of Sciences, Engineering, and Medicine are private, nonprofit institutions that provide independent, objective analysis and advice to the nation to solve complex problems and inform public policy decisions related to science, engineering, and medicine. They operate under an 1863 congressional charter to the National Academy of Sciences, signed by President Lincoln.
Learn key takeways, major implications and more from the rapid expert consultation.
Contact: Molly GalvinDirector, Executive CommunicationsOffice of News and Public Information 202-334-2138; email news@nas.edu
Sign in to access your saved publications, downloads, and email preferences.
Former MyNAP users: You'll need to reset your password on your first login to MyAcademies. Click "Forgot password" below to receive a reset link via email. Having trouble? Visit our FAQ page to contact support.
Members of the National Academy of Sciences, National Academy of Engineering, or National Academy of Medicine should log in through their respective Academy portals.
While logged on as a guest, you can download any of our free PDFs on nationalacademies.org . You will remain logged in until you close your browser.
Thank you for creating a MyAcademies account!
Enjoy free access to thousands of National Academies' publications, a 10% discount off every purchase, and build your personal library.
Enter the email address for your MyAcademies (formerly MyNAP) account to receive password reset instructions.
We sent password reset instructions to your email . Follow the link in that email to create a new password. Didn't receive it? Check your spam folder or contact us for assistance.
We sent a verification link to your email. Please check your inbox (and spam folder) and follow the link to verify your email address. If you did not receive the email, you can request a new verification link below
Related Stories
AI News
12 arrests, but Vancouver largely well behaved after latest FIFA World Cup match: police
35 minutes ago
AI News
World Cup results: Stephen Eustáquio's late goal sends Canada to Round of 16 in a 1
35 minutes ago
AI News
Pride Parade hits Toronto’s streets with PM Mark Carney marching
35 minutes ago
AI News
U.S. and Iran exchange strikes near vital Strait of Hormuz
35 minutes ago
AI News
Why can’t India’s government build a decent website?
36 minutes ago
AI News
Wildfires prompt First Nation in northwestern Ontario to order vulnerable residents to leave
36 minutes ago
AI News
Pesticide regulation changes raise questions in Northeastern Ontario
36 minutes ago
AI News
Fewer newcomers are arriving. In P.E.I., that shift is already being felt
36 minutes ago