Artificial intelligence (AI) is reshaping the cybersecurity landscape at a pace that outstrips the mechanisms society has historically relied on to secure digital systems. While the implications of AI for cybersecurity have long been anticipated within technical communities, public discourse around these risks has expanded rapidly—particularly in the wake of recent advances in generative models, large language models (LLMs), and emerging agentic systems. Yet much of this discussion has remained at a high level, often emphasizing headline risks over the underlying technical dynamics and their downstream consequences. The adversarial, asymmetric nature of cybersecurity makes these advances especially consequential: defenders must protect every asset at all times, while attackers need only succeed once.
The current moment has important parallels to the late 1990s and early 2000s, when the rapid adoption of interconnected digital systems outpaced the development of corresponding security practices. As in that period, capability is advancing more quickly than the mechanisms needed to ensure security, and incentives are often misaligned with long-term resilience. However, the stakes today are higher: modern societies are far more dependent on digital infrastructure, and AI-enabled cyber capabilities are advancing at a much faster pace.
This rapid expert consultation examines how recent advancements in AI will alter the balance between defense and offense, how these capabilities are transforming the cyber lifecycle, and what policy measures and research investments would help mitigate near-term risks while supporting a more resilient long-term cybersecurity posture for the United States.
Recent advances in generative AI, reasoning, and agentic systems represent a turning point for cybersecurity. Frontier AI systems are rapidly expanding what is possible for attackers and defenders. In the near term, however, these advances are likely to favor attackers. Attacker workflows, such as vulnerability discovery, exploit development, and social engineering, compress readily into fewer steps and less time, lowering the cost and expertise required to carry out sophisticated operations. Defensive work—including monitoring systems, validating alerts, coordinating responses across teams, taking remediative action, or continually maintaining and improving the security of software systems—is harder to compress and must be integrated across complex systems and organizations. These developments create a period of elevated risk in which attacker capabilities are likely to advance faster than defensive capabilities can adapt.
At the same time, the pace of advancement in AI-driven cyber capabilities is outstripping current measurement and evaluation approaches. There are no widely accepted frameworks for evaluating how effectively AI systems perform offensive or defensive cyber tasks, nor for tracking how those capabilities evolve over time. More fundamentally, generative AI systems lack clear behavioral guarantees, and their outputs must be understood probabilistically rather than deterministically. The resulting uncertainty makes it difficult to predict system behavior, particularly in adversarial settings, and limits the ability of policy makers and practitioners to calibrate responses.
Despite these uncertainties, the direction of change is clear: the baseline level of cybersecurity across society will need to rise. Organizations will need to adopt stronger security practices, improve software quality, invest in more resilient architectures, and respond more quickly to emerging threats. AI can support this transition by enabling better detection of security vulnerabilities, improved communication among organizations through automated synthesis of threat information, and more scalable sharing of cyber threat intelligence. However, achieving
these benefits will require new incentives and coordination mechanisms that allow defensive capabilities to scale alongside the threats they are intended to counter.
There may be opportunities to mitigate near-term risks and buy time for defensive adaptation. Approaches such as controlling access to leading-edge AI models, restricting exports of critical hardware, and limiting model distribution may slow the spread of the most powerful offensive capabilities. However, these measures are unlikely to be comprehensive or durable as advanced AI capabilities diffuse globally through multiple mechanisms, including open-weight and open-source models developed domestically and internationally. As a result, long-term security will depend less on restricting access and more on improving resilience.
Over longer time horizons, AI may enable a fundamentally different and more favorable defensive posture. This publication describes how AI could enable a transition from static, episodic defense to continuous defense-in-depth, in which posture assessment, vulnerability discovery and patching, formal verification, threat detection, intelligence generation, and incident response operate as ongoing, interconnected processes against a shared, continuously updated picture of systems and their environments. Because this capability scales with the defenders' visibility into their own infrastructure, it offers the potential for a structural advantage that is more difficult for attackers to replicate.
Realizing this promise will require investment across technical, architectural, and institutional dimensions. Securing AI-enabled systems themselves, as well as using AI to secure other infrastructure, will be essential, particularly as agentic systems and data-integrated architectures introduce new attack surfaces. Progress will depend on improved measurement and evaluation, the alignment of incentives with security goals, and strengthened public–private collaboration to develop shared frameworks, standards, and evaluation infrastructure.
Taken together, the analysis in this publication suggests that adopting AI-enabled cybersecurity defenses will become increasingly important as AI-driven cyber capabilities continue to advance (Box 1). Failing to do so would leave mission-critical infrastructure exposed to autonomous, AI-enabled attacks operating at a scale beyond what human defenders can effectively address. The policy and engineering challenge of the next several years will be to accelerate a transition from the near-term environment, marked by attacker advantage, toward a longer-term regime in which defensive capabilities can scale more effectively.