AI arrives in the cybersecurity domain at a moment in which defenders are already contending with adversaries that are faster, more adaptive, and more resource efficient than they are. Recent advances in generative AI, reasoning, and agentic systems expand capabilities for both attackers and defenders, but in the near term, advances are likely to advantage attackers by compressing key stages of the attack lifecycle and lowering barriers to sophisticated vulnerability exploitation.
There are no widely accepted frameworks for evaluating AI-enabled cyber capabilities or tracking their evolution. The lack of clear behavioral guarantees in generative AI systems further complicates risk assessment, limiting the ability of policy makers and practitioners to calibrate responses.
The baseline level of cybersecurity across society must rise, including stronger security practices, improved software quality, faster response to threats, and more effective sharing of cyber threat intelligence. AI can support this transition but will require new incentives and coordination mechanisms.
Approaches such as controlled access to advanced models, export controls on critical AI hardware, or limits on model distribution may slow the spread of offensive capabilities but are unlikely to be durable in a global ecosystem characterized by rapid technological diffusion.
Emerging approaches such as continuous, AI-driven defense in depth—along with advances in modeling, testing, and system architecture—have the potential to shift the balance toward defenders, provided that sustained investment and coordination occur.
Artificial intelligence (AI) is revolutionizing many domains by introducing advanced reasoning capabilities, automation, and greater autonomy into processes that have previously depended on highly skilled human labor. In cybersecurity, an inherently asymmetric and adversarial domain, such shifts may have especially significant implications. While impacts of AI on cybersecurity have long been anticipated within technical communities (NASEM 2019), recent advances in generative models, large language models (LLMs), and emerging agentic systems have brought new visibility and urgency to these issues.
The promise of AI offers important opportunities to strengthen cybersecurity. Security teams that are often stretched thin may be able to leverage AI-enabled tools to improve threat detection, identify and remediate vulnerabilities, support incident response, enhance software assurance, and facilitate threat intelligence sharing
separate analysis. This publication focuses primarily on areas where recent advances in AI appear most likely to alter cyber operations, cyber resilience, and the balance between attackers and defenders.
This publication is not intended to provide formal recommendations or policy advice; rather, it is designed to inform near-term decision making by policymakers and institutional decision makers across government and the private sector. Consistent with that audience, the publication balances accessibility and technical rigor, exploring issues most relevant to its analysis in greater depth while treating more peripheral topics more broadly.
Cybersecurity is fundamentally shaped by asymmetry. Attackers need to identify and successfully exploit a single vulnerability to compromise the security of a target, while defenders must secure systems across all assets, entry points, and stages of activity. This imbalance has historically favored attackers, particularly in complex and dynamic environments. Recent advances in AI interact with asymmetry in important ways. Many attacker workflows including reconnaissance, vulnerability discovery, and social engineering can be compressed into fewer steps and less time when supported by AI (Sela 2026). These activities can be scaled and automated, lowering the cost and expertise required to carry out sophisticated operations. Agentic AI may further amplify this dynamic by enabling autonomous attack agents to probe large attack surfaces, test rare corner cases, and rapidly mutate tactics at machine speed, while defensive workflows must still balance accuracy, mission continuity, and resource constraints (Li and Zhu 2025). By contrast, defensive activities such as monitoring systems, validating alerts, coordinating responses, and patch deployment are more difficult to compress, as they often require coordination across teams and systems, and must be executed carefully to avoid unintended consequences.
As a result, advancements in AI have the potential to reshape the equilibrium and dynamics of the cybersecurity landscape. This will significantly change how organizations protect networks, systems, and critical functions. At the same time, these developments raise broader questions about risk, resilience, governance, and the responsible use of increasingly capable AI systems in cybersecurity.
The current moment has important parallels to the late 1990s and early 2000s, when the rapid connection of computers to the Internet outstripped the development of corresponding security practices. These parallels are instructive: when interconnected technologies were first adopted at scale, security received far less attention than capability deployment. Capability was relatively easy to measure and demonstrate, while security was more difficult to quantify and often deprioritized.
Over time, major security incidents and large-scale system compromises led to the emergence of new, more robust institutional and technical responses. These included the development of more secure software practices, the growth of cybersecurity as a professional field, the establishment of regulatory and reporting requirements, and the creation of market mechanisms such as cyber insurance. Transparency, accountability, and the systematic measurement of risk gradually became more central to how digital systems were designed and governed.
This historical experience offers two relevant lessons. First, when technological capabilities advance more quickly than security practices, the resulting vulnerabilities can persist for extended periods and can have broad societal consequences. Second, aligning incentives through regulation, market mechanisms, and institutional norms is critical to closing the gap between capability and security.
The current moment echoes these earlier dynamics, but with higher stakes and greater urgency. The United States is far more dependent on digital infrastructure than it was 25 years ago, and AI-driven cyber capabilities are advancing and diffusing at a much faster pace.
Despite these parallels, several features distinguish the current AI-driven transition from earlier technological shifts.
Rapid advancement, deployment, and availability. AI capabilities are improving at an unprecedented pace and are being adopted rapidly and widely on short timescales. At the same time, access to these capabilities is expanding through both commercial services and open-source models, reducing barriers to entry for both legitimate users and adversaries.
Lack of behavioral guarantees. Generative AI systems do not offer clear guarantees about their behavior. Their outputs are best understood probabilistically rather than deterministically, and even expert users may not be able to fully predict or explain their performance in certain scenarios. This introduces uncertainty into systems that are increasingly being used in high-stakes contexts and can lead users to overestimate their reliability or assign anthropomorphic qualities to their outputs.
Emergence of agentic systems. AI systems are evolving from passive tools that support human decision making into systems that can act with increasing autonomy. Agentic systems are capable of carrying out multi-step tasks, interacting with external tools, and adapting to changing conditions. This shift increases the potential benefits, but also heightens the risks because errors or adversarial manipulations can propagate through automated workflows.
Integration into critical infrastructure. AI is being incorporated into systems that underpin essential services, including health care, energy, transportation, finance, and national security systems. As dependence on these systems grows, the potential consequences of security failures increase correspondingly.
Taken together, these dynamics suggest that the current moment represents a significant inflection point for cybersecurity. AI is not only accelerating existing processes, it is reshaping the structure of cyber operations and introducing new forms of risk. The sections that follow examine how these changes manifest across the cybersecurity lifecycle, how they affect the balance between offense and defense, and what implications they hold for policy, investment, and institutional design.