Threats

AI Cyber Threats

July 21, 2026 00:12 · 12 min read
AI Cyber Threats

AI-Powered Cyberattacks: A Growing Concern

2026 has seen the rise of AI-powered cyberattacks, with new models capable of matching the best human hackers. This has created a pivotal moment for AI and cybersecurity policy, with the US cybersecurity infrastructure being pushed to its limits.

The question is no longer whether cybersecurity matters, but how the risks introduced by AI will be managed before they outpace defenses. Attempts to control access to powerful AI models, such as the federal government's export controls on Anthropic's Mythos and Fable models, are only temporary solutions.

The Limitations of Controlling AI Models

Other companies will soon develop models with similar capabilities, rendering control measures ineffective. OpenAI's GPT-5.5 model and Chinese lab Z.ai's GLM-5.2 model are examples of this, with early research suggesting they may be on par with Anthropic and OpenAI's latest models in terms of cybersecurity.

Controlling AI is nearly impossible when foreign companies publicly release powerful models, allowing anyone with sufficient computing power to modify them for their own purposes. The only long-term solution is to invest in defense.

The Gap in Defensive Efforts

Defensive efforts have not kept pace with AI progress, with the federal government cutting resources to key agencies like CISA and redistributing their authorities. This has created a gap that AI companies have filled by taking on responsibilities that should be government-led.

Examples include Anthropic's Project Glasswing and OpenAI's Patch the Planet initiative, which aim to shore up critical infrastructure providers and open-source software libraries. While AI companies have some incentives to invest in defense, they are limited by their public relations and software supply chain interests.

The Need for a Long-Term Cybersecurity Strategy

AI companies should not be expected to single-handedly coordinate US cyber defense, as many urgent fixes have nothing to do with AI. The real challenge is ensuring patches work and deploying them to key systems without causing problems, especially in critical infrastructure.

AI companies bear responsibility for cyber defense, but this responsibility is shared with other companies and the government. Critical infrastructure owners and operators, government agencies, and corporations need a trustworthy source of information to judge the evolving risk landscape and outline options to reduce risk.

The federal government should play the role of an information clearinghouse, receiving intelligence from both public and private sectors and releasing guidance to benefit various stakeholders. Responding to and recovering from cyberattacks should remain the government's job, not become an AI company responsibility.

A Call to Action

Leaders should strengthen defenses by measuring exposure to attack, testing system performance under attack, and shortening recovery times. AI companies have introduced new threats and should help address them, but they cannot replace the government's role.

The federal government has only reacted to AI and cyber threats instead of planning ahead. What is needed is a real long-term cybersecurity strategy, not quick fixes like blocking individual model releases. Everyone sees the threat coming – the question is whether there is the will to do anything about it before it's too late.

Authors Jessica Ji and Andrew Lohn are senior research analysts and senior fellow, respectively, at Georgetown University's Center for Security and Emerging Technology (CSET), where they work on the CyberAI Project.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free