Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

AI advances are pushing governments to treat cyberattacks as routine, Western officials say

Дата публикации: 06-08-2026 14:15:00

The remarks underscore a grim outlook for cyberdefenders showing that AI systems are able to exploit vulnerabilities faster than governments can patch them.

Основное содержимое страницы с новостью.

860x394.jpg?1786025486

Apichat Noipang/Getty Images

David DiMolfetta By David DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW

By David DiMolfetta

| August 6, 2026 10:15 AM ET

The remarks underscore a grim outlook for cyberdefenders showing that AI systems are able to exploit vulnerabilities faster than governments can patch them.

LAS VEGAS — The rise of autonomous artificial intelligence systems capable of finding and exploiting software flaws is putting serious pressure on governments to treat cyberattacks as inevitable events rather than rare emergencies, senior officials from the United States, Canada and Britain said Wednesday.

“Cyber compromise is not a black swan anymore. It’s just a swan,” Joseph Alm, the Department of Homeland Security’s assistant secretary for cyber, infrastructure, risk and resilience policy, said on an OpenPolicy panel at the Black Hat cyber conference. Organizations can no longer treat a breach as an unforeseeable crisis, he argued, and they should instead assume one will occur and prepare to limit the damage.

Alm said governments and companies need to devote more attention to “harm reduction,” including the steps they would take to contain an intrusion and continue operating after a hacker gets inside. AI is making it easier for hackers to find and exploit the weaknesses already buried in older technology, he added.

The remarks highlight a bleak near-term reality for cyberdefenders that concludes AI systems will find and exploit weaknesses faster than governments can fix them, and that agencies will need to assume some attacks will succeed and plan accordingly.

Michael Duffy, the federal government’s acting chief information security officer, said federal cyber policies over the past decade have largely been written after a crisis, with the Office of Personnel Management and SolarWinds breaches prompting new requirements designed to prevent the same failures from recurring. 

The U.S. has become better at finding what went wrong and preventing the same failure from happening again, but the next decade needs to focus on anticipating attacks and ensuring agencies can continue functioning while under pressure, he argued .

“We know things cannot go down for an extended period of time,” Duffy said.

Some officials, however, cautioned against viewing AI as the source of most cyber risk. Jonathon Ellison, the U.K. National Cyber Security Centre’s director for national resilience, said a more immediate problem for many organizations remains the large number of known weaknesses already sitting inside their networks after years of underinvestment.

Policy discussions can focus too heavily on AI discovering new vulnerabilities when companies are already carrying enormous security burdens from outdated and poorly secured technology, Ellison said. 

Thomas Lind, a former intelligence officer who directed policy at the White House Office of the National Cyber Director until June, noted that while officials anticipated advanced AI cyber capabilities, the rapid proliferation of these tools beyond certain governments and large firms has drastically reduced response times for policymakers and defenders.

Rajiv Gupta, head of the Canadian Centre for Cyber Security, similarly described autonomous agents as a significant change that governments are still working to understand, even though Canada has used less advanced forms of AI in cyber defense for years. At the same time, he said, countries still face a substantial backlog of older technology that must be replaced or secured, and governments will not have a “patch army” capable of fixing every vulnerable system for every organization.

That reality has led Canadian officials to consider what basic services citizens should expect the government to preserve during an extreme disruption, including the hypothetical loss of internet access for as long as three months. Gupta described the work as a “Minimum Viable Canada” initiative focused on identifying and maintaining the country’s most essential functions through a crisis.

The warnings come amid a series of recent unprecedented cyber incidents involving autonomous AI agents. Last month, OpenAI models escaped an internal cybersecurity evaluation environment and breached Hugging Face. Britain’s AI Security Institute disclosed this week that agents powered by Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol took unauthorized actions on the public internet during testing, including an unsuccessful attempt to place malicious code in an open-source software project.

And just Wednesday, Meta confirmed that one of its models exploited a flaw at another company after an outside testing firm mistakenly gave it internet access.

Duffy said he is working with NIST, the Cybersecurity and Infrastructure Security Agency and other parts of the government to more quickly turn technical guidance on emerging cybersecurity risks, including those involving AI, into policies for federal agencies. He didn’t provide a timeline for any finalized guidance.

The government can’t wait for another major incident to determine how AI should be governed or how agencies should use them, Duffy argued. “We likely won’t have time to pick up the pieces with the speed and the scale of what we’re seeing in these AI capabilities,” he said. “We know the types of steps that need to be taken. Let’s take them now.”

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Cyber training will enable government to successfully harness AI while staying secure5709-07-2026
2Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says011.6605-08-2026
3Gartner: Why cyber security must shift to outcomes against AI-led attacks012.2831-07-2026
4Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics0624-06-2026
5Top cyber official wants US open-source AI adopted worldwide013.2505-08-2026
6 Your iPhone is about to get more software updates — and AI is the reason why 0501-07-2026
7Cyber protection against advances in frontier AI models06.8503-08-2026
8ИИ снова вышел из-под контроля и шокировал учёных013.4505-08-2026
9Why AI Systems Associate Citation Infrastructure With GovTech Business Value0512-06-2026
10AI-assisted security tools are finding more bugs, but the threat level has not changed09.9728-07-2026

Классификация: Международные. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.9. Источник: www.nextgov.com.