AI makes it impossible to ignore cybersecurity. The use of advanced AI tools for autonomous hacking leads directly to two of cybersecurity’s most intractable problems: the difficulty of getting the private sector to adopt adequate cybersecurity measures and the reluctance to counter foreign actors who can’t be held unaccountable. These are problems of markets and diplomacy that date back to the 1990s.
Mythos and similar AI tools automate the hacking process, speed up the discovery of vulnerabilities or configuration errors, and write code to exploit them. AI tools exploit software errors and weak cyber defense. Since this is automated, there is increased risk of collateral damage if the tool attacks something other than the intended target. Risks that once seemed acceptable have increased. The vulnerabilities that allow exploitation are not new — the means to exploit them are.
AI hacking tools change the informal risk and cost equations that have shaped cybersecurity for decades. Cybersecurity at the firm level is a business decision: companies accept risk rather than spend the cost of defense or insurance, given what they believe is the low probability of unacceptable losses from being hacked. The ubiquity of ransomware has challenged these assumptions, but companies still tend to underestimate the risks given the opaque cyber environment and the immense attack surface presented by the modern digital economy.
There are several steps that can be taken to reduce the success rate of AI hacking, including both conventional cybersecurity techniques and new mechanisms developed for AI tools. But smaller companies and public sector entities already lack the resources for adequate cybersecurity, as evidenced by the recent spate of attacks against water facilities in Michigan and elsewhere.
While major banks, financial institutions, and key infrastructure service providers like large electrical power companies or telecoms can afford and are incentivized to create high-level cyber defenses, less critical or less-resourced sectors are not as prepared. The incentives for many companies and individuals to spend on complex and sometimes imperfect cybersecurity solutions are low.
In an ideal world, AI tools will allow us to address the many unintended vulnerabilities that exist in the software running digital infrastructure. Change will take time, however, and until this occurs, autonomous hacking tools will have countless opportunities to exploit those vulnerabilities. The arrival of quantum decryption in the next 3 to 5 years[JP3] [NP4] will only expand those opportunities.
These problems require both technical and policy solutions, including additional cybersecurity funding that some companies and public sector organizations will be unable to afford. An effective response to the new risks created by AI tools is not just technical. It must include a mix of tax incentives, regulation, insurance requirements, procurement policies, and investment in research — perhaps outlined in a new national cyber security strategy.
We must also contend with the presence of hostile foreign actors, either criminal actors operating from sanctuaries like Russia or state actors like China, who will not be deterred from cyber-attacks and can use new AI tools to boost their efforts. Geopolitical rivalries and western political indecision have thwarted efforts to dissuade foreign opponents from engaging in cyber-attacks or encourage them to enforce laws against cyber criminals. Like companies, countries also make decisions about risk, and in an international environment where the penalties for hacking are negligible and have been for decades, there is little incentive to stop.
This is a long-standing problem, but it is not a technological problem. It is a foreign policy problem. AI will not change the politics of international negotiation. This limits the value of solutions like AI guardrails in the same way that cyber security norms have had limited value — potential attackers ignore them.
AI safety negotiations will face the same set of problems seen in cybersecurity and arms control negotiations. All nations will use AI, but only a few will militarize it.
It is possible that bilateral discussions on AI safety between the US and China could ultimately improve stability and reduce risk. Bilateral discussions are scheduled for September. The UN has also begun a series of discussion processes to address AI risk. If cybersecurity or arms control negotiations are precedents, it will take years to arrive at a meaningful agreement.
China could, as it has done in other instances, agree to the outcome of negotiations but not actually treat them as binding. This requires that accountability procedures be part of any multilateral agreement. We can modify Ronald Reagan’s statement to fit the situation and say, “distrust and verify,” as a more appropriate motto for international AI rules. Ultimately, this requires that countries have the political will to insist on accountability and impose consequences. So far, that has been lacking.
These problems have existed since the dawn of the Internet. AI tools do not immediately change the risk versus cost equations, and while international negotiation can bound the problem of misuse, it cannot prevent it. Without more attention to cyber-defense, the situation will get worse. The most interesting thing about AI and cybersecurity is that it may finally force countries and companies to do things that they should have done long ago.
Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Tech 2030
A Roadmap for Europe-US Tech Cooperation