When Anthropic released Mythos, one of the most powerful artificial intelligence (AI) models to date, attention focused on the risks of the breakthrough technology, especially its ability to find and exploit software vulnerabilities. But the same models can also give cyber defenders the upper hand.
Rather than viewing AI solely as a risk, we should also acknowledge its potential to defend American interests and national security. America should rapidly develop and deploy AI to improve cyber resiliency. This means enabling general advanced AI model access for the cyber defenders protecting our nation’s critical infrastructure.
While adversaries can use advanced AI models to reduce the vulnerability exploitation timeline from days to hours, defenders can likewise use AI to discover vulnerabilities quickly and at scale. The results of Anthropic’s Project Glasswing speak for themselves: in just one month, Anthropic and its partners used Mythos to discover more than 10,000 high- or critical-severity vulnerabilities.
According to a recent Cybersecurity Advisory, AI-generated exploits to critical infrastructure are “an active threat.” Although AI may not have been responsible for recent water infrastructure attacks in at least 12 states, it could have helped defend against them. Critical infrastructure entities operate internet-connected operational technology (OT) systems that are often end-of-life, meaning there are no new software updates to protect them because replacement is too expensive. Advanced AI models could have enabled proactive action in response to the FBI’s public service announcement for the water sector about OT devices, released just days prior to the reported attacks. Threat actors can use AI as a sword, but defenders can use it as a shield against known vulnerabilities.
Widespread reliance on open-source software creates an additional imperative for AI as a line of defense, because vulnerabilities in widely used code can affect systems and sectors that rely on the same software. In the long run, AI will also help address persistent challenges with patching timelines, as automated patching technologies can enable cyber defenders to respond to AI-enabled cyberattacks and meet new federal regulatory deadlines.
The U.S. government can take the first step to strengthen cyber resiliency using AI by properly equipping and leveraging the Cybersecurity and Infrastructure Security Agency (CISA). As the nation’s cyber defense agency, CISA is a voluntary partner to the private sector, offering free cybersecurity services and training upon request, issuing guidance and alerts on cyber threats, and serving as a key resource for vulnerability management.
Enabling CISA, in coordination with relevant Sector Risk Management Agencies, to deploy advanced AI for critical infrastructure protection is an opportunity to refocus the agency on its core mission of strengthening cybersecurity and resilience. As CISA evaluates its voluntary structures with the private sector, it should prioritize partnerships that enable access to advanced AI models for the most at-risk critical infrastructure owners and operators, such as water systems and hospitals. This will equip vulnerable entities with the tools and information they need to harden their systems.
CISA’s regional offices would be best suited to offer this service because they are directly embedded in the communities that need help. However, the regional offices have historically been understaffed and underutilized. CISA has an opportunity to change this by using its current hiring spree to place skilled talent where it is most needed. Under-resourced critical infrastructure entities need this assistance because they either cannot afford the models or do not know how to responsibly use them.
Given the high and fluctuating costs of running frontier models, CISA cannot offer advanced AI tools to individual entities indefinitely. But, by partnering with frontier labs, CISA can begin to close that gap and support responsible deployment. CISA and the frontier labs can work to lower costs while building sufficient capability to meet the nation’s economic and national security needs. Frontier labs can also help CISA establish best practices for model use and understand the security parameters of the models it would offer as a service.
Importantly, developing a competitive U.S. open-weight model will be essential to securing critical infrastructure at scale. A U.S. open-weight model would enable operators to deploy advanced cyber defenses affordably while reducing reliance on cheaper but potentially insecure Chinese open-weight models in sensitive American systems.
AI is moving fast, and we have no time to waste before autonomous attacks expose cyber risk at scale–a problem for both the public and private sectors. We cannot wait for our energy grid to go down to start taking cyber threats seriously. Our cyber defenders need AI in their hands, not in review.