We urgently need a coherent national AI cybersecurity policy

paulpauper1 pts0 comments

We urgently need a coherent national AI cybersecurity policy

Joshua Saxe

SubscribeSign in

We urgently need a coherent national AI cybersecurity policy<br>Policy should stop treating model launches as the main risk object. Rather, it should measure and shape the entire attacker–defender ecosystem.

Joshua Saxe<br>Aug 13, 2026

10

Share

This Substack post adapted from my AI Security Forum 2026 keynote which I gave last week in Las Vegas · Source deck: aisf_2026.pptx

We’ll soon be in a world full of cheap security agents that can automate much of the kill chains our adversaries currently execute manually. These agents will also be indispensable to defenders. Overall, we can expect a lot more instability and risk in the cybersecurity ecosystem, which had already been poorly managed with rising damages costing close to 1% of global GDP.<br>Government policy will need to help society navigate this transition. But unfortunately, the basic framing of today’s AI security policy is wrong from first principles and woefully anemic.<br>I came to this view after working on frontier model launches, open cybersecurity model evals, and attending lots of AI security policy meetings while working at Meta; and now while building AI-native cyber defense at the startup I cofounded, Abundant Security.<br>What follows is a critique and then a directional proposal around where I think US AI cybersecurity policy needs to go.<br>Ecosystem level harms and benefits, not model launch risk, should become the main object of AI security policy

The dominant policy frame today is pretty simple; test a model for “dangerous dual-use cyber capabilities” and if a threshold is crossed, block the launch or request that the model be more heavily guardrailed. We saw this with the Claude Fable and GPT 5.6 launches, for example.<br>Actually (and obviously) models’ dual-use cyber capabilities are not the direct cause of cyber harms. Cyber harms depend on attackers’ goals, capabilities, how quickly they adopt AI at all assuming it furthers their goals, what defenses defenders have deployed, how quickly defenders are adopting dual-use AI capabilities assuming these are their priority, and the like. It’s a complex picture that requires a combination of human, economic, and technical intelligence.<br>The main object of AI security policy should be to understand this picture and figure out how to minimize overall net harms given AI’s affordances for both attackers, defenders, and victims given surveillance information about both groups. See below for an estimate of overall cyber damages over the past few decades; these damages are enormous and haven’t been perturbed by individual model launches over the past 4 years; the relationship between AI and net damages is complex!

Current policy biases irrationally towards AI’s benefits for attackers

It’s widely known that most (and arguably all) AI cybersecurity capabilities are useful to both defenders and attackers. But today’s AI security policy is implicitly biased towards treating AI cybersecurity capabilities as risking benefitting attackers. This is problematic because, in fact, it’s plausible and even likely that AI is currently benefitting defenders more than attackers. For example, AI been ubiquitously adopted in phishing defense:

And AI has proven miraculous for defenders in finding and fixing security vulnerabilities in code:

AI is widely used in phishing attacks today, but it’s not clear how large its causal role in increased phishing-related damages is. We haven’t seen a meaningful uptick in vulnerability exploitation derived economic damages due to attackers use of AI, but this doesn’t mean that nation states won’t use AI to assemble war-chests of cyber weapons they could use in the event of a conflict.<br>Overall, it’s an open, empirical question whether AI is benefitting attackers more than defenders in phishing, or in vulnerability finding and exploitation, but what concerns me is that federal AI cybersecurity policy isn’t spending the resources to answer these questions empirically and base policy off of those signals.<br>Build an AI cybersecurity observatory

In contrast to the anemic model in which federal policy focuses on gating model launches based on how cyber-capable they are, we need a policy that focuses on surveilling the entire national cybersecurity attacker, defender, and victim ecosystem and recommending nuanced choices across a much broader menu of policy options. An AI cybersecurity observatory — robust and well resourced — would be a way to achieve this (I try to depict this below):

The safety observatory would assemble the information feeds necessary to robustly understand how a given regulation, subsidy, federal cybersecurity hardening program, model launch delay, or any of a multitude of other possible intervention would affect the national and global cybersecurity ecosystem.<br>Then it would recommend policies based on these signals. I fantasize about what that full picture would look like...

policy cybersecurity model security defenders cyber

Related Articles