Executive SummaryThe cyber domain touches nearly all systems and aspects of society, so any changes tothe relative offense-defense balance in cyber could be very impactful. As a digitaltechnology, AI can be expected to have a more direct effect onthose balances than inother domains.To assess how AI may affect the offense-defense balance within cyber, we collectedarguments for an offensive or defensive bias in various aspects of cyber operations aswell as arguments for what gives cyber its unique character. We then considered howvarying levels of AI advancement might strengthen, weaken, or alter those arguments.The results of that analysis are grouped into five categories: Changes to the DigitalEcosystem, Hardening Digital Environments, Tactical Aspects of Digital Engagements,Incentives and Opportunities, and Strategic Effects on Conflict and Crisis.There is no single answer to the question of whether AI will make cyber offense ordefense dominant. Cyber attackers and defenders have too many different goals thatcan be achieved in multiple ways, but AI is likely to change the cyber landscape inways that can be predicted and perhaps controlled to some extent.Although AI will increase the scope of defensive tasks by making the digital ecosystemlarger and more complex, it may also reduce the scope of defensive tasks in otherways,such as by decreasing the number of network connections to monitor. AIsystems could replace known human weaknesses, but AI components are oftenvulnerable. AI components could also aggregate too much information or control intohigh-risk digital targets,and eliminating manual controls could reduce resilience duringattacks. As system designers, acquisition officials, and users incorporate or implementAI, they will decide how much risk to accept along each of these lines.AI also promises to further harden digital environments by performing tasks thatcurrently overwhelm defenders. If these taskscan be done reliablyby AIand ifdefenders cankeep up with fasterdiscoveries of new vulnerabilities andattack tactics,then defenders can take advantage of their ability toimpose delays and frictionstogain more from AI than attackers. Doing so could prevent AI from enticing new threatactors and could limit the strategic benefits that aggressors might see from AI’sincrease in speed and scale. But that defensive advantage is far from guaranteed andthere are several missteps that could push the balance toward offense insteadofdefensein the years to come. Center for Security and Emerging Technology |1 Table of ContentsExecutive Summary................................................................................................................................1Table of Contents...................................................................................................................................2Introduction...............................................................................................................................................3Changes to the Digital Ecosystem....................................................................................................4Hardening Digital Environments........................................................................................................5Tactical Aspects of Digital Engagements.......................................................................................5Incentives and Opportunities..............................................................................................................6Strategic Effects on Conflict and Crisis............................................................................................6Recommendations..................................................................................................................................7Incentivize Reliability Over Originality.........................................................................................7Fund Provable Security.....................................................................................................................8Fund Live Patching.............................................................................................................................8Establish and Maintain Standards for Security and Reliability of AI Systems................8Maintain the Option for Human Control.....................................................................................9Assess Compilation and Aggregation Risks..............................................................................9Enable Air-Gapping and Reduced Connectivity.......................................................................9Design Systems to Enhance Defensive Advantage................................................................9Practice AI-Induced Cyber Emergencies..................................................................................10Conclusion.....................................................................