{*}
Add news
March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010 November 2010 December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024 October 2024 November 2024 December 2024 January 2025 February 2025 March 2025 April 2025 May 2025 June 2025 July 2025 August 2025 September 2025 October 2025 November 2025 December 2025 January 2026 February 2026 March 2026 April 2026
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
19
20
21
22
23
24
25
26
27
28
29
30
News Every Day |

Time for government, business leaders to figure out AI cybersecurity regulation

Science & Tech

Time for government, business leaders to figure out AI cybersecurity regulation

Cybersecurity experts Fred Heiding (from left), Josephine Wolff, James Mickens, and Robert Knake.

Photos by Niles Singer/Harvard Staff Photographer

7 min read

Experts say capabilities of agentic AI rising, along with risk to personal data, economy, national security

As new agentic AI models continue to come online, cybersecurity experts laud their ability to sift through vast quantities of data quickly and autonomously — making them great tools to help fight cybercrime.

But, they warn, those attributes could also be put to work by bad actors to hack systems and risk our personal data, our economy, and our national security.

A group of cybersecurity experts were recently brought together for a Berkman Klein Center for Internet and Security discussion, during which all agreed that it’s high time for business and government leaders to regulate the tech — before it’s too late.

Cybercrime, recent data from IBM shows, is rising rapidly. According to a 2026 study, the company found that cyberattacks aimed at public-facing software and systems applications — many of which utilized AI — had a year-over-year increase of 44 percent.

High-profile attacks include the November data breach of Anthropic — the AI company behind the Claude Code assistant. Attackers were able to use their own AI models to scan for weak spots in its source code and publish its inner workings.

“The unfortunate thing is that the bad people only have to win once in some sense, whereas the defenders have to win all the time,” said James Mickens, Gordon McKay Professor of Computer Science. “To me, at least, that’s a concerning aspect of what it means to think about agentic cyber security, attacks and defenses.”

Moreover, cybercriminals have made alarming progress in phishing attacks over recent months, using AI to fine-tune targets and craft messages.

“A year ago, we still had email messages in our inbox that had misspellings that were not colloquial English, that were easy to identify if you were vigilant. Now, all those signals are gone.”

Robert Knake

“A year ago, we still had email messages in our inbox that had misspellings that were not colloquial English, that were easy to identify if you were vigilant. Now, all those signals are gone,” said Robert Knake, panelist and partner at Paladin Capital, a cyber-venture capital group.

Knake also served as the first deputy national cyber director for strategy and budget in the newly created Office of the National Cyber Director at the White House from 2022 to 2023.

In Knake’s view, the federal government needs to start requiring the private sector to take greater steps to prevent attacks that jeopardize consumer and national safety.

 “We’re not at a place where we can say any error in your software that leads to a harm, you need to be responsible for. That will kill off software development,” he said. “But we could create a safe harbor in which we say, if you’ve done … these basic things, like using the most current and known secure version of an open-source package … you should not be held liable for a bad outcome from your software. If you haven’t done them, you should be.”

According to Mickens, this type of regulatory scheme may be easier said than done — especially as the cybersecurity landscape continues to change.

For decades, he said, tech companies like Microsoft and Amazon have included stopgaps in their codes to prevent traditional internal security breaches, without formal government regulation.

“The big difference with AI is that the threat model changes,” Mickens said. “Essentially, there’s some human in a chair that’s outside of the data center who’s sending evil commands to the code that’s running in the data center and otherwise trying to trick it into being evil with AI.”

Any conversation on mandating security measures against outside forces and AI will have to clearly define the liabilities at stake and the types of hardware and software that would ensure compliance he added.

Josephine Wolff, associate dean for research and professor of cybersecurity policy at the Fletcher School at Tufts University, added that regulation could become especially tricky if the private sector is asked to be proactive in finding vulnerabilities across large networks.

“Documentation and inventories are both really important and really hard,” she said. “Can you inventory all of the code that’s running on your computers so that if there’s a vulnerability, if something goes wrong, you can at least know where you need to look?”

But while the liability piece remains murky after online systems are breached, all the panelists agree that companies should not be responsible for retaliation against the hackers. A school of thought in combatting cybercrime argues firms that are hacked may be in a unique position to “hack back.”

“I think that the more actors you have out there in the name of self-defense, intruding on other people’s networks, the less likely you are to de-escalate anything,” Wolff said. “The idea that you’re going to bring in the private sector and have that lead to anything but greater chaos seems hopelessly optimistic to me.”

Moreover, she added, the idea that large companies like Google and Microsoft would make sophisticated surgical strikes to take down small clusters of servers launching denial of service attacks at them is unlikely.

“I think you would have a whole bunch of much crazier firms with many fewer lawyers feeling like, here’s our opportunity to take on North Korea. And that doesn’t seem to me like a safer world.”

Mickens imagines a world in which offloading retaliation efforts to the private sector could also lead to corporations running unmanned agentic firewalls.

“It sees an intrusion, traces the hackers back to London, Berlin, and then does something offensive. I think that world very quickly degenerates into essentially high-frequency trading, except now in cyber security, where you just have a bunch of algorithms going back and forth and reacting to each other in very real time,” he said. “I don’t think we want to get into that world for the same reason that, in general, we don’t want to sort of deputize vigilantes in the physical world.”

And as for combating phishing scams bolstered by AI, the panelists imagine a world, equally obscure at present, that would allow genuine human identities to be verified online.

“This has been a problem in the ecosystem going back 30 years,” Knake said. “I think that the threat of AI just means that we are going to have to know with certainty who we are dealing with, and that it is a real person if they are claiming to be a real person, so that we can trust who you’re engaging with.”

Mickens added that while digital identification could be a viable option to combat cybercrime moving forward, it may hit some roadblocks because of how consumers use the internet.

“One reason digital IDs have traditionally struggled is that there are many scenarios in which someone wants to be identified as part of their identity, but not the full identity,” he said. “For example, if I’m the victim of domestic abuse or I’m a runaway kid or whatever, I may want someone to know I am a human but I don’t want them to actually know my real name. I want the things that I say to be associated with a particular pseudonym consistently, but I don’t want it to be my real name. Those types of practical problems would need to be solved to make some of these proposals real.”

Overall, tech companies and government agencies are facing constant changes in AI capabilities. Along with the changes come both challenges and opportunities to harness technology.

“The ability to have agentic AI essentially sitting over your shoulder, on your phone, on your computer, looking at everything you’re doing and saying this certainly looks like it’s a kill chain for a fraudulent scheme, is there,” Knake said. “We can do this. We just need to find the right market players who will make that investment and build that technology.”

Ria.city






Read also

From Salah to Vinicius: Eight Big Names Who Could Head to Saudi Pro League This Summer 

How Bob Dylan and The Beatles pushed each other to evolve

Video shows teen snatched at bus stop – but victim slips SOS at gas station to escape repeat offender suspect

News, articles, comments, with a minute-by-minute update, now on Today24.pro

Today24.pro — latest news 24/7. You can add your news instantly now — here




Sports today


Новости тенниса


Спорт в России и мире


All sports news today





Sports in Russia today


Новости России


Russian.city



Губернаторы России









Путин в России и мире







Персональные новости
Russian.city





Friends of Today24

Музыкальные новости

Персональные новости