Website copyright © 2002-2025 by Dennis D. McDonald. From Alexandria, Virginia I support proposal writing & management, content and business development, market research, and strategic planning. I also practice and support cursive handwriting. My email: ddmcd@ddmcd.com. My bio: here.

On Reading the National Academy's "Implications of Recent Advancements in Artificial Intelligence for Cybersecurity"

On Reading the National Academy's "Implications of Recent Advancements in Artificial Intelligence for Cybersecurity"

By Dennis D. McDonald

I’m reading the National Academies’ 2026 report Implications of Recent Advancements in Artificial Intelligence for Cybersecurity. I’m especially interested in what it says about the governance challenges associated with AI-supported cybersecurity attacks and society’s short-term inability to completely resist them.

According to the report, a major challenge is caused by “asymmetry”: organizations need to defend against all possible angles of attack, while AI-supported cybersecurity attacks need only find a single vulnerability and then pile on additional attacks against it.

The implications for needing “across the board” defenses are profound. Any organization’s unified governance of data, AI, and cybersecurity requires a framework consisting of three things:

  1. Decision-making bodies.

  2. Decision-making rules and procedures.

  3. Mechanisms to ensure compliance with those rules.

Unfortunately, the speed with which AI-based cybersecurity attacks can learn, adapt, and attack again is a major reason why traditional organizational models may have difficulty keeping up with cybersecurity policies, processes, and systems.

According to the authors of this National Academies report, AI tools must themselves be adopted and managed as an integral part of cybersecurity defense.

What is the likelihood that organizations will be able to pursue unified and coherent responses to AI-based cybersecurity attacks if they enlist AI tools as part of the team?

I’ll be looking for clues to how to answer that question as I read through the report, then I’ll report back.

Copyright © 2026 by Dennis D. McDonald

Addendum 7/22/26: SOCIAL ENGINEERING AND SYNTHETIC IDENTITY

I'm working my way through a close reading of the National Academies’ 2026 report "Implications of Recent Advancements in Artificial Intelligence for Cybersecurity" and will be publishing an analysis of it on my website www.ddmcd.com. I’m especially interested in what it says about the governance challenges associated with AI-supported cybersecurity attacks and society’s short-term inability to resist them. Here's an early draft of a section of my forthcoming article titled "Social Engineering and Synthetic Identity":

"AI systems can generate realistic personas that look, act, and talk like real people. Adversaries can use these systems to mimic real people in real time. This places stress on the responding organization to verify identity.
According to the National Academies report, one approach to protecting against such AI-based mimicry—which has become commonplace as a plot element in science-fiction media—is to require the labeling (e.g., watermarking)  of AI-generated content.

That requirement obviously would not protect against adversarial sources using AI deceptively. The report therefore suggests that verification and trust efforts focus on including authenticating the source associated with a message, regardless of whether the message itself is AI-generated.

The report also suggests that the security and authentication procedures surrounding high-value transactions need to be reworked to provide more resilient defenses against AI-based impersonation of participants.

Involving AI to help guard against and respond to such attacks reminds me of the old side-by-side authentication procedures used in Minuteman nuclear missile silos. There, a group of humans could make a major life-and-death decision—launching a missile armed with a nuclear warhead—only by following a detailed set of rules. Those rules included not only verification of the source of the launch order, but also a series of coordinated steps requiring both verification and trust to proceed to an actual launch.

Following this step-by-step model might involve keeping both humans and AI “in the loop” when making a decision in which an external adversary attempts to exert control through an AI-based agent. Such a situation could trigger an explicit, step-by-step handoff of responsibilities between humans and AI, structured—ideally--so that human authority and accountability are always maintained."

(The above is followed by a more explicit discussion of the organizational implications of governing how AI is used in defending against AI-aided cybersecurity attacks. Let me know by email if you would like to know when this is published.)

Science Communication, Truth, and the New Media Challenge

Science Communication, Truth, and the New Media Challenge

Is the Trump Administration Playing Whack-a-Mole with Scientific Communication?

Is the Trump Administration Playing Whack-a-Mole with Scientific Communication?