"The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge?" Jessica Ji and Andrew Lohn write, and their argument frames a debate that has moved from hypothetical to immediate in 2026.
AI-powered cyberattacks in 2026: a pivotal window
According to Ji and Lohn, 2026 has become the year when long-held predictions about AI-enabled cyberattacks are beginning to materialize. New models now possess capabilities "on par with the best human hackers," creating what the authors call a pivotal window of opportunity and risk. That convergence of advanced AI and persistent cyber vulnerability is straining American cybersecurity infrastructure and forcing a reassessment of who must lead the response.
Export controls on Anthropic’s Mythos and Fable were temporary
The authors document a recent federal effort to control access to models with powerful cybersecurity capabilities — specifically, export controls on Anthropic’s Mythos and Fable models and the subsequent revocation of those controls. Ji and Lohn argue that such restrictions can only be temporary: as with prior model generations, other companies will soon reach comparable capability levels and make them widely available, undercutting the efficacy of block-and-delay approaches.
Open-weight models: GPT-5.5 and Z.ai’s GLM-5.2
Competition among model developers has accelerated. The authors note that OpenAI was "already hot on Anthropic’s heels with its GPT-5.5 model." They also report that Chinese lab Z.ai released an open-weight GLM-5.2 model; early research cited in the piece suggests GLM-5.2 "may be on par with Anthropic and OpenAI’s latest models when it comes to cybersecurity." The result, Ji and Lohn say, is that "controlling AI is nearly impossible when foreign companies race to build more powerful models and release them publicly," because anyone with sufficient compute can adapt these models for offensive use.
CISA funding cuts, redistributed authorities, and the corporate fill-in
Ji and Lohn trace a key part of the problem to changes in federal resourcing: the federal government "cut resources to key agencies like CISA and redistributed their authorities." That shift, they argue, left a gap that AI companies have begun to fill — not because they were meant to replace public institutions, but because the technical capability and incentives exist to act. Examples cited include Anthropic’s Project Glasswing and OpenAI’s Patch the Planet initiative, both described as efforts to shore up critical infrastructure providers and open-source software libraries.
But the authors caution that corporate incentives differ from public ones. AI firms "have some incentives to invest in defense" — such as reputational benefits and protecting supply chains they rely upon — yet those incentives are limited: companies are "incentivized to limit liability and blowback associated with irresponsible corporate behavior, not to secure the nation or its citizens." In short, corporate action can help, but cannot substitute for a grounded, government-led response.
What this means for AI companies, critical infrastructure owners, and the federal government
- AI companies: They can use advanced models to find vulnerabilities and write patches, and some have publicly committed to improving U.S. cyber defense. Still, Ji and Lohn say these firms "are only positioned to help with one part of a very large problem" and should not be expected to coordinate national cyber defense.
- Critical infrastructure owners and operators: Many of the most urgent fixes "have nothing to do with AI" — the problem is ensuring patches actually work and deploying them to fragile, understaffed systems that must run continuously without interruption.
- The federal government: Historically the "information clearinghouse" — receiving intelligence, issuing guidance, and leading response and recovery — the government should retain that role, the authors argue. They warn the government has so far "only reacted to AI and cyberthreats instead of planning ahead."
Practical fixes the authors press for
Ji and Lohn lay out concrete defensive priorities: measure exposure to attack, test how systems perform under attack, and shorten recovery times. They emphasize that stopping model releases is a short-term maneuver; the long-term fix is investment in defense and a return to a government-led architecture for receiving intelligence, issuing guidance, coordinating response, and managing recovery.
The clocklike language in the piece is deliberate: "Everyone sees the threat coming — the question is whether or not we have the will to do anything about it before it’s too late," Ji and Lohn conclude. The policy calculus they describe is stark — blocking individual models buys time, not security; rebuilding defenses and restoring government capacity are the tasks that will determine whether that time is used wisely.




