the public’s imagination in 2023, as Americans experienced novel applications such as chatbots
and image generators. AI will almost certainly continue to evolve at a rapid pace in the years to
come, with public and private entities around the world vying for profit and competitive
advantage.
The evolving AI landscape will present cyber defenders with new opportunities to defend critical
infrastructure against malicious activity. The cybersecurity community has a long history of
harnessing the power of machine learning techniques for basic tasks like data processing, email
filtering, and malware identification. New cyber defense tools that integrate AI could eventually
enable cyber defenders to more efficiently detect anomalous network traffic and other adversary
activity, coordinate the defense of complex systems and networks, and augment a cybersecurity
workforce that is already stretched thin.
AI tools may also make our software development ecosystem safer and more secure. While
LLMs have shown some fluency in programming languages, they cannot yet generate
commercially useful secure code without human intervention. Responsible integration of AI
tools into the software development lifecycle may enable developers to identify vulnerabilities in
new code and suggest potential fixes. As AI tools mature, they could be able to make widely
used software products more secure by rewriting existing code into a memory-safe programming
language.
However, realizing the promise of AI also challenges us to manage the risks it poses to
cybersecurity. Today, LLMs can quickly and cheaply generate persuasive and micro-targeted
text, images, audio, and video in different languages. Cybercriminals, hacktivists, and others
with limited resources and technical sophistication may use these capabilities to conduct
phishing campaigns, information operations, and other malicious cyber activity. AI-enabled
surveillance and censorship technologies enable authoritarian regimes to more effectively and
efficiently target journalists, dissidents, and human rights defenders. Without safeguards, AI
technologies may also put Americans’ privacy at risk by making it easier to extract, identify, and
exploit personal data. As the AI ecosystem continues to evolve, there is an opportunity to ensure
that its core elements—data, computing, and algorithms—are developed with safeguards against
misuse.
2024 REPORT
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE
7