A new report from the National Academies of Sciences, Engineering, and Medicine suggests artificial intelligence will fundamentally reshape the cybersecurity landscape, creating both new risks and new defensive capabilities. The rapid expert consultation concludes that frontier AI systems are expanding the capabilities of both cyber attackers and defenders. In the near term, however, AI is likely to favor attackers by lowering the expertise, cost, and time required to carry out sophisticated cyberattacks.
For organizations that manage sensitive research data, intellectual property, or critical laboratory infrastructure, the report's findings highlight the importance of evaluating whether existing cybersecurity practices are prepared for an increasingly AI-enabled threat environment.
Preparing for heightened AI cybersecurity risks
The report emphasizes that AI capabilities are advancing faster than the methods available to evaluate their cybersecurity implications, making organizational risk assessments increasingly complex. In the near term, attackers are expected to use AI to automate vulnerability discovery, develop more convincing phishing campaigns, and accelerate other forms of cyber exploitation.
To strengthen resilience, the report identifies improving software quality, reducing vulnerabilities through timely patching, and increasing coordination and information sharing among organizations as important elements of an effective cybersecurity strategy.
Giovanni Vigna, PhD, director of the AI Institute for Agent-based Cyber Threat Intelligence and Operation at the University of California, Santa Barbara, noted that "cybersecurity will need to improve rapidly to meet this challenge." While the current outlook presents significant challenges, the report concludes that investments in defensive technologies and coordinated security efforts can eventually shift the balance back toward defenders. Delaying cybersecurity improvements could leave organizations more vulnerable as AI-enabled attacks grow more sophisticated.
Building toward continuous, AI-enabled defense
Although the report identifies heightened near-term risks, it presents a more optimistic long-term outlook. As defensive AI technologies mature, organizations may increasingly adopt continuous, automated defense-in-depth strategies that integrate vulnerability discovery, patch management, threat detection, and incident response into an ongoing security process.
Such systems could help security teams identify anomalies more quickly and consistently while allowing cybersecurity professionals to focus on higher-level analysis and complex decision-making.
Paul England, PhD, an independent consultant and co-author of the report, summarized the outlook: "The short-term outlook is concerning, but the longer-term outlook is cautiously optimistic." He noted that reducing the transition period between today's increased vulnerability and tomorrow's more resilient security ecosystem will require sustained investment rather than relying solely on restricting access to advanced AI models.
The report also emphasizes the importance of secure-by-design software development and greater collaboration among government, industry, and academia to improve long-term cybersecurity outcomes.
Implications for laboratory data protection
Although the report addresses cybersecurity broadly rather than laboratories specifically, its findings have important implications for research organizations that rely on connected instruments, digital records, and collaborative research environments.
Laboratory leaders may wish to review institutional cybersecurity policies, evaluate how sensitive research data is protected, and work with information technology teams to assess monitoring, incident detection, and software update practices. Organizations may also consider updating cybersecurity awareness training to address increasingly sophisticated AI-assisted phishing and social engineering attacks.
For laboratories handling proprietary research, clinical information, or other sensitive datasets, maintaining strong cybersecurity practices is increasingly important for protecting scientific operations. By strengthening cybersecurity governance, supporting secure software practices, and coordinating closely with institutional IT teams, laboratory leaders can improve resilience as AI-enabled threats continue to evolve.
This article was created with the assistance of Generative AI and has undergone editorial review before publishing.








