AI and Cybersecurity: Anticipating Today to Master Tomorrow

Against the backdrop of debates surrounding the release of ‘Mythos’, Anthropic's latest model, and its potential in terms of capabilities in the field of cybersecurity, the Council is publishing a short note setting out its initial thoughts on the subject.

Read the note


AI is agnostic with regard to cybersecurity 

The impact of AI on the security of information systems is threefold, as ANSSI points out: 

  • The cybersecurity of AI: like all information systems, AI systems may come under attack and must therefore guard against it.
  • Cybersecurity through AI: AI tools enhance the capabilities of defenders, particularly with regard to detection.
  • Cybersecurity in the face of AI: attackers are already using AI, thereby gaining in effectiveness and speed. 

Artificial intelligence (AI) is a technology used by attackers and defenders alike. Whilst it is still too early to say whether this technology will benefit one side more than the other, certain common-sense observations are worth making:

  • Harnessing AI to ensure compliance: those actors, public and private alike, who fail to make the ongoing effort to understand and integrate these new uses will quickly be left behind.
  • Keeping humans in the loop at key stages: whilst AI constitutes a valuable aid for developing, correcting, and testing software, dispensing entirely and immediately with human expertise would appear to be a guarantee of failure.
  • Anticipating new vulnerabilities and deploying patches accordingly presents a considerable challenge, at a time when many actors are already stretched to capacity.
     
A new ‘sovereignty dilemma’?

Whilst they must harness these tools to make the most of them, actors will probably be confronted with difficult trade-offs between performance and strategic autonomy. 

Furthermore, the exclusive provision of Mythos to a handful of actors, almost all of them American, raises with great acuity the question of French and European capabilities in the evaluation of AI models.
 

Initial operational avenues 

Against this backdrop, the CIANum calls in particular for:

  • actors not to give in to the surrounding panic, but rather to consider AI governance and security frameworks from the moment solutions are adopted. In the short term, enterprises could envisage the creation of a permanent function dedicated to the autonomous discovery, qualification, and remediation of vulnerabilities, as an extension of the ‘DevOps’ method;
  • the implementation of general frameworks which, although not specifically designed for AI, remain entirely apposite, such as the one associated with the European NIS2 Directive;
  • the accelerated structuring of a European public-private ecosystem for the evaluation of AI models around the French National Institute for the Evaluation and Security of AI (INESIA) and leading-edge AI laboratories in Europe.


Read the note