27 July 2026

How the U.S. Can Survive a Large-Scale AI Cyberattack

Center for Strategic and International Studies | Andrew Faulhaber

Anthropic’s decision to withhold its Claude Mythos frontier artificial intelligence model due to its 73 percent success rate in expert hacking simulations exposes the growing threat of automated, large-scale cyberattacks against United States critical infrastructure. A coordinated strike on these 16 critical sectors could paralyze power grids, financial systems, and emergency services.

To mitigate these vulnerabilities, the Cybersecurity and Infrastructure Security Agency acts as the national coordinator, yet it lacks the authoritative command to direct other federal entities during a crisis. Establishing a physical operations center for the Cyber Unified Coordination Group would bridge this leadership gap, enabling real-time cyber threat intelligence sharing between the military, civilian agencies, and private operators who own most domestic infrastructure. Furthermore, expanding initiatives like CISA's Cyber Storm exercises and Anthropic's Project Glasswing will incentivize private sector defense, securing critical networks before offensive AI capabilities are fully weaponized by adversaries.

Comment
The structural limitation of the Cybersecurity and Infrastructure Security Agency as a coordinator rather than a directive authority exposes a fundamental vulnerability in American domestic cyber command and control. Informal coordination forums like the Cyber Unified Coordination Group introduce critical latency. Without empowering CISA with the statutory authority to issue binding directives to the Department of Energy and private utilities, the operational response to a grid-scale attack risks fragmentation. This friction between CISA and sector risk management agencies ensures that technical remediation cannot keep pace with the speed of machine-generated exploits.

No comments: