24 September 2026

AI and the Future of National Security: Findings from a survey of 100+ national security practitioners on the opportunities and risks of advanced AI deployment in military, cybersecurity, intelligence, and CBRN

Institute for Security and Technology | Mariami Tkeshelashvili, Ritika Verma

The Institute for Security and Technology has released a landmark survey of 111 national security experts warning that adversarial AI misuse and automated disinformation represent the most critical threats to United States national security. These findings reveal deep institutional unreadiness across federal agencies to counter rapid technological escalation.

Respondents, representing the Department of Defense, State Department, and the Intelligence Community, emphasize that defensive vulnerabilities stem primarily from sluggish bureaucratic response times and outdated legal frameworks rather than technical limitations. AI offers significant opportunities to accelerate scientific discovery and bolster cyber defence capabilities. However, integration risks remain high. Over ninety percent of surveyed practitioners have actively engaged with international AI policy, yet coordination gaps persist. Institutional inertia hinders rapid adaptation. Consequently, the slow pace of policy formulation leaves critical infrastructure vulnerable to automated exploitation. Ultimately, the gap between technological advancement and regulatory oversight creates a strategic vulnerability that adversaries are poised to exploit.

Comment

The findings of the AI Risk Barometer expose a critical disconnect between technological capability and institutional agility within the Department of Defense. While advanced machine learning models offer unprecedented speed in processing intelligence, bureaucratic friction limits their deployment. This lag creates a window of vulnerability that adversaries can exploit through automated cyber operations.

Specifically, the acquisition cycle of the Department of Defense remains structured for hardware procurement rather than continuous software iteration. This structural mismatch prevents the rapid integration of real-time security patches required to defend against automated malware. Consequently, the Defense Information Systems Agency faces persistent difficulties in securing legacy networks against dynamic, AI-driven threats.

Strategic Question for Discussion
If the Department of Defense acquisition cycle remains optimized for hardware, what happens to the viability of the Defense Information Systems Agency's network defense when facing rapidly evolving, AI-driven malware?
The current trajectory indicates that legacy network security will become increasingly untenable, forcing a shift toward zero-trust architectures. My assessment is that without a fundamental overhaul of software procurement pathways, the Defense Information Systems Agency will remain perpetually behind the patch cycle of automated threats. This gap suggests that defensive posture will rely more on isolation of compromised systems than on active prevention.
Share your assessment in the comments below.