Cyber war won’t be the same in the age of AI
The writer is the author of Full Stack Spies: Cyber Espionage in the Age of US–China Competition
Last month, the Australian government revealed that AI agents had breached its healthcare systems. A fortnight earlier, Anthropic reported that Russian cyber actors were using AI to perform reconnaissance, hacking and data theft more cheaply and efficiently. These and dozens of other cyber attacks are not yet fully autonomous, but they are beginning to show the cost of delegating control to machines.
For human defenders, autonomous cyber attacks are a perfect storm, clouding an attacker’s intent and complicating the task of holding a human “hand on the keyboard” accountable. But using AI also creates uncertainty for the attacker. The AI will adapt its behaviour based on what it encounters — networks, defences and opportunities — deciding for itself how to pursue a human-provided objective. This behaviour may not always be predictable, and soon may not always be controllable.
Moscow has a tradition of exploiting uncertainty. In 1918, Russian military thinkers incorporated surveillance evasion lessons from the first world war into the broader concept of maskirovka. Deception creates uncertainty in an adversary’s mind about intent and capabilities, delaying, confusing and constraining its response. A century later, this strategy often appears in Russia-linked cyber operations.
Historically, deception was an adversarial act: one side deliberately created uncertainty for the other. But autonomous systems introduce uncertainty in both directions — and not necessarily intentionally. A defender must account for the future behaviour of an autonomous system; an attacker has to weigh the risks of losing control over how a defender might interpret its behaviour.
Maskirovka sought to weaponise uncertainty to exploit a basic logic of deterrence: an adversary is less likely to act when it believes the cost of doing so, including the risk of retaliation, will outweigh the gains. That is no longer a clean calculation. Today, uncertainty can change the willingness to act on both sides. For the attacker, the loss of control has become part of the calculation. A misinterpretation can make escalation harder to contain.
What sort of state (or AI lab) might wish to take that risk? An actor seeking a tightly controlled outcome may not want to offload consequential decisions. But one that values adaptive and persistent access to networks may be willing to accept uncertainty, despite the risk of unintended consequences. Likewise, one with its back to the wall may seek to create room to manoeuvre.
Criminal and state-backed actors are now showing a willingness to trade control for capability, whether for espionage or ransomware. The more autonomy is delegated to AI systems, the harder it may become for defenders to distinguish a machine’s unintended action from escalation and for attackers to control the consequences. Deterrence today must target this trade-off.
Imagine a scenario like the recent cyber attacks on the French defence industry or Polish power grid, but where the operator sets an objective instead of dictating every step. In one network, the AI steals credentials and collects information. In another, it finds a connected system and probes it to help preserve access. A defender watching the second operation cannot see the original instruction, only hostile actors moving deeper into its network. The defender must decide: is this espionage, preparation for sabotage or something else? What is the appropriate response?
The value of deception lies not in hiding the truth indefinitely, but in doing so long enough to compress a defender’s decision-making window. Introducing autonomous systems into the mix changes the old bargain. The deceiver can no longer be certain that the ambiguity it creates will remain on the other side. In a crisis, that could leave both sides scrambling to respond to an action whose meaning neither can discern.