Why in the News?
Artificial Intelligence (AI) and cyber threats have merged into a single, compounding security risk that traditional defences cannot contain. AI-powered malware now adapts on its own, autonomous agents undermine established protocols, and the newest models can find and exploit vulnerabilities faster than humans. The deeper conflict is that the technology capable of defending systems is the same technology enabling attacks, while the rules to govern it remain undeveloped.
What is Agentic AI?
- Definition: Agentic AI refers to systems that act autonomously to pursue goals, taking sequential actions with minimal human prompting. It differs from Generative AI, which produces content in response to a user request.
- Significance: Autonomous agents can perform complex tasks once reserved for people. As agentic operations grow more sophisticated, threat levels rise further.
Working
- Perception: Gathers real-time data from tools, screens, or sensors.
- Reasoning: Uses large models to break a big goal into small steps.
- Action: Uses external software or APIs to complete the work.
- Learning: Adapts its future choices based on past results
What is Zero Trust?
- Definition: Zero Trust is a security model that assumes no user or device is trustworthy by default, verifying every access request continuously. It replaces the older assumption that anything inside a network is safe.
- Erosion: Malicious autonomous agents are positioned to undermine Zero Trust protocols. This aggravates insider threat vectors within organisations.
How is AI transforming cyber threats?
- Adaptive malware: AI-powered malware can adapt and evolve in response to its environment. This makes it harder for traditional anti-virus software to detect. Example: Self-Modifying Code: Rewrites internal structures or instructions continuously to change file fingerprints
- Vulnerability discovery: The latest AI systems can detect zero-day vulnerabilities across major operating systems. A zero-day is a software flaw unknown to the vendor and unpatched at the time of attack.
- Capability transfer: Newer AI machines let rogue groups demonstrate capabilities once limited to nation states. This lowers the barrier to sophisticated attacks.
- Dual-use warning: The World Economic Forum warns AI will strengthen cyber defences while also enabling more sophisticated automated attacks. The same model can render current Zero Trust protocols ineffective.
How is AI reshaping warfare?
- Precision targeting: AI-powered smart systems detect, track and predict missile trajectories with high accuracy. This was demonstrated in recent conflicts.
- Autonomous munitions: Systems can independently identify and strike targets. This shifts elements of the kill decision away from human operators.
- Multi-source intelligence: AI can fuse intelligence from photos, text, radio and electromagnetic signals. This denies adversaries a tactical advantage.
- Cognitive core: Automated analytics platforms (such as Palantir Technologies or military software like Ukraine’s Delta) manage vast data inputs to recommend strikes and run logistics.
- Drone accuracy: Software upgrades have pushed first-person view drone hit rates from roughly 30–50% up to 80%.
Where does the deeper tension lie?
- Concentrated power: A handful of Western firms hold the most advanced models and behave as owners of future technology. Control over the mightiest technology is concentrating in a few private hands.
- Governance vacuum: AI has the potential to become the dominant source of military and economic power. The rules to govern it remain in a fledgling state.
- Escalating rivalry: The United States has accused China of stealing from its most advanced language model to build a rival. This reflects the intensity of the US-China technology competition.
What are the challenges to safe AI and cyber governance?
- Hallucinations: Advanced models produce distortions and misleading outputs. Judgments built on them become unreliable and subjective.
- Algorithmic bias: Biases creep into AI-driven decisions, including a bias towards national security framing. Unrestricted reliance on such outputs magnifies risk.
- Algorithmic radicalisation: AI platforms can push opinion makers towards extreme views. Guarding against this requires active oversight.
- Warning-understanding gap: In defence sensing, AI-dictated warnings can outrun proper understanding of reality. Acting on premature warnings carries strategic danger.
- Loss of human control: Increasingly capable models and robots are replacing human roles in critical decisions. Keeping machines under human oversight is becoming harder.
Conclusion
The convergence of AI and cyber capability creates a civilisation-scale threat because the technology that defends systems is the same one that attacks them, and no adequate governance exists. The single most important precondition, human oversight backed by enforceable rules, is missing, and altruism from AI firms is not a substitute for it.
Back2Basics
CERT-In:
- Indian Computer Emergency Response Team is the national nodal agency for cyber security incidents under the Ministry of Electronics and Information Technology.
- Statutory basis: Operates under the Information Technology Act, 2000.
Generative vs Agentic AI
| Generative AI | Agentic AI |
|---|---|
| Creates content (text, images, code, audio) from user prompts. | Performs tasks autonomously to achieve a goal. |
| Responds to instructions but does not independently plan actions. | Plans, reasons, makes decisions, and executes multi-step workflows. |
| Output-focused. | Outcome-focused. |
| Requires frequent human prompts for each step. | Needs minimal human intervention after receiving the objective. |
| Limited memory and action capability. | Can use memory, APIs, tools, and feedback to adapt actions. |
| Example: ChatGPT writing an essay or generating code. | Example: An AI assistant that books travel, compares prices, sends emails, and updates the calendar automatically. |
PYQ Relevance
[UPSC 2022] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.
Linkage: UPSC has examined India’s cyber security architecture and the challenges in developing a comprehensive cyber security strategy. The article shows how AI-powered cyber threats and autonomous agents demand an AI-enabled, adaptive cyber security framework beyond traditional defences.