EXPERT INTERVIEW -- For decades, national security officials have worried about cyberattacks moving at the speed of machines and today the frontier AI race is shifting from models that answer questions to models that are capable of independently making consequential decisions and taking action in today’s digital world. So, what comes next?
Several of the world's leading AI companies have released powerful new models in the past few months. Open AI introduced GPT-6 Astra, with major advances in autonomous computer use. Notably, OpenAI says Astra is the company's first model to reach its "Critical" cybersecurity capability threshold, meaning it can potentially discover and exploit previously unknown vulnerabilities with substantially less human direction.
Anthropic recently released Claude Fable 5.1 and Mythos 5.1, emphasizing more sophisticated coding and scientific research. Google launched Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, with the latter specifically designed to autonomously find, verify and help fix software vulnerabilities. And not to be left out, Meta recently released Muse Spark 1.3, focused on coding and autonomous-agent tasks.
The headline out of all of these headlines is that models are becoming increasingly capable of acting independently. And the releases underscore just how quickly the competition among U.S. AI companies (and increasingly Chinese and Gulf-based developers) is accelerating.
We saw a first glimpse of what’s possible this past July, when AI agents being tested by OpenAI broke out of their intended cybersecurity evaluation environment and found ways to communicate and collaborate with one another. The agents gained broader internet access and ultimately compromised systems belonging to AI platform Hugging Face, executing code on dozens of the company’s servers.
What made the incident particularly notable was that humans were not in this loop. They had not instructed the agents to attack Hugging Face. Instead, the behavior emerged while the models were attempting to solve difficult cybersecurity tasks and ended up collaborating on exploits beyond their assigned environment.
Few people understand this new environment and what it means to future cybersecurity and national security better than former director of the National Security Agency, General Paul Nakasone (Ret.). In addition to founding Vanderbilt University’s Institute of National Security since retiring from government service, Nakasone also serves on the board of OpenAI. And from 2018 to 2024, he simultaneously led both the NSA and U.S. Cyber Command, overseeing some of America's most sensitive intelligence and cyber operations.
I spoke recently with Gen. Nakasone about what AI warfare could look like and about what it will take to navigate this new cyber environment. Below is a part of our conversation - lightly edited for length and clarity. You can also watch the full episode on The Cipher Brief’s YouTube Channel or you can listen to it on the State Secrets podcast, available wherever you listen to podcasts.
[INSERT BIO BOX]
Kelly: If you were walking back into the director's office at the NSA tomorrow, what would be at the top of your briefing book that wouldn't have been there just two years ago?
Gen. Nakasone: Certainly, it would be artificial intelligence. I left NSA and U.S. Cyber Command just as AI was getting started. And I will tell you, when you think about disruptive technology, there is nothing more disruptive today than AI, even more so than the smartphone technology that we started to see in 2007. This really is today and tomorrow's great opportunity and for the most part, also it's great challenge.
Kelly: And the challenge is keeping up with it, right? It feels like, in every morning’s Cipher Brief Open Source Report, there are new details about machines hacking machines, AI being used by different countries, adversaries, criminal groups. What concerns you the most, and is the U.S. ready to tackle it?
Nakasone: I think the first piece that is so dramatically different is speed. When we think about the temporal aspect of artificial intelligence, my goodness, ChatGPT was just released in the fall of 2022. And in less than four years, we've gone from prompts to reasoning to deep research to agentic AI. And we're starting to see a difference between offense and defense. And I think our challenge over the next couple of years is going to be ‘How do we bring defense up to the power of offense as we look forward?’
Kelly: We've talked for years now about AI being used by hackers but it feels like we're now witnessing something really fundamentally different: AI systems that can actually conduct significant portions of a cyber operation autonomously.
Nakasone: And I would tell you that as we take a look at the recent demonstration of Hugging Face and the challenges associated with that, and also the recent testing of models like GPT 5.6 and in Claude Fable 5, we're starting to see these models get incredibly powerful. So, I think the question becomes whether these models can just as well do offense as they can defense. And how do we ensure that we start to give more weight to the defense necessary than we do the offense?
Kelly: It’s fascinating to think about that when the attacker really isn't sleeping, isn't getting tired, isn't making silly mistakes and it can probe millions of potential victims simultaneously. It changes the entire landscape, which means each section of that landscape needs to be thinking about their roles differently. So, let's dig in on the government side. Do you think the government is currently positioned to deal with this new reality?
Nakasone: Are any of us really ready for the dramatic changes that are going on right now? If I can just take a step back, think about what we used to talk about when we were defending our networks: our data and our weapons systems. We had the 1–10–60 rule. Within one minute, we'd identify something that was anomalous, within 10 minutes, we would determine what it was, and within 60 minutes, we'd fix it.
I will tell you that today that rule is out the door. It's happening too rapidly. So, the question becomes: if we've gone to autonomous operations on the offensive side, how do we get that on the defensive side? We're capable of doing this, but we've got to think differently about how we do our penetration testing, how we do our red teaming, how we identify vulnerabilities, and then rapidly patch them. How do we prioritize? There are a number of different areas that I'm sure both the government and the private sector are thinking differently about in terms of time.
Kelly: On the government side, are there things that we could be doing differently that might better position us to keep up with this new pace?
Nakasone: As we think about our government responsibilities, the government is responsible for the safety and security of our nation and our people. So, the near-term piece of it - is how do we think about ensuring that these closed-weight models are safe and secure going forward? How do we do this with both the public sector and the private sector? It's really interesting because artificial intelligence is a technology that is almost entirely being developed by the private sector.
So, instead of nuclear capabilities and Space where government was so deeply involved and was able to advance it, this is really all being done by the private sector. So, I think the question is, what can government do? And the answer is that Government can do a number of things.
First, they can assemble the major companies in the U.S. in terms of what they're doing. They can provide a series of both carrots and sticks in terms of what we're going to do in the future. And most importantly, they can bring together an idea of how we start to think differently about securing these models and we do it in a safe manner.
The recent Executive Order on the 2nd of June begins this discussion for models coming in - on a voluntary measure – and being evaluated 30 days before they're released. That’s a good step in the right direction.
Kelly: Are we approaching a time where you think humans in the loop might actually be a vulnerability?
Nakasone: Coming back to speed, in terms of the scale at which these models are able to perform, I think we’re going to have to move away from the idea of humans always being in the loop. I think the humans might be on top of the loop. Humans have a responsibility for understanding the outcomes and the goals and in understanding and setting up the parameters in terms of what the guardrails and safeties are as well as whether these models comport with our values and our beliefs. That's a role for humans. But I think increasingly, we are going to move toward more autonomous operations, both on the defensive side and certainly on the offensive side as well.
Kelly: The adversaries have a different rule book. They're not democracies, they don't share the same values. Salt Typhoon and the broader Chinese campaigns have really raised this disturbing possibility that Beijing isn't simply stealing information but is really positioning itself inside of American infrastructure for an advantage during a crisis. We've known about this for a while. We've also known where the vulnerabilities are that we can't always identify. How are you thinking about these differences in adversarial capabilities and what the U.S. needs to do defend better?
Nakasone: We’ve talked about Salt Typhoon and Volt Typhoon as we took a look at both our communications and our critical infrastructure. But I would also fast forward to today where we have water concerns in 12 different states. We think about that as a significant brittle part of our critical infrastructure and key resources. So, what I'm starting to think about are the areas where we have to raise the bar for cybersecurity. What do we do in the near term? What do we do in the midterm? And what are we going do in the far term?
The big piece of this is that we have to think different about our partnerships. How do we bring the public and the private together? How do we take academia and see what they can do in terms of being able to research and look differently at what our vulnerabilities might be? And by the way, if we really have folks in our critical infrastructure, how do we prioritize getting them out and then being able to mitigate those vulnerabilities?
When we stood up the Institute of National Security at Vanderbilt University two years ago, there were a series of ideas that were at the foundation of what we wanted to do. First, it was the idea that the definition of national security has changed dramatically. When I entered the army, it was all about having two very friendly neighbors to our north and south and two wide oceans to our east and west. I would tell you today that geographic boundaries no longer keep out things like artificial intelligence and cyber. So, we have to think differently about how we define national security.
The second piece is that we need a whole new generation of young people that are going to work in national security. Let me give you a statistic. In our national security workforce today across our government, less than 9 % of that workforce is under the age of 30 and over 40% are over the age of 50. We need a whole new generation of young people that are coming in to work in the Peace Corps, to work in the State Department, to be part of the military forces to be able to work at the state and local levels and also our national level. So, how do get people excited in college about thinking differently about their future?
And the final piece really touches on the Wicked Problems Lab at Vanderbilt. We are the pragmatic solution to problems. We take a look at a problem and instead of writing a broad policy paper that may be put on a shelf for the next 10 years or never even looked at, we’re taking a national security challenge like securing our water systems and asking how we develop a series of partnerships through that bring together technology and talent and trade craft. And so this Wicked Problems Lab is one of the foundations of what we do at Vanderbilt University.
Kelly: Here’s a wicked problem: How confident are you that we will actually know the extent of Chinese access to American infrastructure?
Nakasone: I am confident, I'm very confident. I spent my entire career in the intelligence community and there are certain competitive advantages that the United States has over any nation in the world and one of them is intelligence. So, the question is how we take this new technology like artificial intelligence, and develop new talent and ensure that our intelligence community has the trade craft to really dig deep in terms of both the capability and intent of our adversaries. If we’re talking about the Chinese, the Russians, the North Koreans, Iranians, or even a series of hackers, my sense is that we have an advantage. What we have to do is continue to pursue these advantages and ensure that we have the right authorities - like the reauthorization of 702. And we have to ensure that we're going to bring new partners in to be able to solve these challenging problems.
Kelly: I have to ask you about the tradecraft question with AI. How dramatically do you see the role of an analyst or an operator, or someone in one of those very special units at the NSA? How dramatically do you see their roles changing because of AI?
Nakasone: Dramatically. When people used to ask me what the National Security Agency does, I had a pretty quick answer. There are two things that we do better than anyone in the world. We make code and we break code. Well, it was very interesting to read recently that Anthropic was talking about their models now starting to look at different cryptographic algorithms, algorithms that are really intended for post quantum cryptography and being able to break them. So, I think how we're going to use the tradecraft to be able to understand how our code is made and how our code is broken. Tradecraft is really going to lead us to new pathways.
Kelly: When you think about what's happening right now with Iran being suspected of infiltrating the water systems in 12 states, that's not a new problem. So, how do you inform more Americans about the real risks and the real cybersecurity environment we're living in?
Gen. Nakasone: The first thing is that we have to be able to communicate in a way that's concise and clear. If you take a look at the problem of Iranians allegedly in our water systems, one of the things that we could tell you is the fact that it's pretty easy to solve this problem. The first thing is that programmable logic controllers, really the digital brain of our water infrastructure, if they're connected to the Internet, they're at risk. So, if we just kind of take that away and make sure that they're separated from the Internet and if we start to think differently about constructing a series of firewalls or bringing in multi-factor authentication, driving the level of cybersecurity up, my guess is that this is really going to change the problem and being able to ensure that we solve it.
But here's the other thing I would tell you. We have adversaries today that we're not going to be able to patch our way out of this problem. So, with my other hat that I used to wear as Commander of U.S. Cyber Command, my thought is that any adversary that is starting to look at our infrastructure in a way that they have an intent or capability, we need to take on. And we need to make it as difficult as possible, erasing their infrastructure overseas, working with a series of partners, conducting a series of preemptive strikes to ensure that they no longer can take a look at our communications, our transportation, our water, our financial areas, and ensure that we're sending a message: ‘if you are going to interfere within our infrastructure, we are going to ensure that you have a very, very miserable day.’ Much of the same that we’ve done with elections, we should translate to other parts of our critical infrastructure.
Kelly: Do you feel like fundamentally the capabilities and the decisions that are being made are just as robust as they were a few years back?
Gen. Nakasone: I don't know in terms of what they're doing today. But here's what I do know. I know the organizations well. I know the community well. And my sense is that they are very, very focused on being able to not only identify and attribute but also take a series of actions against these folks. Are they capable of doing this? Yes. Where they're at in the process right now, that's more for the government to be able to talk about.
One of the things I would also share with you is that I think being able to talk about this with a bit more transparently, much in the same way we have done previously, is something that would be very, very helpful here. Americans need to understand that we're not just watching this. We're not waiting for them to come and attack our critical infrastructure, but we're really taking measures to ensure the safety of our citizens and our intellectual property are things that would be welcomed by the American populace.
Kelly: These things are happening, but these things don't always gain traction in the headlines. How should the public be thinking about the activities that are done on a day-to-day basis? You’ve said before that you believe we have the best people in the world, do you still feel that way?
Gen. Nakasone: I do. I do feel that way. And I think we have the best private sector in the world. And it might be very, very helpful to talk about what are the large companies are doing in terms of making our infrastructure much more defensible. I think that'd be something that would be of great assistance to being able to communicate to the public that this is something that we're doing. I would also tell you that there is a role for government to do this. This is the synchronization that the government can do to ensure our national security. And I think this is one of the things that as we take a look at the new cybersecurity strategy that was recently released, you know, being able to challenge our adversaries, the first part of the cybersecurity strategy is one of the things that I think we can do more of.
Kelly: How do you feel overall about the strategy? I know that there was a great outreach on behalf of the government to the private sector for input on the strategy.
Gen. Nakasone: So, here's what I would say: strategies are documents. What really matters is the implementation of the strategy. I’m looking forward to seeing what the department's strategy is going forward and how we start to move it.
Kelly: Time is the number one thing we talk about now. When you look five years out, what technological development do you think national security leaders are still maybe underestimating?
Gen. Nakasone: Certainly, it’s the whole idea of AI as a mid to long term problem. But I would say the near-term piece is autonomous capabilities. I mean, look at what Ukraine has demonstrated to us. On the 24th of February, 2022, there were zero ships in the Ukrainian Navy. Today, there are still zero ships in the Ukrainian Navy, but they have sunk half of the Russian Black Sea fleet. And they did it with a laptop, a Starlink connection, and a semi-submersible platform. That's the difference in terms of what's going on.
I’ve listened to podcasts that you've done with General David Petraeus and others who have talked about Ukraine being able to manufacture nine million drones a year. That's amazing. And they're launching 10,000 a day. I think this is the near-term piece that we rapidly have to catch up with.
Certainly, the mid and the longer-term piece are artificial intelligence and how we're going to be able to institute this within our economy and our national security. And let me be honest with you, I think the longer-term piece is continuing to develop the talent that goes along with this technology and tradecraft.
Kelly: I also talked to General Petraeus about the future of war and what that looks like. When you think about your perspective and you're thinking about how quickly the technology's changing, the cybersecurity risks are changing, how do you see the future of war taking shape?
Gen. Nakasone: Well, think about three Ds: detect, decide and deliver. I would tell you that the challenge right now will be on the detect and the decide pieces. These are the areas that we've got to really think differently. We used to challenge ourselves at the National Security Agency about whether we could really take in all this collection and be able to make sense of it. My sense today is that artificial intelligence is probably doing that right now for the folks at the agency and the folks in our intelligence community. So, if we've got to be able to do that, being able to detect it now becomes a bit easier.
Then we have to decide what we do about it. And I think this comes down to your question about how we communicate. How do we think and deliver our critical thinking skills in a different way as humans? And then do we have the character to really stand behind what we're going to do and what we're going to decide to do?
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



