Artificial intelligence is changing more than cyber risk. It is changing the economics of cyber.
For decades, sophisticated cyber operations were constrained by scarce human expertise. Whether discovering vulnerabilities, developing exploitation techniques, or responding to incidents, many cyber activities depended on specialized talent that was expensive and relatively limited.
AI is reducing the cost of that expertise, allowing more actors to perform more sophisticated cyber tasks at greater speed and scale. Frontier AI models demonstrated what was possible. The rapid diffusion of capable open-weight models—AI models whose weights are publicly released, allowing organizations to download, modify, and build on them—shows how quickly those capabilities can spread. The result is not simply a shifting balance between attackers and defenders—it is a world in which sophisticated cyber capability becomes abundant: cheaper, faster, and more widely available.1
For governments, the stakes are unusually high. Agencies protect the systems, data, and digital infrastructure that underpin essential public missions—from emergency response and elections to public health, transportation, and national security. When those systems fail, the consequences extend beyond financial loss to public harm, eroded trust, and national security risk.
Governments across all levels now need to defend those missions as attackers can discover and operationalize vulnerabilities faster than many agencies can remediate them. That pressure is already evident: In the 2026 NASCIO-Deloitte Cybersecurity Study, the share of US state chief information security officers (CISOs) who reported being extremely or very confident in their ability to secure public data fell from 48% in 2022 to 22% in 2026.2
As cyber capabilities become more abundant, governments around the world face an evolving challenge. Success depends on adapting to a world where both attackers and defenders have access to increasingly powerful cyber capabilities. That shift requires governments to rethink how they prioritize risk, reduce exposure, build resilience, and shape the broader cyber ecosystem.
Governments should focus on addressing AI’s dual impact: transforming cyber defense and reshaping the broader cyber ecosystem. Operationally, agencies need to redesign their defenses. Institutionally, governments should influence the conditions under which organizations protect themselves. Together, these responsibilities frame the four races that follow.
Operational:
Institutional:
As AI lowers the cost of vulnerability discovery, the challenge shifts from identifying cyber risks to deciding which risks matter most. Frontier and open-weight AI models increase the speed and scale of cyber operations, dramatically expanding the number of vulnerabilities and attack pathways that governments need to understand and prioritize. Governments cannot eliminate every vulnerability. Instead, they must translate technical exposure into operational context, and that context into mission priorities, to determine which machine-discovered risks pose the greatest threat to public missions.
As AI generates larger volumes of vulnerability findings and threat intelligence, another related challenge emerges: separating signal from machine-generated noise. Agencies will need processes to validate AI-identified vulnerabilities, exploit paths, and threat intelligence before scarce remediation resources are diverted toward low-consequence risks.
This requires looking beyond the technical severity of a vulnerability. Context—including mission criticality, exploitability, operational exposure, interdependencies, and available mitigations—determines which vulnerabilities deserve immediate attention. A technically “critical” vulnerability in a low-impact system may pose less real-world danger than a “medium” vulnerability in a system that supports emergency response, water operations, or election administration. In government, cyber risk should be measured by its consequences for public missions as much as by exploitability.
Agencies need to see their technology environments through a mission lens. Which systems support national security? Which services must continue during a crisis? Which data sets are essential to public trust? Which vendors, local partners, or legacy platforms create hidden dependencies? These questions are becoming more urgent.
AI can help agencies build richer operational context by correlating vulnerabilities, assets, threat intelligence, mission dependencies, supply-chain relationships, and known exploited vulnerabilities. Along with better tools, agencies also need cross-functional triage processes that bring together cyber, IT, mission owners, procurement, legal, privacy, and operations leaders. Deloitte’s 2026 Global Future of Cyber Survey found that 63% of private-sector respondents have implemented a business information security office role, which acts as a bridge between an organization’s business units and its cybersecurity team.3
The goal is to move from vulnerability management to mission risk management, focusing scarce time, talent, and funding on the weaknesses most likely to disrupt essential public services.
As AI makes exploit development faster and less costly, government cybersecurity increasingly depends on closing the gap between vulnerability discovery and remediation. This window between disclosure and exploitation continues to narrow. Vulnerabilities that once required rare expertise to deploy can now be turned into working exploitation tools with AI assistance. As a result, the critical challenge is no longer just finding vulnerabilities, but fixing them before attackers can act.
Many agencies still operate with fragmented ownership structures, manual reporting processes, lengthy testing cycles, and risk-averse approval chains designed for a slower threat environment. Those operating models become difficult to sustain as remediation windows shrink from months to weeks—or from weeks to days.
Remediation is becoming a shared responsibility across government, vendors, and critical infrastructure operators. This shift is already reflected in a June 2026 White House executive order calling for a public-private AI cybersecurity clearinghouse for more coordinated vulnerability discovery, remediation, and patch distribution.4 The challenge is particularly acute for state and local governments, which often manage mission-critical systems with fewer cyber resources. In the 2026 NASCIO-Deloitte Cybersecurity Study, only 22% of state CISOs reported cybersecurity budget increases of 6% or more between 2023 and 2024, while legacy infrastructure, growing sophistication of threats, and limited funding remained their top concerns.5
AI can help accelerate the entire defensive lifecycle—from vulnerability prioritization through to patch testing, threat detection, incident response, and recovery planning. Deloitte 2026 Global Future of Cyber Survey found that 75% of organizations are already incorporating advanced reasoning capabilities for real-time analysis and digital infrastructure monitoring as part of their cyber operations.6
Technology alone cannot close the gap. Faster remediation also requires clearer decision-making authority, tighter coordination across IT and mission teams, and less administrative friction during high-risk events. Governments should also redesign their operating model for remediation. Agencies may not eliminate every vulnerability before attackers act, but they can redesign how quickly they respond, reducing the window of exposure.
Even the fastest remediation efforts can’t prevent every compromise. The next challenge is limiting the consequences when attackers inevitably get through. As sophisticated attacks become less expensive to execute, governments should prepare for more frequent compromises, and resilience—the ability to contain disruption, recover quickly, and sustain mission delivery—will become a more critical priority.
For years, government cyber programs have emphasized prevention: finding vulnerabilities, reducing attack surfaces, and stopping intrusions before they occur. Those activities will remain essential. But as AI helps attackers discover and exploit vulnerabilities faster—including previously unknown vulnerabilities—even well-defended organizations may experience more compromises. In that environment, resilience becomes a primary line of defense.
AI increases both the likelihood of compromise and the speed and sophistication of what happens after compromise.7 Automated reconnaissance, credential abuse, synthetic identity, lateral movement, and vulnerability chaining can turn one weakness into a broader mission disruption faster than traditional response models assume.8
This shift is especially important for government because many public systems cannot simply be taken offline. Emergency response networks, public health systems, utilities, transportation platforms, courts, and benefits systems operate continuously and depend on aging, interconnected technology environments. Some systems will remain vulnerable because of operational constraints, procurement cycles, or vendor limitations. The critical question is whether agencies can prevent one weakness from becoming a cascading public-service crisis.
Resilience also requires protecting the integrity of systems that remain operational. AI-enabled attacks may not always take systems offline; they can manipulate data, models, configurations, or automated workflows in ways that allow services to continue operating while producing untrustworthy outputs. For governments using AI to support decisions and deliver public services, resilience includes both restoring systems after a compromise and preserving confidence in the integrity of the data, models, and decisions those systems produce.9
As resilience becomes more important, the traditional division of responsibilities between chief information officers (CIOs) and CISOs begins to blur. Often, CIOs own continuity of operations while CISOs focus on threat management. Effective resilience depends on both jointly owning mission continuity.
The challenge is particularly acute for state and local governments. The NASCIO-Deloitte study found that the share of state CISOs who were “not very confident” in the cybersecurity capabilities of local governments and higher education institutions rose from 35% in 2022 to 63% in 2026.10 Because public systems are increasingly interconnected, weaknesses in one organization can quickly become risks for many others. Whole-of-state cyber models offer a way to pool limited resources such as monitoring, incident response, and recovery capabilities.11
That reality is pushing governments toward a more resilience-oriented posture. Zero trust architectures, network segmentation, continuity planning, and rapid recovery capabilities are becoming as important as perimeter defenses. Whole-of-state cybersecurity models may also play a growing role by providing smaller public entities with shared capabilities such as monitoring, incident response, forensics, and recovery support.
In an AI-enabled threat environment, resilience becomes a strategic advantage. Governments that can recover the fastest may be more effective than those focused primarily on preventing attacks.
No government agency can build resilience alone. Because AI changes the economics of cyber, governments have a unique role in shaping the conditions under which cyber resilience is built.
Governments can shape the incentives, standards, infrastructure, and coordination mechanisms that determine how resilient the broader cyber ecosystem becomes. With AI transforming the economics of cyber, that institutional role becomes as important as defending government systems themselves. A recent open letter signed by a broad coalition of AI, technology, cybersecurity, and other organizations reinforces the need for collective action. It calls for governments to strengthen channels for actionable threat intelligence, prioritize the most serious risks, coordinate incident response and recovery, and expand defensive AI capabilities and hands-on support for under-resourced critical infrastructure organizations.12
Public-sector resilience depends on an interconnected ecosystem spanning federal, state, and local governments, schools and universities, hospitals, transportation systems, utilities, emergency management organizations, cloud providers, software vendors, managed service providers, and critical infrastructure operators. A weakness anywhere in that ecosystem can quickly become a mission risk for government.
That interconnectedness also extends to the AI supply chain. AI models are increasingly embedded in security tools, coding assistants, vulnerability scanners, and incident response platforms, raising new questions about model provenance, deployment environments, update mechanisms, data governance, and third-party risk. As AI accelerates vulnerability discovery and exploitation, governments will need vulnerability disclosures, threat intelligence, and remediation guidance in machine-readable formats that security tools can process automatically.
State governments are already beginning to adapt. The 2026 NASCIO-Deloitte Cybersecurity study found that roughly one-fifth of states are moving toward whole-of-state cybersecurity models that extend shared monitoring, incident response, and recovery capabilities beyond state government to local governments, schools, higher education, hospitals, and other critical infrastructure partners.13 In this evolving cyber landscape, governments that shape incentives, coordinate action, and strengthen ecosystem resilience will be best positioned to protect public missions.
Cyber becomes enterprise governance. Cyber resilience is now an enterprise leadership responsibility, not simply an IT responsibility. Agency leaders should align mission priorities, decision rights, funding, and accountability so organizations can prioritize, remediate, contain, and recover at the pace AI-enabled threats demand.
CIOs and CISOs become joint stewards of mission continuity. As resilience becomes as important as prevention, CIOs and CISOs should jointly own the operating model for mission continuity—not just the technology stack. Their shared challenge is to keep essential services running when prevention fails.
Ecosystem resilience matters as much as agency resilience. AI-enabled threats cross organizational boundaries. Policy leaders should strengthen shared capabilities, coordinated governance, and support for under-resourced jurisdictions so one weak link does not become a broader public-sector risk.
Innovation and security become simultaneous responsibilities. The objective is to enable AI adoption safely and at scale. Cyber leaders should help agencies govern AI use, including digital identities for AI agents, model guardrails, access controls, usage policies, and training to reduce shadow AI and inadvertent misuse.
Ultimately, the governments best positioned for the AI era will be those that recognize the economics of cyber have fundamentally changed—and redesign their operating models, ecosystem governance, and mission resilience accordingly.