Original Broadcast Date: 09/20/2026
Sponsored by Carahsoft
The growing intersection of artificial intelligence and cybersecurity is creating challenges for defenders on multiple fronts, and Donald Coulter, Senior Science Advisor for Cybersecurity at the Department of Homeland Security’s Science and Technology Directorate, says organizations need to prepare for both a growing volume of attacks and increasingly capable threats.
Coulter says it is difficult to separate those two trends.
Cybersecurity organizations have long worried about the volume and speed of attacks, including how quickly vulnerabilities can be identified, targeted and exploited. At the same time, Coulter says AI models are showing a sharp increase in their capabilities.
Their ability to think and plan is extending from hours to days and weeks, he says, with the trajectory potentially moving toward month and multi-month timescales. That raises questions about how sophisticated future attacks could become.
For defenders, Coulter says the challenge is ensuring their capabilities keep pace.
The relationship between attackers and defenders already contains an asymmetry that can benefit attackers, he explains. Defenders therefore need to expand their ability to address vulnerabilities and do it as quickly as possible.
One way to prepare is to build what Coulter calls an “adversarial mindset” into AI tools and systems.
That process begins during architecture and design. Organizations should think about what could go wrong, how someone could misuse a system and what an attacker would potentially want to exploit.
Coulter says the approach is similar to giving a system to someone and asking that person to break it, but it goes further than a single test.
Organizations can apply that thinking throughout the entire lifecycle of a system, from requirements and initial concepts through design, implementation, operations and maintenance. At every stage, developers and operators can ask where vulnerabilities exist, what could go wrong and how they can mitigate those risks.
That mindset also becomes important as agencies attempt to defend at what Coulter describes as machine speed.
AI can provide opportunities to become more resilient and secure faster, but Coulter notes that generative AI risks can be non-deterministic. Organizations cannot necessarily prepare for threats coming from a single direction. Instead, defenders need enough agility to change their approach while still operating quickly.
The AI supply chain adds another layer of complexity.
Coulter says organizations need to consider where their data originates and whether they can prove its provenance. A dataset that is safe at one point could potentially change ownership and later become poisoned.
But the supply chain does not stop with data.
Organizations also have to consider the chips, servers, infrastructure and software pipelines used to train and operate models. Traditional software vulnerabilities remain relevant because software still needs to be compiled and executed. Physical infrastructure such as data centers also creates potential vulnerabilities to both cyber and kinetic attacks.
As AI systems become more capable, Coulter says the focus is also expanding beyond traditional adversarial attacks. Organizations need to ensure systems behave the way they intend and do not move in unexpected directions or circumvent the guardrails developers establish.
For DHS S&T, Coulter says the priority includes identifying and codifying best practices for secure engineering and development.
He points to “secure by design” approaches and expands that concept to include being “resilient by design.” That includes developing processes, recommendations, tools and infrastructure that federal agencies and critical infrastructure partners can use.
Achieving that requires collaboration.
Coulter says private industry, academia and government all have a role in building the practices and capabilities needed to secure increasingly sophisticated systems.
As attackers gain access to more powerful tools, his message for defenders centers on preparation: think like an adversary throughout the lifecycle, understand vulnerabilities across the supply chain and design systems that can remain resilient when something inevitably goes wrong.
