On August 10th California announced its pioneering AI Cyber Defense Program designed to strengthen the protection of state systems and critical infrastructure against emerging artificial intelligence-enabled cyber threats. The directive, which builds on the September 2023 and March 2026 AI executive orders, directs state agencies to:
Establish an AI Cyber Defense Program within the California Cybersecurity Integration Center
Expand the use of AI for vulnerability detection, network hardening, and incident response
Increase support for local governments and critical infrastructure operators
Designate an AI Cybersecurity Officer in every state agency
The program builds on California's broader AI strategy and reflects growing concern that increasingly capable AI systems are transforming both how adversaries conduct attacks and how organizations defend against those cyber threats.
This program represents one of the most significant public-sector acknowledgments to date that AI is changing cybersecurity on both sides of the battlefield. The initiative's focus on leveraging AI for cyber resilience reflects that AI can increasingly become a force for defenders, and not just attackers.
California recognizes that AI is making attacks faster, cheaper, and more sophisticated, and that defenders must leverage AI to improve the effectiveness of traditional cybersecurity activities. However, the AI era demands more than simply applying AI to existing security processes. As AI adoption accelerates there are additional challenges beyond the scope of California’s program which organizations will need to address:
AI agents introduce a new class of autonomous actors capable of accessing data, executing workflows, making decisions, and taking actions on behalf of users. Identity governance must evolve from managing people and systems to managing autonomous AI actors.
New risks within AI-enabled systems, such as prompt injection, model manipulation, and data poisoning introduce security concerns that many traditional cybersecurity programs were not designed to address. Future security programs must prevent and observe AI behaviors, prompts, and agent activities, not just networks and endpoints.
Organizations increasingly depend on third-party AI providers, creating supply chain risks that can be difficult to assess and manage. In fact, according to the 2026 Verizon Data Breach Investigations Report (DBIR)i, 48% of breaches involved a third-party. Without a structured assurance framework, it can be challenging for customers, regulators, and business partners to determine whether AI systems can be trusted.
Despite these challenges, AI presents transformative opportunities for defenders. Organizations can use AI to identify vulnerabilities faster, improve threat detection capabilities, and enhance decision-making during cyber incidents. It provides an opportunity to modernize risk management programs and establish new levels of transparency and confidence in AI-enabled systems.
Companies will be most successful when they view AI systems beyond just their defensive technology and begin treating them as critical assets which require their own security, governance, and assurance. By combining AI-enabled cyber defense with comprehensive security assurance, organizations can build the trust necessary to accelerate AI adoption while maintaining confidence across the broader digital ecosystem.
Recent advances in frontier AI models have demonstrated an unprecedented ability to accelerate portions of the cyber attack lifecycle. In February 2026 the AI Security Institute (AISI) estimated that the length of cyber tasks AI models could complete was doubling every 4.7 months which was an acceleration of their November 2025 analysis which stated this process was doubling every 8 months. Then in May 2026 AISI reported that two new models, Claude Mythos Preview and GPT-5.5, substantially exceeded both doubling rate trendsii.
Activities that previously required substantial proficiency can increasingly be performed quickly, at greater scale, and with less expertise. This requires defenders to respond-in-kind by leveraging those same technologies to identify vulnerabilities, automate investigations, and improve response times.
The potential cybersecurity impact of AI is not just theoretical but occurring today in real-world attacks. Weeks before California’s announcement, a suspected Iran-linked intrusion hit more than thirty municipal water utilities, including several in Minnesota, and separate disclosures showed frontier AI models pulling off multi-step cyberattacks on their own in controlled tests.
At the same time, the federal safety net states have relied on is thinning: The Cybersecurity and Infrastructure Agency (CISA) proposed budget is shrinking by nearly a third, The Multi-State Information Sharing and Analysis Center (MS-ISAC) free federal support dried up in late 2025, and the grant program that funded state and local cyber defense is running dry. California is stepping in to close that gap itself, building on Cal-Secure 2.0, the updated statewide cybersecurity roadmap it released just weeks earlier.
These developments point to a fundamental shift in the cybersecurity landscape. AI is rapidly lowering the barriers to sophisticated cyber operations, allowing attackers to execute increasingly complex activities with greater speed, scale, and efficiency. At the same time, public-sector organizations face growing resource constraints and shrinking access to traditional sources of cybersecurity support. The result is a widening gap between the capabilities of adversaries and the capacity of defenders relying solely on traditional security approaches.
As AI evolves, organizations will increasingly need to focus their security efforts across four distinct but complementary domains:
Traditional information security governance
Traditional information security
AI governance
AI information security
California’s program is focused on enhancing traditional cybersecurity mechanisms to protect against AI-driven threats. This is one of the strongest aspects of California’s program since it focuses on operational cyber defense rather than treating AI solely as a governance challenge. Using AI to accelerate vulnerability identification, improve threat detection, and triage and prioritize security events has the potential to help defenders keep pace with an increasingly fast-moving threat landscape.
Leveraging the use of AI in defense is an effective strategy, but it is just one of several updates necessary to address today’s AI-driven threats. The emergence of AI has introduced threats across several domains which require corresponding enhancements. When reviewed holistically, AI requires companies to implement additional controls across multiple traditional information security areas. For example:
Historically, organizations could operate on weekly scans or monthly patch cycles. AI-enabled attackers may identify and weaponize weaknesses much faster. Organizations may need to evolve from periodic vulnerability management to continuous exposure management operating at machine speed.
Traditional identity programs were built for people. The rise of AI agents introduces a new class of non-human identities that can autonomously perform tasks, access systems, and make decisions. Organizations will need to update their security practices to ensure AI agents operate within clearly defined authority boundaries and are subject to the same accountability and monitoring expectations as human users.
Secure development practices increasingly need to account for models in addition to code. Organizations must understand not only whether software is secure, but also whether the AI components embedded within that software behave predictably, resist manipulation, and operate within established risk tolerances.
Traditional security monitoring capabilities focus on identifying malicious activities within systems and networks. AI-enabled environments require organizations to additionally monitor model behavior, agent actions, prompt interactions, and AI-specific attack techniques that may not generate the indicators traditionally associated with cyber threats.
The use of AI to defend the system is a tool to improve defenses, but it should be paired with necessary updates to traditional governance and traditional information security practices to appropriate protect an organization against increasingly sophisticated adversaries.
Defending against AI-driven threats is only one side of the equation. As organizations deploy AI-enabled technologies throughout the enterprise, new attack surfaces and risks are introduced that traditional information security programs were not designed to address.
This is where the broader industry conversation must continue to evolve. Organizations need to think not only about how AI can improve cyber defense, but also how to internally manage AI risks and secure the AI-enabled systems they are deploying. This goes beyond traditional governance and information security, requiring companies to deploy AI governance and AI information security across the enterprise.
The emergence of AI introduces a new governance challenge where organizations must now govern not only technology, but also models, agents, and automated decisions. As a result, traditional governance areas must evolve to address a new class of risks such as:
AI Acceptable Use Governance: Formal rules regarding which AI tools employees may use, what data may be entered into those systems, and what business processes may be supported by AI.
Human Oversight Requirements: AI systems can make recommendations or take actions that have significant business impacts so this should govern that decision-making process.
AI Agent Governance: Defining permissible and restrictive actions for AI agents, including logging and review of their activities.
However, AI governance alone falls short of demonstrating that AI threats have been addressed in deployed AI-enabled systems. As AI systems become operationally embedded across critical infrastructure, such as healthcare and financial systems, organizations must increasingly focus on another question:
How do we securely deploy and manage our AI-enabled systems?
To demonstrate that system-level threats have been mitigated, organizations should incorporate threat intelligence to identify and address the corresponding AI-specific threats (such as those threats and corresponding mitigations identified in MITRE ATLAS). Guardrails should act within the AI-enabled system to protect against threats such as:
Prompt injection
Data poisoning
Model leakage
Hallucinations
Unsafe outputs
AI Privilege Misuse
AI security requires organizations to ensure the AI system's behavior, outputs, decisions, and actions can be trusted under both normal and adversarial conditions. These threats are not mitigated using traditional information security controls and must be controlled within each deployed AI system.
There is an additional layer to the AI threat landscape when viewed through the lens of third-party risk. Most organizations are not building every AI capability themselves. Increasingly, they rely on vendors and services providers who are using AI-enabled systems to provide services and manage their data. As a result, an organization's exposure to AI risk frequently extends beyond the AI systems it operates directly. California’s initiative includes provisions aimed at supporting local governments and critical infrastructure operators, acknowledging that security weaknesses often emerge at ecosystem boundaries rather than within a single organization.
Organizations may have strong internal governance and security practices, yet still inherit risk from a provider's AI model, training pipeline, or AI integrations. As AI becomes more deeply embedded across products and services, trust will increasingly depend on the ability to demonstrate that these systems have been assessed against consistent, security-focused requirements.
This challenge becomes particularly important for critical infrastructure and public-sector environments, where a vulnerability in one supplier can have downstream consequences across many organizations.
As AI adoption accelerates, organizations should treat AI supply-chain assurance as a foundational component of cyber resilience rather than an afterthought. For third-party risk management programs, the answer to these challenges is to obtain the appropriate level of assurance from their vendors that use AI-enabled systems. Unfortunately, most organizations today are not prepared to provide that level of assurance.
Today, most organizations can articulate AI principles, governance objectives, and risk management processes. Far fewer can produce independently validated evidence demonstrating that deployed AI systems are secure and operating as intended.
This is where the industry conversation must continue to evolve in order to build trust through assurance.
California's AI Cyber Defense Program is an encouraging development because it recognizes that AI is now a cybersecurity issue, not simply a technology policy issue. The program's emphasis on proactive defense acknowledges both the opportunities and risks associated with increasingly capable AI systems.
The organizations that succeed in this new environment will be those that move beyond AI aspirations and governance statements toward demonstrable security outcomes. They will establish controls that address emerging AI risks, validate that those controls are operating effectively, and extend those expectations throughout their supply chains.