FBI Warns AI Amplifies Cyber Threats, Urges Focus on Foundational Security
The FBI is sounding the alarm that artificial intelligence is significantly accelerating adversary capabilities, making attacks faster and more sophisticated, while stressing that fundamental cybersecurity practices remain the most critical defense.

Top officials from the Federal Bureau of Investigation have issued a stark warning: artificial intelligence is rapidly enhancing the speed and sophistication of cyber adversaries, presenting a growing challenge to organizations worldwide. Jason Bilnoski, deputy assistant director of the FBI’s cyber division, stated that AI is "taking actors to the next level," leading to an "exponential increase in the use of AI, whether it's nation-state or criminal." He cautioned that the "wave is coming" and that the full impact of AI-enabled attacks has yet to be realized, with current numbers in the FBI's annual report on digital crimes already demonstrating a measurable effect.
Despite the advanced capabilities AI brings to attackers, Bilnoski emphasized that the most effective defenses against these evolving threats lie in adhering to basic cybersecurity hygiene. He noted that investigations frequently reveal adversaries exploiting fundamental security principles that organizations are failing to implement. The FBI's ongoing focus on ten core defensive measures, such as multi-factor authentication, remains paramount. "What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday," Bilnoski asserted, underscoring the enduring importance of foundational security practices.
In response to the escalating threat landscape, the FBI is also integrating AI into its own defensive strategies. Bilnoski indicated that the bureau will "continue to pursue AI in a way that will help us defend at scale." This proactive approach aims to leverage AI for enhanced threat detection, analysis, and response capabilities, allowing the FBI to better counter the speed and volume of AI-augmented attacks.
Furthermore, the FBI's newly released cyber strategy explicitly addresses the role of AI in both offense and defense. The strategy outlines plans to deploy AI-enabled tools for tasks such as triaging large datasets, accelerating malware analysis, prioritizing victim notifications, and mapping adversary infrastructure. It also commits to securely scaling AI-driven defenses and disruption efforts, aligning with broader national cybersecurity objectives.
Colleen Ferranti, assistant section chief of the FBI’s cyber engagement and intelligence section, highlighted the implications of AI-driven vulnerability discovery for patching strategies. She argued that traditional quarterly patching cycles are no longer sufficient. Instead, organizations must adopt a more dynamic, risk-based approach to patching, performing it continuously to keep pace with the rapid discovery and exploitation of vulnerabilities. "So, from our perspective, the day-to-day or quarterly or Patch Tuesday — this needs to be a patch-all-of-the-time," Ferranti advised.
The FBI's new cyber strategy also reaffirms a commitment to victim relief and justice, pledging to treat victims with dignity and respect, protect their privacy, and rigorously adhere to legal and ethical standards. The strategy includes plans to swiftly share threat intelligence, respond rapidly to incidents, and expand its Industrial Control Systems (ICS) Coordinator program to ensure dedicated personnel are available in every field office.
This strategic shift reflects a broader trend across government agencies and the cybersecurity industry, acknowledging AI's dual nature as both a powerful tool for defense and a significant amplifier of threats. The FBI's emphasis on both advanced AI adoption for defense and the reinforcement of basic cyber hygiene signals a pragmatic approach to navigating the complex future of cybersecurity.
The FBI's updated cyber strategy, released alongside these remarks, details the bureau's priorities, including the use of AI for defense and analysis, efforts to provide relief and justice for victims, and the importance of continuous, risk-based patching over traditional, less frequent cycles. This document represents the latest in a series of cyber strategy publications from the current administration, signaling a coordinated effort to address evolving digital threats.