3 min read

The offense-defense balance in cyber has a shelf life, and CNAS just estimated it- 229

The offense-defense balance in cyber has a shelf life, and CNAS just estimated it- 229

May 6, 2026

Cybersecurity has operated for years on a comfortable, if uneasy, assumption: AI-driven detection tools favor defenders, because scaling coverage across a large attack surface has always been cheaper than mounting a single sophisticated intrusion. A new CNAS analysis, "Tipping the Scales," argues that assumption is a snapshot of a moving target rather than a stable law — and identifies three specific mechanisms, each currently under appreciated, by which the advantage now sitting with defenders could flip toward attackers within a three-to-seven-year window.

The report's author, Caleb Withers, and the analysis built on it locate the fragility in three separate trends rather than one. The first is kill-chain compression: sophisticated intrusions have historically required hundreds of person-hours of human reconnaissance and planning, and that lag time has functioned as an implicit defensive buffer — a vulnerability disclosed today rarely gets exploited by a serious actor the same day. As agentic AI systems mature toward autonomously orchestrating full attack sequences, from target identification through exploitation and exfiltration, that planning-to-exploitation window could collapse from days to hours, fundamentally changing the economics of how fast a patch actually needs to ship. The second is compute economics: most defensive AI tooling today runs at near-zero marginal cost once trained, but the most capable frontier models require meaningful compute per inference, meaning organizations with broad attack surfaces may find state-of-the-art AI coverage cost-prohibitive to apply uniformly, even as well-resourced state actors allocate substantial compute toward a small number of high-value targets. The third, and most structurally uncomfortable, is reliability asymmetry: an attacker whose AI tool fails simply wastes effort, while a defender who has integrated an unreliable AI system into critical infrastructure absorbs that failure as operational disruption — a dynamic the July 2024 CrowdStrike outage illustrated starkly, even without any adversarial intent involved. The practical implication is that the reliability bar required for defensive AI sits meaningfully higher than for offensive AI, and is correspondingly harder and more expensive to clear.

The report's policy recommendations follow directly from that asymmetry. Strengthening secure-by-design and secure-by-default requirements in government procurement is framed as urgent rather than aspirational, on the logic that AI is lowering the cost of scanning for basic, unsophisticated vulnerabilities fast enough that organizations coasting on security-by-obscurity are running out of runway — the window in which an unpatched system simply hadn't been noticed yet is closing. The more politically uncomfortable point raised is that awareness campaigns won't move this needle; only procurement standards paired with proportionate liability for negligence will, and current sector-specific regulation in finance and healthcare offers a partial template that water utilities and other critical-infrastructure sectors still lack entirely.

On the geopolitical lever itself, the analysis draws a sharper distinction than most commentary on AI competition: intellectual property theft concerns are treated as a partial distraction from the more tractable chokepoint, which is compute access. Export controls on advanced semiconductors have demonstrably slowed the pace of frontier model development in China — DeepSeek's own published research has acknowledged training-scale constraints as a limiting factor — but the analysis is careful to frame this as buying time rather than securing a permanent advantage, given China's heavy investment in domestic semiconductor development, even as extreme ultraviolet lithography capability remains a genuine and difficult-to-replicate chokepoint in the near term. The strategic question this raises for the U.S. and its allies is not whether compute controls work, but what gets built with the time they buy.

The report's final concern is arguably its most novel: an alignment problem specific to national-security deployment. A commercial model optimized to be helpful, honest, and harmless is not the same system a nation-state needs for cyber-offense operations, where harmlessness is explicitly not the objective — creating an evaluation gap where procurement processes assess model capability under ideal conditions but rarely test behavior under adversarial conditions or extended autonomy. The UK's AI Security Institute is held up as a working template for closing that gap: by investing in genuine technical evaluation and benchmark development rather than regulatory mandates alone, it has positioned itself as a collaborator frontier developers actively want to work with — a form of influence the analysis suggests is more durable, and more replicable by middle powers with limited compute budgets, than compute investment or export policy alone.