WASHINGTON (Realist English). Cyberspace is rapidly becoming the sixth domain of warfare – alongside land, sea, air and space.

However, according to former Director of the US Cybersecurity and Infrastructure Security Agency (CISA) Jen Easterly, America’s primary vulnerability lies not in hackers’ actions but in decades of poor-quality programming. And it is artificial intelligence that has the potential to radically shift this balance – both in favour of defenders and in favour of attackers.

“We cannot afford the luxury of viewing AI as separate from national security. Cybersecurity and AI are inextricably linked today. You cannot have effective cyber capabilities without some form of embedded AI,” Easterly said during a panel discussion at the RSA Conference in San Francisco.

‘We don’t have a cybersecurity problem’

Easterly’s central thesis, which she has repeated in numerous speeches and interviews in 2025–2026, sounds paradoxical: “We don’t have a cybersecurity problem. We have a software quality problem.”

The cause of most breaches and data leaks is not sophisticated hacker methods, but decades of “misaligned economic incentives,” when software vendors prioritised speed to market, “cool features” and cost reduction over security. As a result, critical infrastructure – from power grids to financial systems – is built on “flawed, insecure code.”

Particularly alarming is the fact that vulnerabilities identified by MITRE 20 years ago (cross-site scripting, unsafe memory handling, SQL injection) remain “golden oldies” in the hacker arsenal. “The People’s Liberation Army of China relies not on exotic cyber weapons,” Easterly notes, “but on vulnerabilities in routers and other network devices.”

AI – a double-edged sword

Easterly calls artificial intelligence “the most powerful technology of our lives,” which will change “literally everything.” However, her assessment is twofold:

A weapon of defence. AI has the potential to radically transform cyber defence: finding and fixing vulnerabilities faster than ever before, detecting attacks at early stages, and even automating responses. “If we can safely build, deploy and manage these incredibly powerful technologies, I believe it will lead to the end of cybersecurity” – in the sense that breaches would become an anomaly rather than a “cost of doing business.”

A weapon of attackers. Adversaries are already actively using AI: phishing emails have become “almost perfect,” malware is harder to detect, and state-sponsored hackers are experimenting with AI models to automate entire attack chains.

“Attackers will use AI too,” Easterly warns. “The attack-defence dynamic is not going away.”

The key problem is who owns this weapon. “Nuclear weapons were created and guarded by governments that had no incentive to use them. AI is being created by private companies that answer to investors. Self-regulation is not enough.” Annual losses from cybercrime are already comparable to the GDP of the world’s third-largest economy.

‘Regulatory chaos’ and vendor responsibility

Easterly is calling for the US to adopt a harmonised federal approach to AI regulation. The current “patchwork” of rules, she says, creates only bureaucratic burdens without real protection.

She cites the 2022 conflict between CISA and the Securities and Exchange Commission, when the two agencies set different rules for disclosing cyber incidents, leading to “regulatory chaos.”

She also insists on introducing a liability regime for software quality: “Instead of blaming victims for not installing patches, or blaming the intern for downloading a malicious file, I believe we need to demand more from our vendors. We need to demand accountability and security by default.”

The private sector – the ‘sixth domain’ of war

Easterly emphasises that a “sixth domain” is emerging in cyberwarfare – the private sector. It is there that “the overwhelming majority” of critical infrastructure resides: water, electricity, healthcare, finance, transport and communications. “The private sector, more than anyone else, is on the front lines of these battles,” she said.

In a world with 5.7 billion social media users, billions of connected devices and millions of transactions every minute, “everything can be attacked,” and preventing every attack is impossible. The only answer is resilience: “Disruptions will happen,” so business and government must build systems, prepare data and train people to be ready for them.

Jen Easterly views AI not merely as another technological trend but as a fundamental shift that could either “end” cybersecurity as an industry or make it more effective than ever. However, for that to happen, she argues, three conditions are necessary: a shift from the “patchwork” approach to quality programming, harmonised regulation, and a shift in responsibility from users to vendors.

Otherwise, AI will remain not a shield but the most powerful weapon in the hands of America’s adversaries.

“One of the things that has occurred to me over the past couple of days is that we are at a moment where cybersecurity and AI are inextricably linked,” Easterly concludes. The question is who will be the first to learn how to use this connection to their advantage.