What happened

Two senior FBI cyber officials used the Billington CyberSecurity Summit this week to describe how AI is changing the threat picture, one day before the bureau published a new cyber strategy. Jason Bilnoski, deputy assistant director of the FBI's cyber division, said AI is taking attackers "to the next level" and warned of more offensive activity hitting networks with greater speed and capability. "The wave is coming. I don't think we've hit the crest yet," he said, pointing to a new AI section in the FBI's annual report on internet crime.

His assessment of the defensive side was less dramatic. AI is not yet beating organisations that pay attention to the basics, he said, and investigators keep finding the same hygiene failures. He pointed to the FBI's recent emphasis on ten fundamental defensive measures, such as multifactor authentication, and said hardening those controls would cut the risk of targeting by both criminal and nation-state actors.

Colleen Ferranti, assistant section chief in the FBI's cyber engagement and intelligence section, said AI-assisted vulnerability discovery means quarterly patch cycles no longer hold. She called for continuous, risk-based patching instead. The strategy itself commits the bureau to using AI tools for triage and malware analysis, states an intent to adopt agentic AI to scale defence, and pledges to protect victim data and privacy when handling information gathered during incidents.

Why this is a GRC story

The technology story and the control story are drifting apart, and that gap is a governance problem. Security teams are being asked to fund AI programmes while the controls that stop most intrusions, multifactor authentication, patching, and asset visibility, still sit on a remediation list somewhere. The FBI's own officials are saying the fundamentals come first.

The patching comment matters most to anyone who owns a change calendar. Moving from quarterly patching to continuous, risk-based patching is not a tool purchase. It changes how risk is accepted, documented and reported, and it needs an accountable owner plus a written risk appetite, not just a faster deployment pipeline.

The AI commitments in the strategy also reach into procurement. Vendors serving government and regulated customers should expect their own AI assurances to be tested against the same expectations the bureau has set for itself.

What to watch

Watch how the ten fundamental controls get adopted in practice and whether regulators begin referencing them in assurance expectations. A control list gains weight quickly once auditors start citing it.

Watch also whether patch cadence starts appearing in regulatory findings or litigation after an AI-assisted exploitation event. An organisation that documents a quarterly patch cycle as its standard may find that record used as evidence against it.

Attribution: Analysis based on CyberScoop and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News