Let AI find the cyber threat, but keep enforcement predictable

Frontier AI can help government cyber teams uncover vulnerabilities, test systems and analyse data. But enforcement actions that affect access or operations should follow predictable rules.

AI can help cyber defenders find vulnerabilities, test systems and analyse threats, but enforcement actions still require predictable, tightly governed controls. Image: Canva

Governments are beginning to ask a more practical question about frontier AI: not only whether the models are safe, but how their capabilities could be used in cyber operations. 

 

Speaking during the panel “Defending Government Against Frontier AI Threats” at GovInsider’s Cybersecurity Day on 13 August, Palo Alto Networks’ ​​Director​​ of industry solutions, Japan and Asia Pacific, Siddharth Deshpande, said the focus had shifted in recent months. 

 

“We were talking about AI safety in the early part of the year. But now it’s about ​leveraging Frontier ​AI ​​to combat rapidly accelerating AI powered threats​​​​,” he said. 

 

That shift includes examining how frontier models could be used in offensive cyber operations and, increasingly, how the same capabilities could strengthen cyber defence.

Keep enforcement predictable​

 

Deshpande distinguished investigative uses from enforcement actions such as quarantining an endpoint, revoking a credential or restricting an administrator’s access.

 

​​“When you look at enforcement from a cybersecurity perspective, you have to be deterministic,” he said​.​​​

 

​​Det​erministic controls require precision, since response and remediation actions often involve removing access or isolating systems — actions that have a real impact on production systems.​​

 

The distinction is therefore not between automated and manual action.

 

Enforcement can still be automated, but it should follow ​​deterministic and reproducible patterns.

 

This requires new agentic AI systems to work in tight integration with traditional cybersecurity analytics, machine learning and automation architectures.​​​​     ​​ 

​​Use AI to search, test and analyse 

 

Deshpande pointed to vulnerability discovery, ​attack path analysis, continuous testing, ​red teaming, penetration testing, data analysis and decision support as ​some ​areas where frontier AI could strengthen existing cyber programmes. 

 

These uses share an important feature: the AI’s findings can be assessed before they lead to action. 

 

A model might surface a possible vulnerability, ​​identify potential attack paths and help cyber ​​defenders​​ take decisions quicker​​​.​ 

 

In each case, AI informs an established security process. For public agencies, this creates a practical boundary. 

 

AI can broaden and accelerate investigative work, while actions affecting access or operations remain governed by deterministic controls. 

 

The question is therefore not simply which model to use, but where it can add value, how it should fit into existing operations and where its authority should end. 

Start with the operating model, not the product 

 

For government agencies, using AI defensively is not simply a matter of adding another tool to their cybersecurity stack. 

 

They first need to decide what task the AI should support and what operating model and guardrails should govern its use.​ 

 

​​​Next, the humans operating the AI ha​rnesses are extremely critical to ensuring success in integrating AI into cybersecurity operations.​​​

 

Through services like Palo Alto Networks’ Unit42 Continuous AI Defense, Deshpande said the company is helping government agencies better leverage the latest Frontier AI models and best practices around emerging concepts like AI Harnesses, into their cyberdefense programme. 

Make red teaming part of continuous assurance 

 

For public agencies, using AI to test systems is not only a technical choice.


It also requires a culture that welcomes scrutiny and addresses weaknesses before attackers can exploit them. 

 

Red teams and penetration testers can sometimes be treated as adversaries because they expose faults, said Senior Lieutenant-Colonel Mok Chuan-Hao, commander of the Singapore Armed Forces’ Cyber Defence Group. 

 

Instead, “we should see red teaming more as a friend, and as a way that we can continuously test our systems,” he said. 

 

Government defenders can also use their knowledge of their own architecture and weak spots to focus testing where it matters and fix problems “before the attacker finds it for you”.

 

For the public sector, this makes red teaming part of continuous assurance rather than an occasional technical exercise. 

 

AI can broaden the search for weaknesses and support analysis, but agencies still need clear boundaries around its authority. 

 

Where a response involves enforcement, the outcome must remain deterministic.