/

The New AI Battlefield: Advanced Models Become a Global Security Challenge

A report by The Soufan Center examines how powerful artificial intelligence systems are transforming cyber defense and criminal activity, raising urgent questions over access, control and the risks of misuse by hostile states and non-state actors.

4 mins read
AI tools

The rapid advancement of artificial intelligence has created a new security dilemma: the same technologies capable of strengthening national defenses can also provide powerful tools for cybercriminals, terrorist organizations and hostile governments. A recent analysis by The Soufan Center examines the growing risks surrounding advanced AI models, highlighting concerns over their potential misuse while emphasizing their increasing importance in cybersecurity and national security operations.

The debate intensified after the U.S. government directed artificial intelligence company Anthropic to restrict access to its most capable AI models for foreign nationals over concerns that the technology could be exploited for harmful purposes. Anthropic responded by disabling access to the models globally to ensure compliance with the directive.

The decision centered on Anthropic’s advanced models, Fable 5 and Mythos 5. While Fable 5 was released for public use, Mythos 5 was designed for a more limited group of cybersecurity defenders and infrastructure providers. U.S. authorities argued that unrestricted access to these systems could create national security risks, particularly if advanced capabilities were obtained by foreign adversaries, criminal networks or violent extremist organizations.

The Soufan Center’s analysis explains that the controversy reflects a broader challenge facing governments and technology companies: determining how to balance the benefits of increasingly capable AI systems with the dangers created when those systems are misused.

Advanced AI models are already demonstrating significant capabilities in cybersecurity. They can assist defenders by identifying software vulnerabilities, analyzing attack surfaces and helping organizations patch security weaknesses more efficiently. However, the same abilities can also assist attackers by accelerating the discovery of vulnerabilities and enabling more sophisticated cyber operations.

The report notes that maintaining technological superiority in artificial intelligence has become a major strategic priority, particularly amid competition between the United States and the People’s Republic of China. As AI capabilities continue to expand, governments are increasingly concerned that advanced models could become tools for cyber warfare, intelligence collection and disruption of critical infrastructure.

One of the central concerns discussed in the analysis is the practice of “jailbreaking,” a method used to bypass safeguards placed on AI systems. Although jailbreaking techniques have existed since the release of ChatGPT in 2022, the report argues that applying these methods to highly advanced models creates a new level of risk.

Cybersecurity expert Katie Moussouris of Luta Security reviewed research involving Anthropic’s Fable 5 and found that the reported vulnerability involved a basic form of jailbreaking. According to the analysis, researchers were able to prompt the model to repair flawed code, which indirectly revealed vulnerabilities that the model had previously refused to identify when asked directly for security assistance.

The incident raised questions about whether restrictions on advanced AI models were driven entirely by national security concerns or were also influenced by disagreements over how such technologies should be used. Anthropic had previously faced discussions regarding military applications of AI, including concerns over the use of models in fully autonomous weapons systems.

The Soufan Center report emphasizes that advanced AI systems are becoming increasingly valuable for both “red teams” and “blue teams” in cybersecurity. Red teams represent adversarial actors attempting to exploit weaknesses, while blue teams refer to defenders working to protect systems and infrastructure. The competition between these two sides is expected to shape the future of cybersecurity.

Beyond jailbreaking, the analysis highlights another category of concern: AI models intentionally designed without traditional safeguards. These systems, sometimes referred to as “dark LLMs,” are created to provide responses to harmful requests that responsible AI systems are designed to refuse.

Such models can potentially assist with activities including automated fraud, phishing operations and the development of malicious tools. The report states that hostile actors have increasingly explored AI systems not only as assistants but as autonomous agents capable of carrying out portions of illicit operations with limited human involvement.

A major example cited in the analysis is Anthropic’s disclosure of what it described as the first known large-scale AI-orchestrated cyberattack. In that operation, which was attributed to a Chinese state-sponsored group, an AI system reportedly carried out an estimated 80 to 90 percent of the activity independently against targets including technology companies, financial institutions and government agencies.

The expansion of AI-driven cybercrime is also affecting individuals and businesses. Data from the FBI’s Internet Crime Complaint Center indicates that AI-related scams caused at least $893 million in losses in 2025. The report identifies deepfake technologies, including voice-cloning attacks used to impersonate executives or family members, as a major contributor to the increase.

The analysis notes that AI-enabled threats are not limited to powerful governments. The technology has lowered barriers for criminals with limited technical expertise, allowing individuals and smaller groups to conduct operations that previously required greater resources, knowledge and manpower.

Cybercriminals can now use AI tools to assist with ransomware development, social engineering campaigns and large-scale fraudulent activities. The report also highlights concerns over state-backed actors, including North Korean operators who have used AI-related methods to support efforts such as gaining employment at strategically important companies.

Despite these concerns, the future balance between attackers and defenders remains uncertain. The Soufan Center cites the 2026 AI Safety Report, a major international collaboration on AI risks, which concluded that it remains unclear whether attackers or defenders will ultimately gain the greater advantage from AI assistance.

The report states that AI’s impact on cybersecurity, violent extremism and information manipulation is still developing. While malicious actors are finding new ways to exploit advanced models, cybersecurity professionals are also using these technologies to strengthen defenses and respond more effectively to emerging threats.

Projects such as the U.S.-based Project Glasswing, which brings together technology companies to improve software security in the AI era, demonstrate efforts to apply advanced AI capabilities toward defensive objectives. Industry leaders have argued that restricting access too broadly could weaken defenders, particularly as competing AI models from other countries continue advancing.

The debate over AI access, security and control is therefore becoming a central issue in global technology competition. As artificial intelligence systems become more powerful, governments, companies and security professionals face the challenge of ensuring that these capabilities strengthen protection rather than expand opportunities for exploitation.

The Soufan Center’s analysis concludes that advanced AI models represent both a major security risk and a critical defensive opportunity. The ability to manage that balance will determine how effectively nations respond to the evolving cyber threats of the AI era.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Latest from Blog