TOKYO - Artificial intelligence is rapidly transforming cyber warfare by enabling faster, automated and continuous attacks, raising concerns that governments and companies may struggle to detect and stop intrusions before serious damage occurs.
Taiyo Tsuchiya, a professor at Keio University who served on a government expert panel examining active cyber defense, said AI has fundamentally changed the nature of cyberattacks by allowing attackers to operate on a much larger scale without the limitations faced by human hackers.
AI systems do not need rest and can continuously search for weaknesses and launch attacks, Tsuchiya said. One particularly serious risk is the ability of AI to discover previously unknown software vulnerabilities, known as zero-day vulnerabilities, and exploit them quickly.
The spread of powerful AI tools is also lowering the technical barriers to cybercrime. Attacks that once required advanced expertise can increasingly be carried out by people with relatively little experience, potentially allowing even high school students to conduct operations that would previously have been difficult.
Concerns over the risks have grown as AI models become more capable. Anthropic said in April that access to its high-performance Claude model would be restricted to certain organizations because of concerns that it could be misused for activities including cyberattacks.
Japan is preparing to strengthen its cyber response framework, with measures related to active cyber defense scheduled to take effect on October 1.
The government's approach rests on three main pillars. The first is stronger information sharing between the public and private sectors. The second is greater use of communications information held by telecommunications companies. The third involves taking steps to neutralize access by attackers once authorities determine who is responsible.
Tsuchiya said, however, that the rapid development of AI has outpaced some of the assumptions made when Japan's new cyber defense framework was originally designed.
"When we first began considering this, we had not anticipated that AI would become this widespread and powerful," he said, adding that Japan may need to reconsider its defenses from a new perspective.
The challenge is particularly serious when state-backed actors use AI to conduct cyber operations. Incidents that once developed over several days or hours may now require responses within less than an hour, placing far greater emphasis on speed.
Cyber defense is increasingly becoming a contest between AI systems on both sides, but Tsuchiya said defenders face an inherent disadvantage.
AI used by attackers may operate with few restrictions and simply be instructed to defeat a target. Defensive AI, by contrast, is generally required to operate within ethical and legal safeguards, often referred to as guardrails.
Those limitations can make defensive systems less flexible than offensive ones, leaving defenders at a disadvantage even when both sides are using advanced AI.
Human expertise therefore remains essential. Tsuchiya said cybersecurity cannot simply be left to computers fighting one another because unexpected situations will continue to require human judgment.
Governments and organizations will need large numbers of trained specialists capable of understanding what is happening in cyberspace and translating that knowledge into policy decisions.
Japan's Self-Defense Forces are developing cybersecurity personnel through a communications school in Kurihama, while the National Police Agency has established a Cyber Bureau and is working to strengthen its specialist workforce. Private companies will also need to expand their capabilities.
Japan is also examining ways to build expertise through overseas companies with more advanced cyber capabilities.
Before the country's new legal framework was established, there were limits on what Japanese organizations could do domestically. One approach now being considered is acquiring foreign companies capable of conducting more advanced operations, sending Japanese personnel to work with them and receive training, and then bringing that expertise back to Japan.
The government is meanwhile working on revisions to Japan's three key national security documents, with the process expected to include the National Security Strategy, which sets the country's basic foreign and security policy; the National Defense Strategy, which outlines defense goals and methods; and the Defense Buildup Program, which specifies the equipment and capabilities required.
Tsuchiya noted that Japan's active cyber defense legislation grew out of policies first set out in the National Security Strategy four years ago, demonstrating how rapidly the cybersecurity environment has changed and how quickly national security planning must adapt to new technological threats.
Source: テレ東BIZ















