Frontier AI cybersecurity systems can significantly improve vulnerability discovery and remediation, software security, and many other cybersecurity activities. But the same capabilities could also enable malicious actors to find and exploit vulnerabilities at unprecedented speed and scale.
That creates a straightforward policy imperative: cybersecurity professionals should be positioned to realize the benefits of the most capable frontier systems before attackers can exploit their risks.
Business Software Alliance released Cybersecurity Professionals First, a framework for a voluntary public-private partnership designed to help make that happen. This type of approach provides security benefits not only for AI companies, but also for governments and the broader economy.
The framework calls for a structured, transparent, globally aligned, and predictable approach to the strategic, phased rollout of frontier AI cybersecurity systems whose capabilities warrant special treatment. Organizations with demonstrated records of stewardship, capability, and impact should have timely access to these systems so they can identify and remediate vulnerabilities before those capabilities become more broadly available.
But access for trusted organizations is only part of the equation.
Most organizations will never directly operate the most advanced frontier AI cybersecurity systems. They can still benefit from them if the partnership supports the integration of these systems into widely used cybersecurity services. Doing so can multiply the defensive impact of frontier systems across many organizations at once, strengthening security across sectors and borders. Enabling that integration should therefore be a central goal of the partnership.
This two-pronged approach, giving trustworthy organizations access to strengthen their own defenses and cybersecurity companies access to better protect their customers, offers an effective and efficient way to turn frontier innovation into broader cybersecurity gains.
A public-private partnership can improve on today’s ad hoc approach to accessing and diffusing frontier AI cybersecurity systems. It can put these systems in the hands of trustworthy organizations to help protect themselves and their customers – and do so quickly enough to give cybersecurity professionals a head start over malicious actors.
