Bridging the Gap
The Swift Centre's 'Bridge the Gap' project seeks to improve AI policy making by providing open sourced policy advice that is built upon robust forecasts on AI capabilities, risks, and impacts by the world-leading team at the Swift Centre for Applied Forecasting.
Review forecasts and policy adviceKey Info
Categories Covered
5Policy Advice Submissions
29How it Works
Forecast
The Swift Centre team provides forecasts on AI capabilities, impacts, and risks.
Policy
Anyone can submit policy advice using the forecasts and have it published on the dashboard.
Review
Policymakers, advisors, researchers, and funders can review the policy advice submitted.
Submissions
By Viola Zhong
For forecast question: By December 31, 2027, a frontier AI agent will autonomously discover and exploit a previously unknown (“Zero-Day”) vulnerability in a Tier 1 operating system on a real-world device without human intervention?
Advice
To: United States National Security Advisor
Date: 2026-04-06
Summary
For a decision. Forecasters assess a 44% probability of autonomous AI zero-day exploitation of Tier 1 operating systems by end-2027 — a floor, not a ceiling, on operational risk. Capability is converging, and the cost of sophisticated cyber operations is collapsing, expanding the attacker population. Only the NSA can direct the required interagency levers, and delay forfeits the defender's lead time, which the US still holds.
Options Overview
Option 1: Monitor and study
Option 2: Defender advantage through structural asymmetry
Option 3: Attacker-side pressure on cost-collapse beneficiaries
Recommendation
Option 2 as the foundation, with Option 3 layered in. This hybrid is robust across forecast outcomes and addresses both the structural threat and the actor classes whose behaviour changes most under cost collapse. A National Security Memorandum is the appropriate vehicle.
Background
The Swift Centre assigns a 44% probability that, by end-2027, an AI agent will autonomously complete a closed-loop kill chain against a Tier 1 operating system (Windows, macOS, Linux, Android, iOS) on real hardware. Forecasters cite agentic AI's offense-favoring pace and rising attempt volume as structural drivers, held down by mature private defenses and the strict closed-loop verification bar.
We assess 44% as a floor on a measurement artifact. Operational threat is governed by capability, not verification, and both halves — autonomous one-day exploitation and independent vulnerability discovery — have been publicly demonstrated; only their integration on a Tier 1 target remains, and the offense-defense imbalance is widening.
The consequence is a collapse in the cost of sophisticated cyber operations — historically $500K–$2M per Tier 1 exploit, now compressing by roughly two orders of magnitude. The beneficiaries are not capability-rich states, which are already exploit-saturated, but cybercriminal affiliates, mid-tier states, and the commercial spyware market. A high-consequence cross-tier scenario also emerges: top-tier states targeting US AI labs and defensive vendors directly, with blast radius in the hundreds of millions of users. No single department owns the response — Treasury, Commerce, Justice, State, Defense, and DHS each hold a fragment, which is why this advice is directed to the NSA.
Options
Option 1: Do Nothing
Existing CISA Binding Operational Directives and sector coordination remain in place. No new directives, sanctions, or procurement requirements. This option does not alter the cost curve, the actor population, or the defender's lead time. It reduces uncertainty about the threat without reducing the threat.
Considerations
Low cost. No new authorities required. Politically frictionless. Aligns with a default preference for evidence-gathering before action.
Risks
The forecast window closes in 22 months; If a major incident occurs in the interim, the NSA will be seen to have had clear warning and chosen to study rather than act. The political and operational costs of that posture are asymmetric and unrecoverable.
Option 2: Defender advantage through structural asymmetry
Direct the interagency, by National Security Memorandum, to amplify the structural advantages defenders hold over attackers — advantages the collapse of AI costs cannot erase. The program has four components. First, an accelerated patch pipeline: compress patch SLAs for known-exploited Tier 1 OS vulnerabilities on federal networks, paired with grant funding for the tooling required, collapsing the discovery-to patch window that currently gives attackers their operational advantage. Second, a shared AI-augmented vulnerability discovery capability: stand up a continuous AI-augmented analysis service across federal attack surfaces and volunteered critical-infrastructure code, amortizing defensive AI capability across thousands of defenders who could not afford it individually — a force multiplier with no attacker equivalent. Third, Secure by Design procurement: condition federal software purchase on memory-safe languages, signed updates, and default-secure configurations, phased over two years, eliminating entire vulnerability classes upstream of any specific exploit. Fourth, expanded telemetry and threat-intelligence sharing: mandate participation by large federal contractors in cross-sector sharing programs and provide legal safe harbor for aggressive intra-industry sharing, converting every defender's detection into every other defender's prevention. Substantially lowers operational harm conditional on the capability existing — collapsing the discovery-to-patch window and amortizing defensive AI across thousands of defenders — by exploiting structural asymmetries (shareability, pre-positioning, supply-chain ownership) that amplify rather than degrade as AI capability rises.
Considerations
Mid-range supplemental cost, executable under existing authorities with no new primary legislation, aligned with the Administration's American AI leadership posture by framing defensive AI as the flagship use case.
Risks
Compressed patch SLAs will face friction from under-resourced agencies (mitigated by grant funding and phased rollout) and the discovery capability will create disclosure-timing tension managed through existing processes; the residual risk is that this option does nothing to constrain attackers themselves.
Option 3: Attacker-side pressure on cost-collapse beneficiaries
Direct the interagency, by National Security Memorandum, to raise costs for the two actor classes most empowered by AI cost collapse: cybercriminal groups and commercial spyware vendors. The program has five components. First, Treasury sanctions: OFAC designates additional cryptocurrency mixers, ransomware infrastructure, and commercial spyware vendors under existing authorities, prioritized by AI-enablement signals — cutting the financial rails that convert intrusions into revenue. Second, Commerce export controls: license requirements on agentic AI models above a defined cyber-offensive capability threshold, with the AI Safety Institute providing the evaluation regime — restricting access to the most capable models while preserving licensed defensive use. Third, procurement leverage: federal procurement of frontier AI services conditioned on misuse detection, capability evaluation, and incident reporting — converting voluntary controls into an industry-wide floor through market shaping rather than new regulation. Fourth, a law enforcement surge: supplemental authorities and resources to disrupt ransomware infrastructure and prosecute operators, with explicit focus on AI enabled criminal services — imposing direct cost on the most active groups. Fifth, diplomatic pressure: coordinated pressure on jurisdictions harboring cybercriminal operators, building on the Counter Ransomware Initiative — degrading the safe-haven environment that currently shields top-tier criminal groups. Together these components attack the expansion of the attacker population through three independent pathways: restricting access to inputs (export controls, procurement), raising the cost of operations (sanctions, enforcement), and degrading the operating environment (diplomatic pressure). The package does not reach top-tier state actors, who are out of range of all five tools and require a separate response architecture. Attacks the second-order consequence of cost collapse — the expansion of the attacker population — by restricting access to capable agentic models, raising the legal and financial cost of operating, and making harboring environments less hospitable; does not reach top-tier state actors.
Considerations
Modest direct cost concentrated in law enforcement, with regulatory components absorbed; politically harder than Option 2, with export controls facing legal and industry pushback and spyware sanctions diplomatically sensitive where allied governments are customers.
Risks
Export controls risk pushing development offshore without reducing the offensive threat; sanctions and enforcement are reactive and adversaries adapt; procurement leverage depends on frontier labs continuing to want federal contracts — making this option more fragile to changing conditions than Option 2.
Recommendation
Adopt Option 2 as the foundation, with targeted Option 3 elements layered on top — sanctions on ransomware infrastructure and cryptocurrency mixers, export controls on agentic models above a defined cyber-offensive capability threshold, and procurement-conditioned misuse detection for frontier AI labs.
The theory of change: by amplifying the structural asymmetries LLMs cannot erase while raising costs on the two actor classes whose behavior changes most under cost collapse, this hybrid reduces aggregate harm through two independent causal chains. Option 2 alone is too slow against the cybercriminal and commercial-spyware threat; Option 3 alone is too narrow to address the structural offense defense imbalance. Together, they cover the failure modes of each.
The recommendation is robust across forecast outcomes. If the forecast resolves YES, the investments are already in place. If it resolves NO because verification fails but capability arrives anyway — the scenario we judge most likely — the same investments still bite, because they target operational risk rather than the verification artifact. If AI cyber capability plateaus entirely, Option 2 remains valuable against the conventional threat, and the Option 3 components are narrow enough to be unwound without lasting cost.
Next Steps
If the NSA agrees: classified briefing within 7 days, NSM drafted within 14 and signed within 30 with taskings to Treasury, Commerce, CISA, and Justice, first progress report at 90 days.
