What happened
RAND Europe, commissioned by the UK Foreign, Commonwealth & Development Office, argues that adversarial attacks that disrupt, deny, or manipulate AI-enabled military and critical-infrastructure systems are an under-governed strategic stability risk, not merely a cyber-security or AI-assurance problem. Key findings: perceived AI vulnerability undermines defence credibility; adversarial AI may tip the offence-defence balance toward offence; ambiguity between model malfunction and deliberate attack complicates attribution and risks miscalculation; and entanglement of conventional and nuclear C3 raises accidental-escalation risk. Recommendations include embedding these risks in international AI-governance forums, sharing threat intelligence with allies, conducting after-action reviews of significant incidents, and strengthening NC3, dual-use C3 and critical infrastructure with fallback options (published Sep 29, 2026).
Why it matters
For executives and boards in defence, critical-infrastructure, and national-security-adjacent sectors, this reframes AI cyber-attacks from a compliance issue to a crisis-stability issue with escalation consequences.
Action needed
Map the report's attack scenarios against your critical systems' AI dependence and ensure resilience/recovery plans, not just defensive controls, are in place.