Cyber Compliance and Beyond logo

Episode 31

When AI Attacks – Part 1

Share
When AI Attacks – Part 1

About This Episode

Podcast Episode 31
July 14, 2026 - 34 mins

AI-enabled cyber operations have moved from theory to reality, with the GTG-1002 incident marking the first widely recognized case of an AI system independently executing a multi-step intrusion. In this 2-episode conversation, Nury Turkel explains how this shift is reshaping national security—from adversaries using AI to accelerate reconnaissance and credential misuse to the growing geopolitical stakes between the U.S. and China in advanced AI development. The episode highlights how governments and organizations must rethink readiness, regulation, and innovation as AI becomes both a transformative capability and a destabilizing force in global competition.

References:

Microphone
Are you a podcast listener?

Get the latest episodes on your favorite streaming platform.

Podcast use is subject to Kratos Terms.

Subscribe via email for the latest podcast

Get email alerts on the latest episodes

Episode Transcript

Cole French:

Have you been wondering whether AI-enabled cyber operations are still theoretical or if they’ve already crossed into the real world? Curious how a single attack GTG-1002 became the first clear sign that AI isn’t just supporting cyber operators anymore, it’s becoming one and what that shift means for national security compliance and the future of US-China tech competition? In part one of this broad ranging two-part series, we unpack how AI is accelerating the threat landscape, why prompts are quickly becoming the new malware, and what GTG-1002 revealed about the next era of cyber conflict.

Welcome to the Cyber Compliance & Beyond Podcast, a Kratos podcast that brings clarity to compliance, helping you leverage compliance as a tool to drive your business’s ability to compete in any market. I’m your host, Cole French. Kratos is a leading cybersecurity compliance advisory and assessment organization, providing services to both government and commercial clients across varying sectors, including defense, space, satellite, financial services, and healthcare. Now let’s get to today’s episode and help you move cybersecurity forward.

AI is redefining what cyber operations look like, faster, more autonomous, and far less dependent on human operators than ever before. In this episode, we explore how the GTG-1002 incident became a watershed moment. The first widely recognized example of AI not just assisting in attack, but acting as an operational actor itself. Six months later, the conversation has shifted dramatically. Boards, CISOs, and policymakers are no longer asking if this could happen. They’re asking how soon it will scale. In today’s conversation, we break down how adversaries are already using large language models to speed reconnaissance, automate movement, and weaponize stolen credentials. Part of an emerging trend where prompts, not malware, drive the attack chain. We also examine how state-sponsored actors like China are leveraging AI as a multiplier for intelligence collection, cyber operations, and strategic competition and why understanding advanced AI systems has become an intelligence priority of its own.

Joining us today is Nury Turkel, a national security attorney and strategic advisor who helps multinational companies navigate AI governance, export controls, sanctions, supply chain risk, and US-China strategic competition. He holds an active US government security clearance as the lifetime member of the Council on Foreign Relations and is recognized by Time and Fortune as one of the world’s most influential leaders. His analysis appears in the Wall Street Journal Foreign Affairs and the New York Times. This is part one of our two-part conversation with Nury, where we set the stage, explore the shifting threat landscape, and begin unpacking the geopolitical stakes. In part two, we’ll dig deeper into regulation, export control, supply chain risk, and what leaders can do right now to prepare for a world where AI-enabled attacks become the norm. We hope you enjoy this episode.

So anyone who’s been paying attention recently, or for quite some time really now, AI seems to be in the news all the time. And something that has really started to be seen out there is AI as a cyber weapon or used in the, as we’ll talk about in today’s episode, the cold cyber war becoming kinetic. And I really appreciate Nury for coming on today to talk to us about this important topic. And in particular, we’re going to talk about an article that Nury wrote in the Wall Street Journal about six months ago on the GTG-1002 cyber attack, and that was Anthropic’s terminology for this particular cyber attack. And Nury, if you could just get us going with, now that we have, like I mentioned, six months have gone by since you wrote this article, what do you think the article got right?

Nury Turkel:

Cole, thank you so much for having me on. It’s a privilege to speak with you about these important issues. The article was never really about the GTG-1002 itself. The bigger point was a broader trend. AI was beginning to move from a total used by cyber operators to an operational actor in its own right. As you know, historically, sophisticated cyber operations were constrained by human talent. People in big buildings and some government facilities or cybersecurity operational centers, those skilled people conducting reconnaissance mapping systems, moving through networks. And what GTG-1002 suggested was that some of those constraints were beginning to disappear. What has changed since publication is that now we have the vocabulary and the case study. Every board, every CISO, every compliance officers can point to a specific incident and ask, “Could this happen to us?” And real story was not to quote. The real story was the operator was beginning to change.

Cole French:

I think I kind of touched on this at the beginning, but I think we’ve all known that AI-enabled cyber operations was something that was coming at some point in time. So this kind of was the first prominent instance of us seeing that out in the real world. So where do you think the discussion stands today as it relates to AI-enabled cyber operations and the move from them being largely theoretical to being real world?

Nury Turkel:

So what is changing right now is not the most critical aspect. I think the speed is something we need to appreciate. Six months ago, many people still viewed autonomous cyber operations as largely theory, something that people read in the news or some people talking in the media. But today, we’re debating how quickly these capabilities will mature and what guardrails should exist. The data now catching up to the warning, CrowdStrike’s 2026 global threat report shows AI-enabled adversary activities up nearly 90% year over year. Average breakout time is now about half an hour, 29 minutes to 32 minutes, and 82% of those detections were malware-free attackers moving through the systems with legitimate tools and stolen credentials. So today what has changed, and I think this should deserve a lot of attention, is the prompts on the AI platform are the new malware.

Cole French:

Yeah. And I know something that I’ve talked a lot about with other folks is really there’s an art form, so to speak, to working with AI tools. I think we think of them in very plain terms, I guess sometimes, at least from a user’s perspective, but the real power of AI comes with... And this speaks to I think exactly what you’re talking about. The power of AI comes from the way in which we can work with AI and prompt it. So to what you’re saying about the prompts I think is right on target, that really the better we get as humans at prompting AI, the better AI is going to get at doing some of these things you’re talking about and it becoming really a cyber operations tool, both obviously I think in a positive light, but also in a negative light, like you just touched on.

Nury Turkel:

Yes. When people look at the cybersecurity concerns, cyber attacks, traditionally they just look at what can be done afterwards, but something that is missing that conversation, that conversation is that what do we do preemptively and what kind of better programs specifically in the software realm can we put in place to prevent some of these things from happening? And now with AI-enabled cybersecurity threats, things much, much complicated. So there’s something important. The definitive framework for mapping adversary behavior still has no identifier for agentic AI-orchestrated GTG-1002 use, for example, as Anthropic reported. And our way of approaching to the extent, I take huge pride of being a national security professional, is already behind our adversaries, for example, China. So what this scenario, what this report that Anthropic shared with the public revealed is that GTG-1002 showed that AI has become a forceful multiplier for state-sponsored operations.

So in other words, you no longer need a large high skilled human team to run a sophisticated multi-vector campaign. You just need a good prompt and the compromised credentials and time. And that changes the threat landscape permanently. And this is something that deserves a lot of attention.

Cole French:

I like what you said there too and it’s got me thinking what I was talking about as well. The prompts, the way in which we think about AI I think is much more what we are telling AI to do. So that’s a very forward-thinking, if you will, way of thinking about it, using it, interacting with it, whereas what you’re talking about, the defensive side of things, that’s a different way of thinking of and using AI. So I think I can see how it’s going to be a challenge to put those sort of defensive guardrails in place. But I do want to also pull the thread on the China thing that you mentioned, which the Chinese were behind the GTG-1002. So as it relates to AI and national power, just speak on what you think that particular attack revealed about the future relationship between AI and national power, and I guess AI and the US and China specifically.

Nury Turkel:

Thank you. That’s a great question. So there are really two dimensions. First, as I wrote in the piece, China can use AI as multiple layer for intelligence collections, cyber operations, analysis and decision support. And then the other is that China’s intelligence services and research institutions have every incentive to understand the strengths, weaknesses, limitations, and the vulnerabilities of leading American AI system or AI labs or AI platforms. If AI is becoming a strategic technology, then understanding the technology becomes an intelligence priority. That’s something that Chinese understood and it has demonstrated that understanding through public statements being made by senior Chinese leadership and their attempts to get access to Americans advanced technology chips, for example. So they clearly understand that priority. So historically, the country thought intelligence about military capabilities, industrial capabilities, capacity, scientific breakthroughs. Today, advanced AI belong in the same category. If AI becomes a source of national power, understanding AI becomes an intelligence mission. And this is also something that China understands very well.

So I think the AI sits at the center of this US-China competition, specifically in the context of tech competition or in AI, who leads the AI. It affects economic growth, it affects military capability, it affects intelligence collection, it affects scientific research. And on China side, they have no money problems. They have a ton of money being already poured into the R&D field. They are advancing and laser-focused in that, and it affects influence and information operations. So when we speak about competition in separate categories, specifically in the context of US-China relations, economic competition, military competition, technological competition are the center of it. So AI touches all of them simultaneously. That’s why I increasingly view AI as a strategic technology rather than simply a commercial technology that we used to know. So AI is not another industry in the context of US-China competition, it’s enabling technology for nearly every other domain of a national power.

Cole French:

It essentially works as a force multiplier. It can be used as a force multiplier across really any industry or domain. Is that what you’re getting at?

Nury Turkel:

Yes, that’s the right way to put it. So what concerns the policymakers today in a broader scheme of things is that if it prevents too much of a regulation or too much a focus on what to do to put rules and regulations with corporate governance, it may hamper the scientific in the R&D and also the market economic competitiveness. We’ll talk about it down the road as we continue the conversation, but there’s a huge misunderstanding of the challenges that we are facing as a society as a country, specifically in the face of or in the backdrop of US-China competition, that this is an unprecedented situation that both countries found itself. In some corners of the policy community, you hear folks saying, “Oh, we should find a way to work with the Chinese.” There’s some validity to that desire. As somebody who’s studying following Chinese politics for a long, long time, I can say with certainty that the China has a different goal in this space, in technological space. They feel that they missed out the industrial revolution, the information age, and now the age of AI, they believe they feel compelled that they must lead.

But one common thing, the common concern I think that both the United States and China share is the cybersecurity, specifically in the age of AI. And when you hear experts with a technical background talk about these concerns, sounds like doomsday, but the Chinese cares two things very much. One is the standing in the world or perception or the image in the eyes of the world community. The other is the economic interest.

They do worry if something goes out of hand as a result of the threats that we’ve been discussing, it will cripple their economy. So they are fair to say equally concerned and there may be a possibility for the US and China to work together in some of these concerns, not on the specific AI, agentic AI, the physical AI and others, but in the cybersecurity realm, I think there’s some possibility that two countries may be able to work together.

Cole French:

I think that’s an important thing you just touched on there in a very detailed way, but I think something that I’ve always thought of as it relates to US and China relations is really what you just pointed out there at the end, authoritarian regime versus democratic political process. So when you start talking about strategic competition or really just competition in general, the playing field functions very differently in each of these countries, even from a military perspective. In China, they can allocate resources from a very high level, within the Chinese government can say, “Hey, we’re going to dedicate all these resources to AI and all these other,” whatever those things might be. But it’s a very strategic and directed from a very small place, if you will, with a lot of power. Whereas here in the US, functions very differently, even though sometimes it may seem like it doesn’t, it certainly does.

We have a political process, funding is scarce, you have to make your case, all those kinds of things. And there’s a lot of different perspectives out there that factor into and influence the direction that we take some of these things. So it kind of gets to the playing field component, I guess, where yeah, the competition is there, but the playing field and what the underlying stakes are and what the underlying stakeholders are and how those function is very different between the two countries.

Nury Turkel:

You put your finger on something very important that I have been also spent so much time and energy over the years. I started researching, writing, speaking about the algorithm that are used for population control in China that started in late 2016. And last May, I wrote a piece and also a policy memo for the Hudson Institute where I was a senior fellow promoting the idea of American AI. That came to mind. So the release of DeepSeek triggered that idea. So the comparison was we have leading AI labs in the United States. They for the most part have been acting responsible in the case of Anthropic without any government regulation, government oversight. They are willing to put forth or share what they identified. This is unthinkable in China. And also in the case of Anthropic and the United States government, the Pentagon, the ongoing litigation, the dispute is something unthinkable would happen in China.

So the technology firms in the United States have accountability to the court and general public. The Florida recently take a legal action against OpenAI. That kind of things cannot happen in China. So we are still in a better position. So I prefer American AI over Chinese AI for a whole host of reasons. And also, I am also in favor much like the AI technology firms that a government regulation should be put in place. During the Biden administration, that willingness to subject themselves to regulatory compliance, governance was about 20%, but now it’s 80%. That remarkable shift demonstrates that corporate America or American tech firms are cognizant of the potential harm that AI could cause as such the government regulation must be put in place. I’ve been a regulatory compliance lawyer my entire career. One common comment that I often hear when I put forth ideas or compliance concerns, I said, “Is this illegal? Is this what the law says?” And then the answer is, yes, this is what the law says, but there’s also geopolitical policy complications that you need to follow, national security complications that you need to follow.

And corporate leadership, recognizing that danger, a potential risk, legal, reputational investment is a really good thing. And also here, the one thing that we also should feel proud of our country is that we can hold the engineers to account and our engineers in the tech firms are not, lack of a better term, puppets of the US government. In China, it’s the opposite. I don’t know if you saw it in the news that the Chinese government’s banning the AI engineers, the skilled workers leaving the country. There was a report either in the Financial Times or Wall Street Journal a few days ago, several days ago that they’re preventing the talent leaving, so something like that cannot happen. So I take American AI every day over the Chinese AI.

Cole French:

So to that point, too, you’re talking about the commercial approach that we use here in the US, the corporations functioning in a competitive economy with accountability versus the nationalistic approach. So do you think that AI currently is still primarily a commercial technology or has the balance shifted and it’s become more of a national security technology? Where do you think we are in that pendulum swing?

Nury Turkel:

I think in the last several months, particularly since early this year, a few companies being in the news, all three AI companies going IPO, NVIDIA’s willingness with desire to sell more chips. I think there’s a healthy debate merging, is still ongoing, and it’s a foundational aspect of a coherent legislative mandate eventually that healthy conversations that we’re hearing specifically on what is more important, selling more chips or defending national security? So American companies operate under investor pressure to public research, reputational stakes attached to the safety. And what Anthropic did with Claude Mythos recently, for example, is the most capable model, their most capable model deliberately withheld from public release giving defenders access through a Project Glasswing. So that shows, some people think that’s a market stunt, but to me that’s a display of a responsibility. I think the OpenAI did something similar as well. So I think that the trajectory is going to the right direction.

And also, the public skepticism on AI, you hear about the tech leaders talking about most of the entry level jobs will be wiping out, 20% as Dario said on CNN, and also as a country we’re not ready. That kind of a warning, even if it sounds very grim, is making people more interested in the subject. Oftentimes in the corporate world, the consumer voice is very important, the corporate decision making. It sounds trivial when you have a consumer expressing concerns over certain business decisions that the corporate America makes or corporate executives make, but in the longer strategic term, the corporate leadership listens to what the consumers are saying. At the end of the day, they make their profit, they make money through purchase. So the consumer activism now, the consumer voice is also forcing companies to find a balance between commercial interest and national security concerns.

Cole French:

So you mentioned NVIDIA, which caught my attention, and I think a lot of people have probably heard about NVIDIA, obviously from a product standpoint, knowing who they are, brand, all that kind of stuff, but also some of the controversy that has come up over the last six to eight months over whether they can sell their chips in China. So really this question’s less about NVIDIA, but balancing innovation, economic competitiveness and national security. So I think you were already going in that direction, but how do you think leaders should think about that tension, and somewhat related to NVIDIA, but I think more broadly, those three things, innovation, economic competitiveness, and national security?

Nury Turkel:

I think this is something that deserves a lot of attention and careful thinking for a couple of reasons. First of all, United States as a country encourages free thinking, innovation, capitalism, market economy. So inherently, what NVIDIA is trying to do is in line with American business tradition. There’s no doubt about it. But at the same time, the ongoing debate is not really about NVIDIA. It’s about how an open society preserves innovation while protecting technologies that have a strategic significance, export controls buy time and they don’t win the race. I’m a compliance lawyer. I do a lot of work for clients on import and export control areas.

We’re not trying to prevent American companies as a society to sell their products and it is not about winning the race. This is about responsible way of making money. The existing laws, EAR, Export Control Administration that is a part of the BIS operations is somewhat outdated. Case in point, the AI chips is inherently dual use. So how do you make sure that the Chinese, for example, the Chinese PLA will not use the NVIDIA, the advanced American chips for military modernization, that is something that the policymakers have been discussing but have not been able to find a clear answer.

The policymakers are increasingly concerned about transferring strategic important capabilities to competitors, namely China, but really that expression, that concern is not really turned into tangible action. What I think should happen is a couple of things. One, we need to be mindful that China’s interest in our advanced chips is not something that the Chinese have been planning for and desire to have specifically access to the blueprint. When you look at a lot of advanced products or modern products, whether it be EV vehicles, handheld devices, telecommunications, equipments that the Chinese have have a lot of foundational connection to the Western technology.

They have not been able to produce or make the machine, like AMSL machine that makes the advanced chips. It’s very, very complicated process. So I think we still have an advantageous position. We need to be able to have a clear mind. It’s not about selling chips. The diversifying the market to other countries and also forcing companies to be transparent, I mean the buyers of the media chips, and finding way to using technology to track where it ends up, like knowing your customer is one example, is the right initial steps can be taken. And also the other thing that must be addressed is that selling advanced chips should not be a transactional matter, a matter of a transactional discussion. This is a matter of national security. When you listen to both sides, for example, those in the US government advocating to sell the chips to the Chinese, and also the company often said, “Oh, we wanted to make the Chinese addicted to the advanced American chips.” It does not work like that.

The China today is not the China 10 years ago where Apple tried, and successfully to the extent, to make the Chinese people addicted to the Apple product. This is a country that wants to replace. This is a country that wants to take over. This is the country that has a concerning relationship with nefarious actors, hostile regimes around the world. So the national security threat is there. And something is very important, which is the American advanced chips already been used for Chinese military as reported a few days ago and also been used for China’s security. There is a documentary published by Bloomberg Original that shows China’s data centers in the far west is using NVIDIA chips. So the question today is not about whether to innovate, protect. The questions how to do the both at the same time. I often tell my clients, being a compliance lawyer, my job being compliance lawyer is not telling no to everything, but there’s a way to do it ethically, legally, responsibly.

Cole French:

I think those are three good tracks to think about when making decisions. And you talked specifically about export controls, which gets me thinking about regulations, regulatory risk. You also mentioned supply chain, hinted at supply chain, and really this is something we’ve talked a lot about. Here in the compliance space, we do a lot of work and we do a lot of talking on this podcast on the Cyber Compliance & Beyond Podcast about compliance. And we’ve worked specifically with the cybersecurity maturity model certification, which is really kind of aimed at helping prevent stuff like what we’re talking about really. And supply chain is a key piece of that. So kind of shifting the conversation a little bit, and we’ve done episodes on export controls and supply chain. We’ll link to those in the show notes so you can go back and listen to them if you’d like.

This is part one of our two-part conversation with Nury. In part two, we’ll dig deeper into regulation, export control, supply chain risk, and what leaders can do right now to prepare for a world where AI-enabled attacks become the norm. Thank you for joining us on the Cyber Compliance & Beyond Podcast. We want to hear from you. What unanswered questions would you like us to tackle? Is there a topic you’d like us to discuss or you just have some feedback for us? Let us know on LinkedIn and Twitter at KratosDefense or by email at ccbeyond@kratosdefense.com. We hope you’ll join us again for our next episode, and until then, keep building security into the fabric of what you do.

Have a topic you’d like to discuss?
Use our contact form to send us a message.
Get updates from Cyber Compliance & Beyond
Sign-up to receive email alerts when podcasts are available.