Cyber Compliance and Beyond logo

Episode 32

When AI Attacks – Part 2

Share
When AI Attacks – Part 2

About This Episode

Podcast Episode 32
July 22, 2026 - 30 mins

Following Part 1’s deep dive into GTG-1002 and the rise of autonomous cyber operations, Part 2 shifts toward what leaders must do to get ahead of next-generation AI-enabled threats. Guest Nuray Turkel explains how regulatory risk forms long before official rulemaking, often emerging first through congressional hearings, agency speeches, draft legislation, and national-security analyses. Nury argues that organizations gain an advantage by tracking long-term trendlines—such as bipartisan momentum and multi-agency action—rather than reacting to headlines, and by cultivating geopolitical literacy and responsible leadership. The conversation concludes with emerging AI-related risks to the defense industrial base and practical steps leaders can take to reduce technical debt, strengthen resilience, and stay ahead of next-generation threats.

References:

Microphone
Are you a podcast listener?

Get the latest episodes on your favorite streaming platform.

Podcast use is subject to Kratos Terms.

Subscribe via email for the latest podcast

Get email alerts on the latest episodes

Episode Transcript

Cole French:

After setting the stage by showing how AI is reshaping cyber operations and global competition in part one, today in part two, we shift from understanding the threat to understanding what leaders must do about it. Today’s conversation dives into the policy signals that quietly shape future regulations, the difference between noise and meaningful trend lines, and the leadership mindset required when technology is evolving faster than governance frameworks. From regulatory foresight to AI-driven insider threat and defense industrial-based risk, we’ll focus on the practical steps organizations need to take to stay ahead.

Welcome to the Cyber Compliance & Beyond Podcast, a Kratos podcast that brings clarity to compliance, helping you leverage compliance as a tool to drive your business’s ability to compete in any market. I’m your host, Cole French. Kratos is a leading cybersecurity compliance advisory and assessment organization, providing services to both government and commercial clients across varying sectors, including defense, space, satellite, financial services, and healthcare. Now let’s get to today’s episode and help you move cybersecurity forward.

In part one, we explored how AI is transforming the threat landscape from GTG-1002’s autonomous operations to the emerging US-China technology power struggle. Today, in part two, we shift into the operational and compliance realities leaders now face. Nury explains why regulatory risk starts with policy ideas, not published rules, and why organizations that track congressional hearings, agency speeches, draft legislation, and national security reviews consistently outperform those waiting for regulations to drop.

Policy signals appear months or even years before they become law, and companies that study trend lines, not headlines, get ahead. Nury also offers a framework for distinguishing signal from noise, including bipartisan momentum, alignment with long-term national strategy, and whether multiple institutions are moving in the same direction, a critical skill in an era of rapid AI announcements, shifting export controls, and geopolitical surprises. He emphasizes that strategic risk must be identified before it becomes a compliance obligation, urging leaders to follow threat intelligence rather than wait for outdated regulations to catch up.

From there, the conversation turns to responsible leadership, making sound judgment, the foundation of influence, recognizing China’s evolving role as a strategic competitor, and educating executives who still view China through an outdated manufacturing-only lens. As the defense industrial base adopts more AI-driven workflows, Nury highlights the rise of AI supply chain risk, shadow AI as an insider threat, and the need for organizations to use their temporary defensive advantage to reduce technical debt, leverage AI for vulnerability discovery, and build resilience into daily practice, not just as a compliance checkbox.

This episode brings our series full circle. Leaders must prepare for next generation AI-enabled threats by becoming AI literate, staying level-headed amid political noise, balancing national security with innovation, and guiding their organizations with judgment, not fear. It’s a clear roadmap for navigating a rapidly shifting future and a powerful close to our two-part conversation with Nury, who is a national security attorney and strategic advisor who helps multinational companies navigate AI governance, export controls, sanctions, supply chain risk, and US-China’s strategic competition.

He holds an active US government security clearance, is a lifetime member of the Council on Foreign Relations, and is recognized by Time and Fortune as one of the world’s most influential leaders. His analysis appears in the Wall Street Journal, Foreign Affairs, and The New York Times. We hope you enjoy this episode.

I thought something you said was really interesting to me, which is that regulatory risk, which is something companies look a lot at and are really trying to keep their finger on the pulse of where are things going from a regulatory perspective, because regulations ultimately end up being a business cost. That is something that costs me money as a business owner is whatever the regulatory landscape is and how that applies to me. But regulatory risk starts with policy ideas. So getting practical here on what we’ve been talking about, what are some policy signals that you’re seeing out there that you think business leaders should be paying attention to as it relates to AI and what we’re talking about here today?

Nury Turkel:

Thank you for that question. I’ve been an unconventional lawyer, been in the government, I’ve been in a private law firms, and I’ve been in a policy circle. Often time when I talk about these things, I focus more on the policy trend line than the legal requirements because everybody can look up the regs in the book and go one way, the other. But as you perfectly pointed out, the regulatory risk rarely begin with a regulation.

I witnessed during the time that Senator Rubio was leading much of the China legislative initiatives, I worked with his team and helped to put in place something very important called Uyghur Forced Labor Prevention Act, which puts more than 80 global brands on notice about the products they’ve been importing to the country. Presumably everything coming here is negative unless proven with the documentation that they’re not made with slave labor or forced labor. So that policy idea, the policy idea we shared at the time with Senator Rubio and his team, is that this is one of the best ways, this is the most effective ways, just telling companies everything you bring is negative.

Rebuttable presumption is the term, until you prove that you’re not using a modern-day slavery to pollute global supply chain. And that policy idea become a law. And now that companies importing today, like 301 investigation on forced labor, has some connection to it. So that piece of legislation was based on the Tariff Act and all law, but within the issues to the modern concerns, which is the modern-day slavery. So that brilliant idea of policy discussion created a law.

I’ve done a lot of FCPA work that’s also very similar, has a similar background, which is, should we allow our American companies to bribe foreign officials because the local culture, local business environment requires so? The answer is no. We should export best practices, ethical business practices to other countries, not adopt the local culture, business culture or corrupt culture. So all of the regulatory risk begin with a regulation and it’s almost begin with a policy idea.

And companies need to pay attention, as I always tell them, watch what policy before they watch the regulation. I ask them to pay attention to congressional hearings, pay attention to speeches by senior officials, pay attention to think tank reports. I’ve done a few of them myself. Pay attention to draft legislation, pay attention to national security review. Most regulations don’t emerge suddenly as I often tell them. The signals usually appear month or even years in advance. And the organizations that consistently outperform their peers are the often ones that recognize policy trends before they become a legal requirement.

So it is very important. I live and work in Washington. I pay attention to those things so that I can give a sound advice to my clients, so they can be ready. They can be quickly adjusted. This is particularly important today with a lot of uncertainties in the issues that we deal with in the policy initiatives coming out of the executive branch. And once it is out, it takes time for it to be validated or overruled as we have seen a number of things including the tariff. But at the same time, we need to be able to help the businesses to adjust quickly and be ready to the regulatory risk that are being formulated, just like the way that the Congress tried to address this advanced chip export, their number of bills being introduced.

It’s not going anywhere right now because the political ... Invites the current political environment. But in the end, these policy discussions, I believe, as I have seen and participated and contributed will become something a legislative mandate. So it’s important to pay attention to policy discussions or policy statements.

Cole French:

And I would say CMMC, which I mentioned earlier, our work in the cybersecurity compliance space, CMMC really is a great example of exactly what you’re talking about. It’s a policy that came into play many, many years ago, and the regulation has followed behind it or regulations have followed behind it. So exactly to your point, the policy was there. Most people, or I don’t know if I want to say most, but a sizable number of people, enough people or enough organizations decided that the policy was essentially optional or really the initial set of regulations were optional or there really wasn’t teeth to enforce that.

So over time, as you said, to add to what you’re saying really, a policy idea becomes regulatory, and it can become regulatory in many different forms. The initial policy itself is one thing, but over time, the regulations evolve to fit that initial policy objective. So if we start with a policy and then we implement regulations, but we find out, oh, those regulations don’t work quite right, then there’s a rulemaking process to enact additional regulations on top of that. So it becomes this thing that grows over time. So following those policy ideas, paying attention to those signals is important.

And to that end, I would say beyond that, how do you advise folks when it comes to distinguishing what’s real and what’s noise when we hear AI announcements, export control measures, cyber incidents, geopolitical surprises, all those kind of things? How do we distinguish that this thing is going to go somewhere from a policy standpoint based on different things we hear in the news? And this thing is maybe not going to go somewhere. This is just noise in the background. How do you help folks determine what to listen to and what to put to the side?

Nury Turkel:

Isn’t it important to pay attention to the difference between signal and noise, and especially today in today’s political environment? Geopolitical surprises, if I could.

So I would ask three questions. For example, does it have a bipartisan support? Does it align with a long-term strategic interest, not a single administration’s priorities? When you look at the AI-related, technology-related policies coming out of White House, sometime some companies are making this mistake because of their relationship with senior officials in administration. They are listening more to them. They think this is just one single administration priorities. That’s a mistake.

You need to look beyond one administration. That is really important signal. Multiple institutions move in the same direction simultaneously. This is also an important signal. And also, the last one I would say when Congress, national security officials, regulatory agencies, investors, industry leaders all converge on the same issue, and this is definitely a signal. So the headlines create noise. In today’s society, people read the headline that is based on the noise. And trend lines create a strategy. So headlines create noise, trend lines create strategy. And those are the things that I would watch out when I’m distinguishing a signal from noise.

Cole French:

I think those are three really good lenses through which to view what we see in the headlines really on a daily basis. So if I’m a leader of an organization and I want to say, “Hey, I want to make sure I get ahead of my compliance obligations,” this is something we navigate or help customers navigate all the time is how can I stay ahead of what the compliance obligations will be? How can I make sure that I’m operating in a way today that when the compliance obligations change in 18 months, I don’t have to go re-engineer my whole organization, my IT, all of that kind of stuff? So how do you counsel organizations on identifying strategic risks before they become compliance obligations?

Nury Turkel:

It’s a great question. We talked about a lack of the regulatory requirements or governance on AI safety. So I would do this. I would follow the threat, not the regulation, because not only we don’t have a regulation, but some of the regulations today are outdated. So regulations codify yesterday’s problem.

Organizations that read Anthropic’s GTG-1002, for example, or Mythos disclosure and immediately ask, “Could this happen to us? Are ahead of organizations waiting for cybersecurity, the CISA advisory?” That organization is in a major leadership shift, but we should not wait for a government advisory.

Threat intelligence is a form of regulatory foresight. So following the threat, not the regulatory or government advisory is something that companies should do in the cybersecurity areas. In a broader global regulatory compliance from my past experience dealing with multinationals, European and Asian companies, often time the leadership C-suite folks think that the regulatory enforcement trends, for example, in the case of the entity listing by BIS during the Biden administration and previous administrations, the FCPA antitrust enforcement actions, they think that they believe that it’s not coming to them. It’s a hyped-up situation in Washington, not really appreciating the seriousness of the trend line in Washington and thinking that it will not happen to them or thinking that the company’s too big for the United States regulatory agencies to go after is a mistake.

And then the third thing is that the companies should look at the policies and procedures already in place and proactively updating them and using those updated PMPs to raise awareness within the company. At the end of the day, the companies will not be able to comply with US or European regulatory requirements in the technology space, and in the national security space, and AI sector without adequately equipping the company employees with the knowledge.

The AI tools should not be used for grammar checking, quick research. It should be used for efficiency. It should be used for creation of a better, more advanced product that today the AI is in a very preliminary primitive used by a majority public. It should not be only used for finding out if AI is good or not, but AI should be used for raising awareness within the company, the training, and it essentially just making everybody ahead of the game or be prepared with a sudden quick policy regulatory changes.

Cole French:

It does take a gifted leader, a gifted set of folks, to really be able to envision what the future looks like, both from a compliance landscape, but also the threat landscape, and what actually is out in the world and where things are going, where things are heading. You do need both of them. I think sometimes there’s this weird relationship with compliance in the operations world where there’s a tension point, and there’s some bitterness, resentment, things like that, against compliance frameworks and governance frameworks and things like that.

But at the same time, there’s sitting back and waiting for these compliance frameworks to essentially, in a way, dictate what’s required. And then there’s weeping and gnashing of teeth about, “Oh, we have to do this, and we have to do that.” But the reality is that in many instances, like you just said, the compliance frameworks are behind what’s actually out there in the real world. So we should be looking at and operating from what’s in the real world, what’s actually out there. And we use the compliance frameworks as guidelines and as anchors to base what we’re doing on.

But if that’s what we’re waiting for, then, yeah, as organizations, we’re going to be behind. So if you want to speak on or add to that from a responsible leadership perspective, what do you think responsible leadership looks like when the world in which we live advances so much faster than governance frameworks?

Nury Turkel:

The responsible leadership, I think the leadership ... I’ve been in a leadership role. I ran a federal government agency. The things that I’ve learned over the years is that the influence comes from judgment more than expertise. When a leadership being chosen or appointed, they often look at the expertise more than that person’s ability to make a sound judgment.

The people’s advice, especially in the trusted advisors, comes from consistent, thoughtful, credible, reliable ability to make a sound judgment. And the one other thing that I’ve observed in my interactions with the senior leadership is that not appreciating that every issue deserves the same level of urgency. You only get eight hours a day, and there’s so much you can be able to accomplish. So the sound judgment, to be able to make a sound judgment and influence others, are some of the key aspects of leadership.

The influence is accumulated slowly and spent carefully. And also going back to the China concern, most of the corporate leadership today treats what our number one adversary or competitor in diplomatic sense is up against or up for. This is something that requires a lot of education. So, in other words, there’s a generation of executives who came up with when the China was primarily manufacturing story. The idea that China is a strategic competitor in AI, and cyber, and technology standard that is still counterintuitive to some of those people.

When you look watching CNBC or the interviews that they give, this is what demonstrate. They think of what we’re dealing with. China is a manufacturing hub, that has gone. That’s not the case anymore. So my job interacting with senior leadership is to help them to bridge that gap. I don’t see it as a remedial. I see it as a meeting people where they are. So this is the same message. The geopolitical risk is no longer background issue.

China is not the same China that you know. These are the things need a thoughtful, careful self-training, self-education, so that you can make a sound judgment and influence your workforce to follow through your leadership.

Cole French:

So we started our conversation talking about AI as a weapon of cyber espionage and things like that. And we’ve zoomed out and talked about geopolitical forces, the bigger picture, all that kind of stuff. So as we wrap this up, bring it back to the defense industrial base, if you will. We’ve talked about CMMC, which CMMC is really a compliance framework that is aimed at and targeted at the defense industrial base.

So to close this out, so organizations thinking about AI systems in the defense industrial base. So how should they be thinking about AI systems that increasingly have access to sensitive information and critical workflows?

Nury Turkel:

So let me start this by pointing out a few lessons that the defense contractors and compliance leaders should take. One, AI supply chain risk is now a compliance issue. If you have an AI system in your stack and you don’t know where the training data come from or what the model can be prompted to do, you have a compliance exposure. And then two, shadow of AI is unmapped insider threat. That is something need to be recognized.

On the CMMC live now, level two wave, November 10, 2026, that is unstoppable data flow with false claims at risk on a named executive. That’s also something that need to be mindful and leaders should take into consideration. There’s also a China counterintelligence story, a model that an adversary is actively probing in a counterintelligence concern, not just a data lost. Vendor risk, software risk, national security risk are increasingly the same conversation.

So organizations currently have a temporary defensive window. Right now, AI can help defenders industry vulnerability and reduce technical debt faster than adversaries can exploit them. That advantage will not last forever. The Anthropic project putting their most capable model in a defender’s hand first is a recognition of exactly this. That is remarkable without any regulatory compliance requirements in the books. Anthropic was doing that. And so the OpenAI’s similar action need to be recognized.

So the history suggests advanced capabilities eventually diffuse. The three priorities reduce technical debt aggressively now, use AI to find your vulnerability before your adversaries does, and build resilience as an organizational discipline rather than a checkbox. That is a common thing in the compliance world that people do things for the sake of checking the box. That is not the right approach. So the best time to fix a vulnerability is before your adversary can find it in a second. This is particularly important in a defense industry.

Cole French:

Just to pull the thread real quick, the insider threat thing you mentioned is something I have not even thought of. And we work a lot with organizations on insider threat and helping to interpret what is an insider threat. And some conversations I’ve had recently have illuminated that I think there is ... I don’t know if lack of understanding is the right term, but that’s what’s coming to my mind around insider threat and what exactly is an insider threat.

I think, historically, people have thought insider threat is somebody who has a malicious intent inside my organization to do harm to my organization. But the reality is an insider threat can be a standard user who makes a mistake, and I think AI fits right in with that. You can use AI in what you think is the proper form and inadvertently potentially cause harm to your organization, and that is an insider threat. That constitutes an insider threat. So we do need to think of it that way.

I think that’s a particular interesting and relevant thing as we’re talking about how do leaders think about some of these things. I think it does require us taking what our preconceived notions are of different things within cybersecurity and expanding those and rethinking them for some of these new things like AI. So just to close us out, one final question here, Nury. And again, I really appreciate you coming on today and sharing your perspective on AI and, really, so much more than that, the geopolitical implications and all of that. This has been a really rich conversation, but just want to close this out.

And we’ve talked about this, but I think it’s important, and I think I’d like for you to just distill it for us as a way of closing out this conversation. So what do you think leaders should be doing to prepare for the next generation of AI-enabled threats?

Nury Turkel:

In a corporate and the government, I made five different recommendations in the AI-powered cybersecurity threat. I’m a big believer of recognizing the issue. I think that we have diagnosis on the problems that we’re facing or problems that we’re having. So I think on the governmental level, we need to laser focus on the prescription.

I think the United States, as far as the government business community, tech community, and the society as a whole, are equipped to come up with a solution to the problems we’ve been discussing. In the context of US-China competition, I think the real question is whether the United States and China will compete, but the question is whether they can compete responsibly. So the hyperbolic statements, in some instance, emotional statement when it comes to national security concerns on chip sales issues are not really helping to resolve this unprecedented challenges that we’re facing.

On the tech world, what I think that the leadership should consider doing is continue to be transparent, continue to share best practices, continue to be honest with the people, public. You mentioned something that inside threat. I look at people how they use AI, and oftentimes, they just rely on what AI-generated information as if they are reliable. Going back to the article that you mentioned at the outset of our conversation, that’s the way the relying on the hallucination and AI platform, the Chinese find vulnerability.

So the fluency in the AI field is something ... Fluency of AI, learning how to use it effectively with a mindset that the information that they’re getting may not be accurate. The human fact-checking should be still the norm. This is for the users. So in summary, I encourage people to, in generally speaking, AI literate and the government policymakers, decision makers to be levelheaded, to be objective while recognizing the potential challenges, to come up with something that is workable, that is enforceable, that it can be implemented to safeguard AI safety.

For the corporate world, they need to find a balancing act between complying with the national security concerns or laws and also making money. The corporate CEOs have a responsibility to the shareholders. Shareholders’ main focus is return of investment. The corporate world, technology world, that is capable of inventing some of the most sophisticated technology and tools, should be able to come up with the ways to strike a right balance between maintaining national security or protecting US national security in particular, civil liberties, privacy, and getting them a return of investment or maintaining economic competitiveness in today’s complicated geopolitical world.

Cole French:

Thank you for sharing those, Nury. I think those are all great things that leaders can be doing, and not just leaders, but all of us, really. And more broadly, I really appreciate you coming on today and sharing your perspective across very wide-ranging and broad topic. And I know our listeners will really enjoy listening to this episode. I learned a lot from it, so I really appreciate you taking the time.

Nury Turkel:

Thank you very much, Cole. I really appreciate our conversation.

Cole French:

Thank you for joining us on the Cyber Compliance & Beyond Podcast. We want to hear from you. What unanswered questions would you like us to tackle? Is there a topic you’d like us to discuss or you just have some feedback for us? Let us know on LinkedIn and Twitter, @KratosDefense, or by email at ccbeyond@kratosdefense.com. We hope you’ll join us again for our next episode. And until then, keep building security into the fabric of what you do.

Have a topic you’d like to discuss?
Use our contact form to send us a message.
Get updates from Cyber Compliance & Beyond
Sign-up to receive email alerts when podcasts are available.