AI is making it possible for criminal networks to target far more Americans and American organizations without needing far more people.
That changes the scale of cybercrime.
AI Is Changing the Math
Fraud, phishing, impersonation, ransomware and other cyber-enabled crimes can increasingly be automated, personalized and repeated across huge numbers of targets. Criminal groups can run more campaigns, reach more victims and adapt faster, without having to grow their operations at the same rate.
For the United States, the implications are significant.
Americans face financial fraud, scams, extortion and identity-based attacks. American organizations face ransomware, financial theft, data theft and operational disruption. And the criminal networks behind many of these attacks can operate from foreign jurisdictions, beyond the practical reach of traditional U.S. law enforcement.
The problem is becoming increasingly clear: AI is giving criminals greater scale, while borders continue to give many of them protection from the institutions trying to stop them.
That combination demands a different response.
And today, the U.S. government took a significant step in that direction.
A Different Approach to Fighting Cybercrime
On August 12, President Trump signed a National Security Presidential Memorandum establishing a new framework for using cyber capabilities against foreign cyber-enabled transnational criminal organizations targeting Americans.
The White House specifically cited ransomware, online financial fraud and other cyber-enabled criminal schemes.
The significance is not simply that the government intends to use cyber capabilities more aggressively. Perhaps the more consequential development is how the administration plans to bring the private sector into the effort.
Under the new framework, vetted private-sector companies could work with government agencies and other companies to:
- collect threat intelligence
- identify criminal networks
- propose cyber operations
- and, when authorized, participate in cyber surveillance and cyber effects operations
There is an important boundary.
This is not a broad authorization for companies to independently “hack back.” Private-sector operations are intended to remain under the direction, control, and authority of the U.S. government.
That distinction is critical.
The private sector has capabilities that could be enormously valuable in confronting cybercrime at this scale. Cybersecurity and technology companies operate across vast digital environments. They can have visibility into malicious activity across networks, endpoints, identities, cloud infrastructure and other parts of the technology ecosystem.
AI and automation can make that visibility even more powerful by helping connect activity across environments, identify patterns, investigate threats and understand criminal infrastructure at a speed and volume that would be extremely difficult to achieve manually.
Government brings something different: authority.
Private companies can bring technology, intelligence, infrastructure, expertise and reach. The federal government has authorities that private companies do not, including the ability to direct operations intended to pursue and disrupt criminal organizations operating across jurisdictions.
The new framework attempts to bring those advantages together.
Scaling the Response
For years, public-private cybersecurity collaboration has largely focused on sharing threat intelligence, strengthening defenses, responding to incidents and supporting investigations.
All of that remains essential.
But the scale of the problem is changing.
If AI enables criminal organizations to run more campaigns against more Americans and American organizations, the answer cannot simply be to investigate more incidents after they happen or ask every potential victim to become harder to attack.
We also have to make it harder for the attackers themselves to operate.
That means connecting activity across victims, identifying the infrastructure and networks supporting criminal campaigns, understanding the organizations behind them and, where legally authorized, disrupting their ability to continue operating.
This is where the public-private model outlined in the memorandum becomes particularly interesting.
The private sector can provide visibility, technology, intelligence and increasingly AI-enabled capabilities to identify and understand criminal activity across the digital environment. The government can provide the authority and oversight necessary to act against it.
Together, those capabilities could move public-private collaboration beyond exchanging information about criminal networks toward actually disrupting their ability to operate.
That would be a meaningful shift.
The Questions That Come Next
There are difficult questions ahead.
- Which companies will participate?
- What exactly will they be authorized to do?
- How will targets be validated?
- How will liability and oversight work?
- What happens when criminal infrastructure overlaps with legitimate systems?
- How will operations be handled when infrastructure spans multiple countries?
- And as AI becomes more deeply embedded in cyber operations on both sides, how will appropriate human control and accountability be maintained?
Those details will matter enormously.
But they should not obscure the larger change underway.
AI is increasing the number of attacks criminal networks can conduct and the number of Americans and American organizations they can reach. At the same time, the borderless nature of cyberspace allows many of those networks to operate from places where conventional U.S. law-enforcement approaches have limited reach.
The United States is now signaling that its response needs to evolve accordingly.
The August 12 memorandum offers an early view of what that could look like: combining government authority with private-sector technology, intelligence, AI and operational capabilities to move beyond responding to individual attacks and toward disrupting the organizations behind them.
In an era when AI is allowing cybercrime to operate at a different scale, fighting it will require us to operate at a different scale too.