The convergence of aging software infrastructure, accelerating artificial intelligence (AI) capabilities, and the growing dependence of every sector on interconnected digital systems creates acute risk. But the same AI systems that are compressing the offensive timeline can also be turned to defensive purposes if policymakers organize to do so.
This paper provides expert analysis on AI-accelerated vulnerability discovery and the structural hardening of critical infrastructure software. The authors draw on a structured review of the relevant technical and policy literature, large language model–assisted research and drafting, and extensive discussions with more than two dozen experts in academia, industry, and government whose knowledge spans machine learning, cybersecurity, high-assurance software engineering, and national security policy.
The authors propose a series of rapid technical convenings, organized on a timeline of four to six weeks per cycle, in which practitioners from across sectors come together to examine the current state of AI-assisted code analysis capabilities; review the findings of Glasswing, Daybreak, and similar programs; and produce concrete guidance for infrastructure operators who want to begin the process of AI-assisted software assessment.
This publication is part of the RAND expert insights series. The expert insights series presents perspectives on timely policy issues.
This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.
RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND’s publications do not necessarily reflect the opinions of its research clients and sponsors.

