US Federal News Bureau
Written by: Tathagata Sen
Updated 4:38 PM EDT, September 11, 2026

The FBI released its first agency-wide, unclassified cyber strategy on September 9, addressing how AI is increasing the speed and capabilities of criminal and nation-state cyber adversaries.
The strategy urges organizations to move toward continuous patching, the practice of applying software security updates as they become available, rather than on a set schedule.
Two top FBI officials previewed the strategy a day earlier, on September 8, speaking at the Billington CyberSecurity Summit, according to a CyberScoop report.
Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said there was an exponential increase in the use of AI by both nation-state and criminal actors. The FBI’s own crime data backs that up, he said, pointing to figures in its latest annual report on digital crimes.
Despite AI’s growing role, Bilnoski said most attacks still succeed because organizations skip basic cybersecurity steps. He pointed to the FBI’s ongoing push around 10 fundamental defensive measures, including multifactor authentication. “What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” he said.
Colleen Ferranti, an assistant section chief in the FBI’s cyber engagement and intelligence section, said AI is also speeding up how fast vulnerabilities are discovered. That means organizations can no longer patch on a quarterly schedule, she said. She called for continuous, risk-based patching instead of relying on set update windows like Patch Tuesday.
The FBI’s new strategy includes a dedicated AI section. It states that FBI Cyber will use AI tools to sort large datasets, speed up malware analysis, map attacker infrastructure, and identify patterns human analysts couldn’t process at the required pace. The strategy also calls for the rapid but secure adoption of agentic AI to scale defensive and disruption operations, subject to human review and legal controls.
The FBI will continue to develop its Computer Network Operations program, which provides investigative teams with court-authorized or otherwise lawfully authorized tools to remotely collect information, conduct surveillance, and disrupt cybercriminal and nation-state activity when traditional methods are insufficient.
For chief data officers (CDOs), the FBI’s message lines up with a broader shift happening across government: AI is making old, familiar threats move faster in addition to enabling new threats. That means AI governance needs an urgent update on existing practices, like patch management, access controls, and vulnerability response, that many organizations were already behind on before AI entered the picture.
The call to abandon quarterly patching in favor of continuous, risk-based patching is a concrete, actionable takeaway CDOs can apply now.