Skip to content
Future

Cybersecurity and AI in 2040

What Could Cybersecurity and AI Look Like in 2040?

Cybersecurity and AI in 2040. Trying to predict technology fifteen years ahead is always dangerous. Go back fifteen years and ask people to describe today’s world of generative AI, autonomous software and billions of connected devices and most predictions would have missed something important.

So I am not going to pretend that we know exactly what cybersecurity and AI will look like in 2040.

What we can do is look at the direction in which technology is moving and ask what happens if some of those developments continue. That produces a rather different picture from the cybersecurity we know today. Antivirus software will probably still exist in some form, but the idea of installing one security product on a computer and expecting it to protect our digital life may eventually seem rather old-fashioned.

Our digital life is no longer contained inside one computer anyway.

It is spread across phones, cloud services, cars, homes, identities, payment systems and increasingly AI itself. Cybersecurity will have to follow it.

By 2040 we may no longer think about protecting a computer. We may think about protecting a digital identity that happens to use computers.

Your AI may become part of your security

One development I find particularly interesting is the possibility of a personal AI security agent.

Today we still expect people to make an extraordinary number of security decisions themselves. Is this email genuine? Is that website really my bank? Should I click this link? Is the person calling actually who he says he is? Is an app asking for information it really needs?

We then blame users when they occasionally get one of those decisions wrong. That becomes increasingly unrealistic when AI can generate convincing emails, voices, websites, photographs and eventually video almost instantly. The old advice to “look carefully for something suspicious” becomes less useful when the fake can look every bit as professional as the real thing.

A personal AI could potentially evaluate many of those interactions before we ever see them. It might compare a message with previous communication, check whether a domain is genuine, examine the origin of a payment request and recognise that somebody who appears to be a familiar contact is behaving in a completely unfamiliar way. Perhaps it doesn’t even warn us about most attacks. It simply deals with them.

That would be a major change. Cybersecurity would move further into the background, much like many safety systems in a modern car. We know they are there, but we don’t consciously operate them every few seconds. Of course that creates another question immediately: who protects the AI that is protecting us?

If our personal security agent becomes a gateway to our identity, communications and finances, compromising that agent could be considerably more valuable than compromising the laptop on which it happens to run.

The identity may become more important than the device

For a long time cybersecurity concentrated heavily on machines. Protect the PC, secure the server and keep malicious software outside the network.

That model is already changing.

People move between devices and cloud services constantly. An employee can be working on a company laptop in the morning, a phone an hour later and a cloud application somewhere else in the afternoon. What connects those activities is increasingly not the device but the identity.

By 2040, proving who or what is requesting access may therefore become even more important.

And I doubt that authentication will simply mean entering a stronger password. Security systems can increasingly consider behaviour, devices, biometric signals, previous interactions and the context in which something happens. A login can be technically correct and still be suspicious because everything surrounding it is wrong. This changes authentication from “prove who you are once” towards something closer to “continue demonstrating that this interaction makes sense.”

There is a downside here too. Continuous verification requires information, and information about behaviour can become extremely personal. A security system that knows enough about us to recognise an impostor may also know an uncomfortable amount about us.

Security and privacy will therefore continue to pull in opposite directions.

Cybersecurity starts moving faster than people

AI will not only protect people. It will increasingly confront other AI systems.

An offensive AI can search for weaknesses, analyse responses and adapt its approach. A defensive AI can observe the same activity from inside the network, combine it with information from other systems and change its defence.

The interesting part is not that one machine will somehow “fight” another machine in the science-fiction sense. Neither needs to be conscious or even understand that humans regard the interaction as a battle.

They only need objectives and the ability to adapt.

Once both sides can do that, speed becomes extremely important. An attacker changes its approach, the defender detects the change and responds, after which the attacker changes again. Several of those interactions could eventually take place before a human security specialist has properly investigated the first alert.

That leads to a difficult balance. We need autonomous defence because people may simply be too slow, but the more authority we give an AI to act without us, the greater the consequences when it makes the wrong decision.

The fastest security system is not necessarily the safest one if nobody can stop it from making the wrong decision equally fast.

Can cybersecurity predict an attack before it happens?

Prediction is one of the more attractive promises surrounding AI security.

The comparison with weather forecasting is tempting. Collect enough information about vulnerabilities, criminal activity, previous attacks and unusual behaviour and perhaps an AI can identify that the probability of an attack is increasing before the attack actually begins.

I think some form of this is quite plausible. We already use threat intelligence and risk indicators today. AI can potentially combine vastly more signals and find relationships that humans would struggle to recognise.

But we should be careful with the word predict. A weather system follows physical processes. A cyber attacker is an intelligent opponent who can deliberately change behaviour after discovering how a defence works. Cybersecurity prediction therefore has an adversarial element that weather forecasting doesn’t. I would be suspicious of a future system confidently announcing that there is exactly a 92% probability of ransomware next Tuesday.

A more realistic system may tell an organisation that several risk indicators have changed, explain why its exposure has increased and recommend additional protection before anything happens.

That is still enormously useful.

It just isn’t a crystal ball.

When a cyberattack can affect the physical world

Perhaps the biggest difference between cybersecurity today and cybersecurity in 2040 will be what is actually at risk.

A compromised home computer can already be a serious problem. But increasingly computers control things that move, heat, cool, manufacture, transport or even help keep people alive.

Connected vehicles, industrial installations, medical technology, home robotics, energy networks and smart infrastructure expand the meaning of a cyberattack. The consequence may no longer be stolen information or an encrypted hard drive. A digital failure can produce a physical result. That makes the separation between IT security and operational safety increasingly difficult to maintain.

A future security system protecting an autonomous vehicle, for example, cannot simply shut everything down whenever it detects something unusual. Stopping may itself create a dangerous situation. An industrial AI faces similar problems. The technically safest cybersecurity response is not automatically the safest response for the physical process.

Once again, context matters.

And then there is quantum computing

Quantum computing deserves a place in any discussion about cybersecurity in 2040, but it is also an area where spectacular predictions are easy to make.

Sufficiently capable quantum computers could threaten some of the public-key cryptographic methods on which modern digital communication depends. That doesn’t mean all encryption suddenly becomes useless, nor do we know exactly when cryptographically relevant quantum computers will become practical at scale. The important point is that organisations cannot wait until such a machine exists before thinking about the problem. The transition towards post-quantum cryptography has already begun, and over the coming years enormous numbers of systems, protocols and stored data may need to be assessed and eventually migrated.

AI could help identify vulnerable cryptographic dependencies, manage migrations and monitor complicated infrastructures, but AI doesn’t magically solve the mathematics of the problem. Quantum-resistant security will still depend on cryptography, standards, implementation and good engineering.

Sometimes the future still needs rather traditional IT work.

Security may eventually become almost invisible

If all of these developments come together, cybersecurity in 2040 could become something most people rarely interact with directly. A modern car already makes countless small adjustments without asking the driver for permission. Stability systems, engine management and safety electronics operate continuously in the background. We don’t receive a message every time the vehicle makes a correction.

Digital security may gradually move in the same direction.

Our devices, identities, networks and AI assistants could continuously evaluate trust and risk without asking us to approve every decision. Most attacks might be rejected before we even know they existed. That sounds ideal, but invisible security also requires enormous trust. If an AI decides which website we may visit, which payment is suspicious, which communication is genuine and which person is really who they claim to be, it has considerable influence over our digital life.

Who sets the rules? Can we challenge a decision? Can governments or companies change those rules? What happens when different security systems disagree?

The technical problem is only part of the story.

The IT specialist doesn’t disappear

It is tempting to conclude that all this automation will eventually remove people from cybersecurity.

I wouldn’t make that assumption.

The job will certainly change. Machines may become better at monitoring huge environments and responding at speeds no person can match, but somebody still has to decide what those machines are permitted to do, what level of risk is acceptable and when an automated decision must be overridden.

In traditional computing, IT specialists spent a great deal of effort defining what computers should do. With increasingly autonomous AI, they may spend much more time defining what computers are allowed to decide.

That is not a smaller responsibility.

It is probably a larger one.

So what will cybersecurity look like in 2040?

I don’t think we will wake up one morning and discover that antivirus software has disappeared and an all-knowing AI has taken over security.

Technology rarely changes that neatly. Old and new systems will coexist. Some organisations will operate highly autonomous security platforms while somebody somewhere will undoubtedly still be running a twenty-year-old application that nobody dares to switch off. But the direction seems increasingly clear. Security is moving away from protecting individual computers towards protecting identities, services and entire connected environments. Detection is becoming more adaptive, responses more automated and AI will increasingly appear on both sides of the attack.

The biggest change may therefore not be a new type of antivirus software at all. It may be that cybersecurity itself becomes less visible to us while becoming far more active behind the scenes. And if that happens, the important question in 2040 will not only be whether AI can protect us from cyberattacks.

It will be whether we have built enough protection around the AI systems to trust them with protecting almost everything else.

Join the conversation

Your email address will not be published. Required fields are marked with *.