The Center for Cybersecurity Policy and Law (CCPL) has released a new paper, Playbook for Expanding Cyber Resilience in the Age of Frontier AI Models, examining how governments with constrained cybersecurity resources can adapt their national strategies as artificial intelligence reshapes both cyber threats and defensive capabilities.

The paper’s central argument is straightforward: frontier AI is changing the cybersecurity environment, but it does not replace the fundamentals of effective national cybersecurity strategy. Governments still need strong governance, skilled workforces, critical infrastructure protection, public-private collaboration, and sustained investment. AI should be treated as a tool that can strengthen those capabilities where it provides measurable value, rather than as an objective in itself.

For countries operating with limited budgets, personnel, or institutional capacity, that distinction is particularly important. The paper cautions against assuming that every government needs to replicate the AI capabilities of major powers or immediately invest in the most advanced models. In many cases, foundational investments such as asset management, multi-factor authentication, vulnerability management, incident response, and workforce development may provide greater near-term security benefits. At the same time, AI can serve as a force multiplier by helping smaller teams process threat intelligence, support incident response, improve government workflows, and make better use of scarce resources.

CCPL launched the paper during a private lunch discussion at the Digi Americas LATAM CISO Summit in Cancún, bringing together government officials, cybersecurity leaders, and private-sector representatives from Costa Rica, El Salvador, the Dominican Republic, Chile, Mexico, Honduras, and other countries across the region. The roundtable kicked off with introductory remarks from Cisco.

Rather than presenting the paper formally, the discussion focused on testing its recommendations against the realities governments face. Participants explored the gap between international conversations about frontier AI and the immediate needs of national cybersecurity programs; the challenge of moving from strategy to implementation; workforce and funding constraints; and the role industry and international partners can play without creating long-term dependency.

A recurring theme was that success should not be measured by how much AI a country adopts. As the paper emphasizes, the more meaningful measure is whether governments become more secure, resilient, and better prepared to manage cyber risk.

The new playbook is intended to provide governments with a practical framework for making those choices—starting with national risk, strengthening foundational capabilities, identifying targeted opportunities for AI, and scaling investment as institutional capacity and experience grow.

Read Next

Expanding Cyber Capabilities Against Transnational Crime

Key details of a new presidential memorandum authorizing companies to conduct cyber operations against transnational criminal organizations remain to be developed.

The EU’s e-Evidence Package Takes Effect Today. Now Comes the Hard Work.

The European Union's new e-Evidence framework promises to dramatically transform the way law enforcement can access data for criminal investigations and prosecutions across borders.

European Commission Publishes Final Cyber Resilience Act Implementation Guidance, Addresses Concerns Raised by Cybersecurity Coalition

The Cybersecurity Coalition welcomes final guidance on the Cyber Resilience Act that provides covered entities with clearer guidance on the landmark product security regulation.