Keira Keogh: Ireland at 60% in AI cyber defence race
Keira Keogh addresses the growing cyber risks from AI, including deep fakes, automated phishing and the new potential for autonomous exploitation of vulnerabilities. She warns Ireland is in a short-term race to fix systems while threat actors use the same tools, and that an AI gap could leave smaller organisations exposed.
Main points of the address
Keira Keogh outlines how AI is already being used to generate false content, deep fakes, graphic imagery and phishing lures, and how those tools bleed into national cyber security. She stresses that nation-state and non-state hybrid warfare techniques now include AI-driven manipulation across online chat spaces and malicious automation.
How AI changes exploitation and defence
The speaker describes recent research suggesting AI can autonomously move from detecting a vulnerable system to exploiting it, accelerating the attack cycle. That shift creates a race: how fast can organisations and states patch vulnerabilities versus how fast attackers find and use them?
The risk of an AI gap
Keogh warns of an emerging division between better-resourced organisations that can adopt defensive AI tools and smaller entities that cannot. She explains this could produce a structural 'AI gap' where some become more secure while others fall further behind, with national consequences.
Policy implications and readiness
Keogh estimates current national readiness at roughly 60 percent and urges stronger measures in the next national cyber security strategy, plus training and legislative clarity for new services. She argues a 2-1 performance will not be sufficient in the near term and that urgent action is required to stay ahead of malicious actors.
We publish thousands of recordings to make Irish politics transparent and resistant to manipulation. Spotted an error? Report it — together we are building a reliable archive of Irish politics.
Will those AI servants try and sell you raffle tickets as well? I don't know. Apologies for being late and thanks to all the witnesses. I was listening online, so excuse me, I'm not sure which one of you mentioned this, but we were talking about the top five AI risks earlier and somebody talked about one of the big risks being the ability of AI actors to sow division within society, and so I'm wondering if you could give us some examples of that and, you know, I think a lot of citizens are maybe unaware of how they've been manipulated, so how we can maybe tackle that. Apologies for, I was listening, so I didn't have the phases in front of me. I think we both mentioned it in passing, Deputy. Apologies for it. So what we're talking about now is essentially the various different types of hybrid warfare that are applied by nation state actors and non-state actors in a variety of different ways. We don't have a formal role in countering FIMI or foreign disinformation essentially, but we do report on it from time to time when we come across it as part of our reporting, so we're in that space to a limited extent. We've seen AI being used repeatedly in generating false content, both deep fakes, so in other words video that looks like real thing in generating false content, both deep fakes, so in other words video that looks like real thing but isn't, and there's been some reporting on that around events late last year as well, and also in the use of just general graphic imagery, comics etc. So it is used in cyber is that those same tools can be used to generate lures as part of phishing, to click on links or open documents or whatever it might be. So it bleeds into our specific world very readily, but it's also a much broader societal problem that has to be addressed as well. Mark may have something else to add to that. No, well other perhaps to complement that from a defence forces national cyber defence, or sorry military cyber defence strategy perspective, one of the pillars we have is cyber awareness training. So this area would be routinely addressed within the military defence community on island, around you know the potential dangers around deep fakes, and we do a certain amount of training for analysts within our security operations centre around the likes of deep fakes etc, to try and alert people to the dangers. So it's something that we're very sensitive to and we try and stay abreast of. And in relation to, so obviously there's deep fakes graphics and images and phishing links, but in relation to bots in online spaces and chat spheres, are you talking about that as well when you're talking about zone division or specifically more so graphics and links? You know I'm thinking about you know the amount of people that are stirring up conversation in chats and when you go into them it's a fake profile, a fake person, but they can they can generate you know conversations at the speed of light and even faster. And is that a concern or is it more so the graphics and the clicks? It's outside of our remit to an extent, it categorically is happening, but we don't have a formal statutory basis to engage in it, so we're kind of outside of our remit even in talking about that. Defence forces may have a broader perspective though. No, all I would say is that you know there is a senior officials group you know charged led by DFA around the whole hybrid space and this is an element of that, so it is being addressed nationally. We have a member, we have a personnel who attend that forum, but it's more appropriately addressed at that forum. Perfect, and then you also mentioned that we are you know in a race, AI Defence is a race, where is Ireland in that race and what do your organisations need to get ahead within that race? So that would have been me Deputy, and I mean this is very complex to explain because essentially you kind of need to go back and understand how the vulnerability management process works and what that means for society, but cut it very, reduce it really quickly. What we have now is the arrival of tools that can scan the entire global IP address structure and find vulnerable systems. Now until recently, as in last week, there was no AI system around, it hadn't been proven that it could be done, that could actually autonomously go from here's a vulnerable system, I'm going to hack that, and then doing it by itself. So you had tools that could do part of the process of a 30 stage process, they could do stages 7 to 15 for example, but you had to have people in the loop. Now it seems very likely given the research published as recently as last night that it is possible to do it, it's theoretically possible to do it, the tools exist. So what that means, and this has huge ramifications, and we could spend the rest of the week talking about what that might play out and there's lots of uncertainty, however at the very least it's clear that A, we're likely to see a lot of vulnerabilities being detected and fixed quickly, and that's a problem in the first instance because the ability of organisations to do all that fixing quickly will be stretched and that's a challenge for society, not just us. But secondly, there's a real possibility that threat actors, it's happening already, we had multiple cyber-enabled attacks late last year, will start looking for the same vulnerabilities. So now we're in a race, how fast can we fix versus how fast can the bad guys find and exploit, and that's the race we're in in the short term. Longer term we're in a longer and much more complex race where some organisations, some entities can fix these structural problems in a much more adept way. So large organisations can take on these tools, procure the necessary services and products and fix their vulnerabilities, but smaller, less well-off, less capable organisations won't. That's what I referred to in my opening address, the potential for an AI gap to emerge between the cyber-haves and the cyber-have-nots, where some people will be, for want of a better term, fine, or even better than fine, more secure than they were before this started. But some entities won't because they just can't keep up, and from a national perspective that's an issue, and it's one of the types of issues we would hope the next national cyber security strategy would have measures to identify and fix as well, because we have a role in that, if you like, catch-up space. And so to put it in a really simple layman terms, if AI defence was an exam tomorrow, what percentage would Ireland score in our readiness? So to extend the metaphor briefly, if this was an exam, the exam questions haven't been written yet, in fact no-one even knows what the subject really looks like. But we're starting from a fairly strong position in that we have existing programmes that does essentially the same things for years, and we have new services already procured, which we can't launch yet because we don't have a legislative basis, that actually deal with exactly the issues we're talking about. So we're in the 60 per centile, we're getting a strong 2-1, but the problem is... I wasn't sure if I was going to get a number there, but 60 per cent sounds... But the problem is, Deputy, that a 2-1 won't cut it two years from now. Everybody needs to be a first or you fail, and that's the problem. It is not good enough is good enough, it is you have to be very good or else you're nowhere.
Thank you for downloading 🙏
If you publish this material on social media, we would be very grateful if you tagged VideoParliament. It helps us reach more people and keep building a transparent archive of Irish politics.