Autonomous Cybersecurity Systems and Legal Responsibility: Regulating AI-Driven Cyber Defence
DOI:
https://doi.org/10.5281/t9afp358Keywords:
Autonomous Cybersecurity, Artificial Intelligence, Automated DefenceAbstract
The emergence of artificial intelligence has enabled the development of autonomous cybersecurity systems capable of detecting threats, analyzing malicious activity, and initiating defensive actions with limited human intervention. These technologies have the potential to improve cyber defence by responding to attacks at machine speed and continuously monitoring complex digital environments. However, autonomous cyber defence also raises significant legal questions concerning responsibility, proportionality, authorization, privacy, due process, and accountability. This article examines the intersection of autonomous cybersecurity technologies and legal responsibility, focusing on AI-driven threat detection, automated incident response, defensive network actions, false positives, algorithmic decision-making, and human oversight. It argues that increasing autonomy in cybersecurity systems creates a potential accountability gap when automated actions cause unintended consequences or affect third-party systems. The article proposes a risk-based governance model based on predefined authorization limits, human supervision, auditability, explainability, proportionality, technical safeguards, and clear allocation of responsibility among system operators, developers, and organizations. The article concludes that autonomous cybersecurity can significantly strengthen digital resilience, but its deployment should remain subject to transparent legal controls and meaningful human accountability.
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Dr. Daniel Ben-Ami , Dr. Yael Cohen (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.


