Why security should embrace AI
AI is a technology that actually benefits attackers
Disclaimer: Opinions expressed are solely my own and do not express the views or opinions of my employer or any other entities with which I am affiliated.

I’ve intentionally made all of my posts free and without a paywall so that my content is more accessible. If you enjoy my content and would like to support me, please consider buying a paid subscription:
This is my final newsletter post before heading out to Las Vegas for Hacker Summer Camp. Because I’m finalizing conference logistics and prepping for a full week, this post is a bit more candid and philosophical than usual. If anything, last week’s post showed I have a lot on my mind.
Next week is going to be a whirlwind of conversations across Black Hat, DEF CON, and BSidesLV. Heading into these events, I still don’t have a completely clear pulse on where the security community stands on AI. Security as an industry tends to lag behind major technological shifts, but the pace of change over the last year has been staggering. It isn’t clear to me whether defensive teams are actively trying to keep up, or if a large portion of the community has simply thrown their hands up in frustration. I’m certain I will meet practitioners spanning the entire spectrum in Vegas.
As many of you know from reading my past pieces, my mind constantly circles back to a core question: How will AI fundamentally reshape the security function?
I’ve been writing about this evolution for years across different phases of AI capability:
Having tracked this space for so long, my biggest ongoing frustration is security's instinctual fear of AI. I completely understand why the fear exists. Frontier models possess unpredictable, non-deterministic capabilities, and the threat surface is evolving faster than our traditional control frameworks. But AI is simply too powerful and offers too much raw economic velocity for businesses to ignore. The commercial benefits will always outweigh the abstract security risks in the eyes of executive leadership.
The Dario Amodei parallel: Focus on the adversary, not the tech
A position paper published by Anthropic CEO Dario Amodei regarding open-weights models offers a great analogy for how security should think about AI.
In his essay, Amodei clarified that Anthropic is not calling for a blanket ban on open-weights models. He acknowledged that open models without dangerous capabilities act as a genuine public good for developers and researchers. Instead of trying to halt open-source progress through protectionist bans, he argued that policy efforts should focus strictly on targeted risks: preventing advanced hardware chips from falling into authoritarian hands, stopping industrial-scale model distillation by malicious state actors, and requiring rigorous pre-release safety testing for all frontier models.
Amodei also challenged the common assumption that broad access to open weights automatically helps cyber defenders more than attackers. Because guardrails can be stripped away from open models, adversaries can easily weaponize unconstrained AI capabilities at machine speed.
This holds a vital lesson for enterprise security teams.
Security shouldn’t spend its energy trying to ban AI usage or restrict internal access inside their organizations. Trying to ban AI inside a company is the corporate equivalent of pushing for a blanket open-weights ban: it fails to address the actual threat, pisses off your internal builders, and leaves you disarmed. The right approach isn’t to oppose AI, but to focus relentlessly on two goals: keeping powerful capabilities out of the hands of adversaries, and equipping your internal defenders with superior AI tools.
The reality of adversarial asymmetry
When cloud computing and mobile architectures disrupted the enterprise, security had to adapt. But AI presents a fundamentally different operational challenge.
When a company delays cloud migration, its adversaries don’t automatically gain a technical advantage in your network. But with AI, adversaries already have access to frontier capabilities, uncensored open-weights models, and automated scripting engines. They don’t care about your internal corporate AI governance policy. They aren’t waiting for your legal team to approve an LLM vendor agreement. They are actively using AI right now to discover vulnerabilities, automate social engineering, and speed up exploit development.
By adopting a reactionary mindset, trying to block developers from using Cursor, blocking API access, or delaying model rollouts, security teams aren’t stopping attackers. They are simply forcing their internal developers into shadow AI workflows while keeping their own security analysts operating at human speed. You are intentionally creating an asymmetric advantage for the adversary.
I acknowledge that many security teams operate in cost-center environments where executive leadership treats defense purely as an administrative expense. These teams are naturally pushed into a reactive, compliance-heavy posture. Having a purely operational or reactive security team is a reality for many companies (and it’s actually ok as I’ve stated in the past), but it is not an excuse to push back against AI. Reactive teams need AI leverage more than anyone else just to level the playing field against automated threats.
Security should demand unlimited AI
Instead of acting as the corporate brake pedal, security should be the single vocal advocate for AI adoption inside the enterprise.
Even if your company is hesitant to roll out AI features to end-users, security teams should be demanding unlimited, unrestricted AI tooling for internal defense. Defenders need access to frontier reasoning models, repository-indexing agents, and automated analysis pipelines to match the velocity of external threats.
When internal auditors object to security feeding telemetry or code into these platforms, the answer comes down to evaluating the real risk profile: depending on the organization, teams should route data through trusted commercial providers with enterprise privacy guarantees (like Anthropic, OpenAI, or Cursor) or self-host open-weight models internally. Pushing back against these platforms out of fear of the vendor is a complete miscalculation. The primary risk isn’t the model provider. It’s the adversary using those exact same model capabilities against you while your defenders operate with hand-tied constraints.
Because security teams work hand-in-hand with IT, Platform, and Infrastructure engineering, they are in a prime position to build this business case. Together, these infrastructure groups can demonstrate to executive leadership that arming defenders with AI significantly reduces organizational risk while accelerating operational output.
A team sport against a common enemy
As we head into Black Hat, DEF CON, and BSidesLV, it’s worth remembering what makes cybersecurity unique compared to almost any other tech sector.
In traditional enterprise software, companies compete fiercely with one another for market share. In cybersecurity, our true competition isn’t the rival security vendor down the street or the security team at a competing firm: it’s the adversary.
We share a common enemy regardless of what company logo is on our badge. That is why I regularly dedicate my time to advising early-stage security founders, sharing tactical playbooks with peer CISOs, and writing this newsletter. Knowledge sharing is our only true defense against an adversary operating with machine-speed AI.
If we want to protect our organizations over the next decade, we have to stop viewing AI as a threat to be contained and start leveraging it as the foundational engine of modern defense. I’m looking forward to diving into these exact ideas with many of you in Vegas next week.





