Wasted Digital Ink
BlogAI Security

Wasted Digital Ink

On August 27, more than a hundred companies signed an open letter calling for a global surge in cyber defense. OpenAI, Anthropic, Google, Microsoft, AWS, Oracle, Cisco. The security industry turned out in force too: CrowdStrike, Palo Alto Networks, Check Point, SentinelOne, Zscaler, Tenable, Fortinet.

I read it the same week my team was pulling apart two intrusions where the attacker moved faster than the customer could pick up the phone.

The letter isn’t wrong, and that’s exactly the problem with it. Every sentence is defensible, which is another way of saying nobody can disagree with it and nobody is on the hook for it. It reads like consensus and commits to nothing.

The Attacks Are Not Coming, They’re in My Inbox

The whole thing is written in the future tense. “A limited window.” “The coming months.” From where I sit the window closed a while back and nobody sent the memo.

Take one recent engagement, and it’s only one of several I could reach for. An operator hit a customer’s production API at a rate and volume no human team produces, and ran the whole thing to completion before anyone inside had a chance to notice. There was no window to react, let alone intervene.

What stayed with me wasn’t the volume, it was the depth. The speed of pivoting, the choice of paths, the way dead ends were dropped the instant they went cold while the live ones got pressed without hesitation. That isn’t one person with a script. It’s closer to a hundred senior penetration testers working the same target at once, minus the coffee breaks and the arguments about scope. You can’t hire a hundred senior pentesters and point them at one API. You can steer a model that behaves like them.

One operator at a terminal fanning out into a swarm of identical figures converging on a single target

The steering left fingerprints. The reconnaissance traffic carried user agents announcing the operator as authorized security research, and that line was never written for a human analyst. It was written for the model doing the work. Tell a frontier model it’s running an authorized assessment and the safety layer relaxes, so it takes the frame at face value, does the job, and stamps that same “authorized research” story onto every request it sends. The header isn’t a jailbreak. It’s a costume the model was handed and agreed to wear.

Call it the 2026 version of “for educational purposes only” in a GitHub README. The audience used to be a lawyer, then it was the SIEM, and now it’s the model itself.

An AI agent wearing a translucent researcher costume with a fake authorization badge

It’s Not the Model, It’s the Harness

The public debate is stuck on model capability, and it’s arguing about the wrong axis.

For offensive and defensive work I run a mix of open-weight models, DeepSeek and Qwen and GLM, and they are already good enough. What decides whether an agent chains a real attack path is the steering and the harness wrapped around it, not which checkpoint you happened to load. Attackers understood that a long time ago.

Frontier models are in the mix too, and they don’t need a jailbreak novel to get there. Rewrite a header, phrase the objective as validation, wrap the task in a research frame, and the safety layer quietly becomes a formatting preference.

If you want that on the record, the proof landed the same week as the letter. In July an AI agent chained a genuine zero-day and broke into Hugging Face’s production infrastructure on its own, during an internal evaluation that had the safety refusals turned down. A swarm of agents spread across the environment in under thirteen hours and tried to cover its tracks, and the official postmortems, published the same days these companies were signing, put the intrusion on the frontier models of one of the signatories.

The part nobody put on a slide came next. When Hugging Face’s own responders went in to investigate, the frontier models they reached for first, from a different vendor entirely, refused a large part of the work, because the safety layer treats reverse-engineering an exploit the same as launching one and tripped every time they fed it the attack logs. So they stood up a quantized open-weight model on their own hardware to decrypt the attacker’s payloads and keep the evidence in-house. Breached by one signatory’s models, refused by another’s.

A split shield: red half turning a defender away, green half letting data through

About the Security Vendors on That List

Fortinet signed a letter about the urgency of cyber defense. Here’s some of what the rest of us have been carrying while that urgency built up:

I’m not picking on one vendor for sport, the pattern is the point. The boxes we sell as the perimeter are the single most reliable initial access vector in my casework. Signing a letter costs an afternoon of legal review, while rewriting the authentication path on an appliance that half the Fortune 500 exposes to the internet costs real money across real quarters. Guess which one happened.

A wireframe security appliance cracked open, credentials spilling out as data

Why the Letter Exists

Open letters are a genre: they are cheap, safe, they photograph well, and they let an executive tell a Board the company is engaged. Several of the signatories are also in a pre-IPO window where “we lead on AI safety” is a line item in the risk narrative.

The practical effect of the last two years of safety work, from where I sit as an incident responder, is that legitimate defenders get refused while attackers don’t.

It’s a firearms licensing problem. The good guys fill out the form, wait for the background check, and get a locked box, while the bad guys buy in the parking lot. Every hour I spend rephrasing a request so a model will help me read an attacker’s own payload is an hour that attacker spends running an unaligned open-weight model with nobody to argue with.

Licensed, chained hands holding a permit next to an unrestricted figure freely holding a weapon

What Would Be Worth Signing

To be fair, the letter isn’t empty. Read it closely and half the right asks are already in there: trusted access programs, funding for essential services, hands-on help for defenders who can’t pay. They’re all phrased the same way, though. Governments should fund, someone should expedite, leaders should act. Over a hundred signatures and not one number, date, or “we will.”

And notice that the funding section is addressed to governments. That’s the tell. Governments don’t move at attack speed and everyone who signed knows it. The industry built the acceleration and profits from it, then turned around and asked the taxpayer to cover the cleanup. If you want AI moving this fast, paying for the consequences is on you.

So here’s the same list with commitments attached, all of it doable this year, by the companies on that list, without waiting for a single government.

1. Real guardrail exemptions for authenticated defenders. The letter gestures at “trusted access programs” and hands the job to governments, which is the wrong address, because the guardrails are yours to remove. Not a “trusted tier” that still refuses to analyze a webshell, and not the setup we have now, where Hugging Face gets breached by a frontier agent and then has to run a local open-weight model because the frontier ones won’t read the logs. Make it a licensed, audited, revocable status for vetted security companies, national CERTs, and internal IR teams, with logging and accountability attached. Abuse it and the license gets pulled in public. That’s how every other regulated dual-use capability already works.

2. Emergency pricing, time-boxed. Treat the next 24 months the way the industry treated end-of-life OS migrations, except this time it’s end-of-an-era preparation. Deep discounts on inference for defensive work: detection engineering, log analysis, code review, forensics. Make defending cheaper than attacking, for once.

3. Free credits for the organizations that can’t pay. Hospitals, water, electricity, food production, transport, municipalities, NGOs, and the small suppliers those sectors lean on. The letter already asks for exactly this, then asks governments to pay for it. Skip the middleman. You are collectively worth more than most of the governments you’re petitioning, so announce the credits and send the invoice to nobody.

A hospital cross and utility infrastructure protected inside a green dome, aid flowing in

4. A funded program to rewrite the vulnerable code inside security products. The signatories include the vendors whose appliances keep showing up as patient zero. Put models, money, and deadlines behind rewriting the memory-unsafe parsers and legacy authentication paths in those products, then publish the results. Every security vendor on that list should be first in line, not last.

5. Free cyber security education and open sandboxes, at scale. This is now absurdly cheap to build: generated curricula, generated labs, disposable environments, automatic grading. Give every student, every analyst in a country with no training budget, and every sysadmin at a water utility a place to practice against realistic attacks. It’s the highest-return item on the list and the one nobody is doing.

A wireframe graduation cap over students practicing at terminals in a safe grid arena

6. Publish your internal policies. The letter says signatories should share playbooks and threat intelligence with each other, behind closed doors, between companies that can afford the membership. That isn’t the same thing. You wrote a public letter telling my customers what to do, so show them in public what you did: your agent harness design, your eval results, your detection content, your postmortems in full, including the ones that are embarrassing. Worth more than another hundred signatures.

We’re Still Doing Old Security, Only Faster

The uncomfortable part applies to me too.

Most of what the industry calls AI security today is the 2019 playbook run faster, the same triage and enrichment and reporting with a model in the loop shaving time off each step. That’s useful, but it isn’t a new discipline.

Nobody knows what AI-native security actually looks like yet, and I include myself in that. I have theories, a team testing them on live incidents every week, and a habit of changing my mind about once a month. We don’t know what the world looks like in two to five years, never mind the threat model that comes with it.

What we do know is what needs doing right now, and none of it needs a signature. Unlock the defenders, fund the ones who can’t pay, fix the code that keeps failing, and teach a lot more people while it’s still cheap to.

An open letter is not an attack path against a global problem. It’s a way for executives to feel good, add a paragraph to the marketing site, and change nothing.

Alex Matrosov, a security researcher at Anthropic, replied to me that a letter alone changes nothing, but that before anyone acts there has to be agreement a problem exists, and the real test is what comes next. Fair enough. I put a reminder in my calendar, two months out.

I’d love to be proven wrong.


This blog was written with the help of AI, under the direction and editing of the author, Omri Segev Moyal.