I read
@DarioAmodei's essay calling on the labs to pace the frontier.
@sama agreed. The frontier will move at whatever speed it moves. The rest of the world will not slow down. Our job in the cybersecurity community is to make sure it moves securely and safely.
Here’s what I see from the front lines:
1. The unit of threat is no longer the hacker. It's an autonomous campaign. I call it the Agent-state. We see coordinated AI agents executing attack campaigns at machine speed.
2. Sophistication is dead as an attribution signal. AI gives every criminal and lone actor elite execution. Identity, infrastructure, and intent tell you who's behind an attack. Skill doesn't.
3. Runtime is the control point. Endpoints, cloud workloads, and SaaS are the battleground. Governance documents don't stop an agent in motion. Enforcement at machine speed does.
4. Every AI agent is a privileged identity. Least privilege, short-lived credentials, traceable actions, and a kill switch. Permissions never expand because an agent decides it needs more.
5. Defense has to be autonomous but also bounded. Machine-speed response, tiered by consequence, with humans owning the high-impact calls.
6. Every failed attack should make every defender smarter. Feed what we block back into detection, across customers and models, with privacy intact. This is what CrowdStrike and NVIDIA introduced with SafeMind: an agentic, always improving model and harness protection system built for defenders.
7. The AI industrial base is critical infrastructure: weights, training clusters, APIs. Call it what it is and protect it like it is.
Pacing what comes next doesn't secure what's already here. The credible path is to deploy with proof: board-level accountability for AI security, independent external red teaming, incident disclosure, secure defaults, and controls that work in production - not on paper. Anthropic and OpenAI just committed to embedding independent evaluators with employee-level access. CrowdStrike will bring what we see from the front lines to that table.
The ability for AI to act must be matched by the ability for defensive AI to stop the breach.