Cyber researcher: model attackers as real organizations and the AI cyber threat looks overrated
joshua_saxe · x · 2026-08-21
Security researcher Joshua Saxe argues the AI cyber policy debate would look different if attackers were modeled as actual people and organizations.
He cites EvilCorp members who stole or extorted hundreds of millions via phishing, malware, credential theft and sophisticated laundering rails — with only a single lone zero-day use across all their operations. Why assume such groups would abandon a proven nine-figure business and retool around AI-driven zero-day research, which demands different skills, infrastructure and QC, at huge opportunity cost?
New AI capabilities matter and some groups will adopt them, but attacker orgs have cultures, business models and skillsets that bottleneck AI adoption just as defender orgs do.
More from Safety
- CMU et al. release DelusionEval, revealing LLMs reinforce delusions and safety failures grow with conversation length — burkov · 2026-08-21
- PNAS Study: Social Algorithms Prioritize Content Clashing with Your Values — msbernst · 2026-08-21
- AI crossing capability thresholds may leave many security systems exposed — austinc3301 · 2026-08-21
- Analysis: AI infrastructure shifts towards secrecy and state control — FinanceYF5 · 2026-08-21
- MIT Paper Finds Deleting Artist Data Doesn't Stop AI Recreating Images — technollama · 2026-08-21
- Lack of training transparency hampers safety research; synthetic data issues often skill-based — JacquesThibs · 2026-08-21