Cyber researcher: model attackers as real organizations and the AI cyber threat looks overrated

joshua_saxe · x · 2026-08-21

Security researcher Joshua Saxe argues the AI cyber policy debate would look different if attackers were modeled as actual people and organizations.

He cites EvilCorp members who stole or extorted hundreds of millions via phishing, malware, credential theft and sophisticated laundering rails — with only a single lone zero-day use across all their operations. Why assume such groups would abandon a proven nine-figure business and retool around AI-driven zero-day research, which demands different skills, infrastructure and QC, at huge opportunity cost?

New AI capabilities matter and some groups will adopt them, but attacker orgs have cultures, business models and skillsets that bottleneck AI adoption just as defender orgs do.

Original post →

More from Safety

Safety channel →