AI is inherently dual-use in cybersecurity: the same models that let attackers find vulnerabilities also let defenders find and patch them first, and because defense means protecting a broad expanse while attackers only need one way in, models ultimately help defenders more even though the near-term attack surface looks daunting.
Ann explains that AI's dual-use nature in cybersecurity means models help both attackers and defenders find code vulnerabilities, but she believes defense benefits more since attackers only need one opening while defenders must cover everything. ✦ AI generated
Ann · a16z Podcast · 2026-07-03 · original ↗
starts at this moment · 29:29
“There's so many nuances around security and even the debate between open versus closed... maybe speak a little bit more about how you've been thinking about that and advising companies on that delicate balance.”
fundamentally as many technologies are AI is dual use right so the first step whether you are an attacker or a defender is finding vulnerabilities in systems and then if you're a defender you patch them if you're an attacker you exploit them so models make the step of finding vulnerabilities in code far easier and quite frankly it makes the next steps, exploit or defend, easier as well.
verbatim transcript · starts at 29:29
29:09particularly with AI. Ann, this is a great question for you. There's so many nuances around security and and even the debate between open versus closed that there are considerations of whether that's even viable to build without upsetting the Apple card on what is allowed with open source given the security nuances. Maybe speak a little bit more about how you've been thinking about that and advising companies on
29:29that that delicate balance. >> So, it's a hot topic right now. um as you know and it's a hot topic around the world because fundamentally as many technologies are AI is dual use right so the first step let's use cyber as an example right the first step whether you are an attacker or a defender is finding vulnerabilities in systems and then if you're a defender you patch them if
29:53you're an attacker you exploit them >> y >> so models make the step of finding vulnerabilities in code far easier Mhm. >> Um, and quite frankly, it makes the next steps, exploit or defend, easier as well. The economics of cyber defense were broken well before, you know, the latest AI models came out. I saw that in the White House where my nightmare was the ransomware attacks against, you
30:18know, rural hospitals in America. There wasn't another hospital two blocks down. So actual Americans opportunity to access health care was disrupted by in some cases states state harbored criminal groups halfway around the world. Right? So infrastructure is very fragile and the reality is that the models help both. I personally believe I'm focused on cyber security for a moment that they help far more in defense because defense is far harder.
30:44You have to be you know defending a broad expanse and attacker has to find one way in. Um so as a result I actually think we have we are in a difficult space at this moment because there's such a broad attack surface there's so many systems that are vulnerable but I think we will see the opportunity for much more secure space to your point you know when I talk with governments around
31:08the world or companies around the world all are grappling with that question of I'll talk about the government side given we know it can both help Most countries have two missions, right? Defending the country as well as defending it, you know, as well as maintaining its interest overseas. Given both, how do we ensure that these powerful capabilities don't fall into our adversaries hands, don't fall into criminals hands to be used for that