AI models help both attackers and defenders find software vulnerabilities, but defenders benefit more because defense requires covering a broad attack surface while an attacker only needs to find one way in, meaning AI could ultimately push the world toward much more secure systems.
Ann argues that although AI is dual-use in cybersecurity, it disproportionately helps defenders because defense is inherently harder than attack, pointing toward a future of more secure systems despite today's dangerous transition period. ✦ AI generated
Ann · a16z Podcast · 2026-07-03 · original ↗
starts at this moment · 30:44
“Maybe speak a little bit more about how you've been thinking about that and advising companies on that delicate balance.”
they help far more in defense because defense is far harder. You have to be you know defending a broad expanse and attacker has to find one way in. Um so as a result I actually think we are in a difficult space at this moment because there's such a broad attack surface there's so many systems that are vulnerable but I think we will see the opportunity for much more secure space.
verbatim transcript · starts at 30:44
30:44You have to be you know defending a broad expanse and attacker has to find one way in. Um so as a result I actually think we have we are in a difficult space at this moment because there's such a broad attack surface there's so many systems that are vulnerable but I think we will see the opportunity for much more secure space to your point you know when I talk with governments around
31:08the world or companies around the world all are grappling with that question of I'll talk about the government side given we know it can both help Most countries have two missions, right? Defending the country as well as defending it, you know, as well as maintaining its interest overseas. Given both, how do we ensure that these powerful capabilities don't fall into our adversaries hands, don't fall into criminals hands to be used for that
31:34purpose? And I think, you know, in the traditional cyber tools arena, we always grappled with this, right? When a capability is on a thumb drive, >> export controls are a joke. You can't actually control it in that way. And there is real power, as we talked about earlier, in the models that the world runs on being run on trusted models. When people are using an American model, they don't have to worry
32:00there's an intentional backdoor. As we talked about earlier, they don't have to worry that a chatbot's answers will be framed by, you know, censoring to fit a particular political story of like an authoritarian government. So the question for now is to say how do we build in the degree of safety in model so that they can be used in environments that need that safety and that is somewhere where because the main
32:30models are American we're in a particular position to think through and build that out and I think this is not done by government it's not done by the private sector what it really needs is people who really understand the models best from the private sector at the table with folks on the government side who are thinking about how do we both promote innovation and control for these