Governments cannot simply ban AI models from having cyber hacking capabilities, because the same capability that lets a defender find and patch vulnerabilities in its own code is inherently the capability to find and exploit vulnerabilities elsewhere — you can't have one without enabling the other.
Ben Horowitz points out the dual-use trap in AI cybersecurity policy: restricting models' ability to find vulnerabilities for defense also removes the ability to defend, since the underlying capability is identical to what attackers need. ✦ AI generated
Ben Horowitz · a16z Podcast · 2026-07-03 · original ↗
starts at this moment · 33:33
you'd like to say okay don't release your model with cyber hacking capabilities. But if you do, as an say and you want to find the vulnerabilities in your own code and patch them, you can't do that without also enabling cyber attacks because as soon as it can find the vulnerabilities, guess what?
verbatim transcript · starts at 33:33
33:33like so for example you'd like to like from a government standpoint you'd like to say okay don't release your model with cyber hacking capabilities. But if you do, as an say and you want to find the vulnerabilities in your own code and patch them, you can't do that without also enabling cyber attacks because as soon as it can find the vulnerabilities, guess what? Uh, and so you're kind of in this
34:03situation where it's like, well, if you kind of lock that up, lock that capability to understand vulnerabilities, then the only people who will be able to understand v vulnerabilities are the bad actors who jailbreak the system. >> And so you you we're in a very >> I would say interesting interesting world on that. >> Yeah. And and I think to that point, we'll focus on the cyber aspect because
34:30that's gotten so much attention with anthropics mythos model, etc. I think what AI models essentially do to Ben's point is you want to be the first to hack your systems >> because, you know, you we often use the expression of, you know, digital doorork knobs. It now allows attackers to jiggle every doorork knob continuously and at scale. So your hope for your network is using those models first to find where
34:54you're vulnerable and frankly then be able to fix it and that wasn't a tractable problem before y >> and I think now the models help you particularly for code bases that were public particularly for if you're relying on third party code or open source code and that's some of the biggest areas of risk or where there is dependencies on code that nobody was really maintaining. So I think we're now
35:16seeing you know companies coming together taking responsibility for that because now the I would say the cost of not addressing insecure code has gone up and the cost of addressing it has gone down. >> Yeah. >> Which is a good shift from where we were before. >> We we we may finally build secure systems. >> Exactly. >> Please God. And more importantly, the the process for building new code can