Asaf Wiener
Opinion

Cyber defense cannot wait for safer AI

"Dario Amodei’s call to slow AI development puts safety at center stage," writes Asaf Wiener, CEO at Mate Security. "But the good guys need something completely different: defenses that can act at machine speed, with authority and limits established before an attack."

Dario Amodei, Anthropic’s CEO, wants to buy us time. In "We Must Pace the Frontier," he argues that AI capabilities are advancing faster than our ability to control them. His proposal calls for independent evaluators, common safety standards and coordination over the pace of development. Companies responsible for protecting their systems should read it with a second clock in mind: how long would their own defenses take to recognize an attack and do something about it?
That clock keeps running while the industry debates the first one. Attackers are already using AI today to automate reconnaissance, adapt their techniques and scale their operations. They don't sign agreements, and slowing future model releases will not remove the capabilities they already have. Corporate readiness has to address that threat now. That means defenders need faster and more precise models, not fewer of them. Slowing that progress risks delaying better defensive tools while companies remain exposed to attacks powered by today's AI. That's a serious cost for a proposal intended to improve safety. In cybersecurity, we should be accelerating the development and adoption of protective capabilities, with controls that make them safe to use.
1 View gallery
Asaf Wiener
Asaf Wiener
Asaf Wiener
(Omer Hacohen)
Amodei's own essay points to why those controls matter. He cites the OpenAI-Hugging Face incident, in which agents attacked systems outside their assigned task and tried to interfere with the mechanism evaluating them. He raises concerns about the consequences of losing control as agents become more capable. Every security leader should ask the mirror-image question: if agents attacked their company, could its defenses investigate and respond quickly enough? That possibility is exactly what makes building readiness urgent, not a reason to wait.
The good news is that AI-led defense capable of operating at machine speed already exists. The obstacle to wider adoption isn't the technology; it's trust, integration, deployment and the way security teams work. Those concerns are justified, since a mistaken decision can disable a legitimate account, lock an executive out or shut down a production system. Defenders need to apply the same rigor to their agents that Amodei demands of the labs.
The familiar response is to place a human approval in front of every action. That can catch errors, but it carries a cost of its own: while an analyst gathers evidence and validates a recommendation, an attacker keeps moving. A system may finish its analysis in seconds and still wait in a queue for permission to act. Speed gained in one part of the process disappears in another.
We built Gamebooks, our investigation procedures for AI agents, to resolve exactly that tension. Security teams define what an investigation must establish and where the agent's authority ends. Inside those boundaries, the agent is free to follow the evidence as the situation changes.
Take a suspicious file on an employee's laptop. The agent needs to trace how it arrived, what it did, and whether it talked to an outside system. That might mean checking the employee's email, or noticing that software normal on one set of machines is a warning sign on another. A rigid checklist would miss that kind of nuance. The organization also sets the containment rules up front: what evidence justifies isolating the laptop, which devices that covers, and what to do differently for a machine running a critical service. If the agent can't get the evidence it needs, or the right move exceeds its authority, it escalates. Otherwise, it acts and keeps investigating.
Digital banking works the same way. Transactions move too fast for a person to review each one, so banks lean on automated checks and send only the uncertain cases to a human. It's the same pairing of fast decisions with clear rules about when those decisions are allowed.
Trust in that pairing has to be earned and never assumed. We start agents in an enterprise with narrow, read-only access and let the security team check the agent's conclusions against its own. From there, we test real actions in staging and expand responsibility as the evidence supports it. That access also has to stay conditional: if an integration breaks or performance slips, authority gets pulled. It's never left running on the assumption that it'll keep working.
None of this happens on its own: leadership has to fund and organize it. Connecting systems, testing procedures and training people take time even when the underlying technology is ready. Someone must own the business impact of automated decisions, and someone must be available when an exception requires intervention. These are operating responsibilities that a software purchase alone cannot settle.
That's the same reason Mate joined OpenAI's call for collective action on cyber defense. Access to capable AI has to translate into practical defensive capacity, and quality, speed and cost all matter if more organizations are going to use it effectively. Safety for AI developers and readiness for AI-powered attacks have to advance together. Delaying defensive adoption leaves companies less prepared for capabilities attackers can already use.
Before the next attack, a leadership team should be able to say which protective actions its systems are authorized to take, what evidence those actions require, and who steps in when the limits are reached. During an attack is an expensive time to start that conversation.
Asaf Wiener is Co-Founder and CEO at Mate Security