1 of 31

Navigating cybersecurity through the rise of AI security superintelligence

Joshua Saxe, co-founder, Abundant Security

2 of 31

3 of 31

We need to use policy to navigate society through the rise of superintelligent security agents

4 of 31

But today’s AI security policy discourse centers on anemic signals and controls

5 of 31

We should be using real world attacker and defender usage trends to understand the net expected harms of a model launch

6 of 31

Another problem is that today’s policy interventions imagine model launches as the main AI security risk object

7 of 31

But actually, cyber damages are smooth functions of ecosystem trends

8 of 31

Bending these trends in the right direction at the ecosystem level should actually be the main object of AI security policy

9 of 31

Additionally, the discourse biases towards AI security risk assessments, and not AI security benefits assessments

10 of 31

But AI may be our best opportunity to reverse longstanding harm trends due to the industrialization of fraud and ransomware

11 of 31

My thesis

  • We urgently need a large, capable AI cybersecurity observatory
  • It would focus on
    • … reducing net harms at the ecosystem level
    • … maximizing AI’s defender benefits
    • … and mitigating its security risks
  • It would track the full breadth of AI security ecosystem and model capability signals
  • It would recommend a full menu of policy actions

12 of 31

My thesis: today vs. the AI security observatory we need

13 of 31

My fantasy of what the AI security observatory would do

14 of 31

A prototype of the contrasting signals an AI security observatory would develop

15 of 31

Misalignment and reward hacking are real; coding agent damages are scaling exponentially.

16 of 31

But such incidents contrast with human-error damages which AI could potentially help avoid.

17 of 31

AI-mediated phishing is occurring at scale.

18 of 31

But AI’s use in phishing should be weighted against its ubiquity in phishing defense.

19 of 31

We now have clear real-world examples of superhuman agentic hacking

20 of 31

These incidents contrast with success in burning down security tech debt.

21 of 31

Overall, the current security crisis predates AI; there’s an opportunity for AI to provide net benefit here, with the right policies.

22 of 31

A prototype of the policy controls a security observatory would help us navigate

23 of 31

Using subsidies and regulation to incentive critical infrastructure hardening

24 of 31

Regulations and support around inference provider know your customer programs

25 of 31

Subsidies and government support for AI cyber defense adoption

26 of 31

Phased rollout of models where it makes sense, accelerated rollout where that makes sense

27 of 31

Building an AI security observatory is urgent; we may soon be living in a very different world

28 of 31

Dual-use cyber capabilities are on an exponential; the stakes keep rising

29 of 31

Dual-use capabilities and attacker access keep getting cheaper, adding urgency

30 of 31

The loss landscape will be complex and increasingly spiky due to AI’s dual use nature; policy precision is key

31 of 31

Thanks; space for questions and discussion�josh@abundantsecurity.co�@joshuasaxe on X