An Illustration of a hacker. AI has lowered the cost and skill barrier to hacking, putting attack capability once reserved for nation-states into the hands of anyone with a model. (Shutterstock/TSViPhoto)
Why We Should Hack Ourselves Before Someone Else Does
AI has erased the cost barrier to constant security testing. Without a legal incentive to act on what it finds, companies will keep waiting for the breach that forces their hand.
For years, I have worked to take the online infrastructure of designated foreign terrorist organizations off the internet. Providing terrorists with material support, technological services included, is a federal crime. Yet tech companies look the other way until a private citizen notices, contacts them through legal channels, and weeks later, something comes down.
In contrast, a copyrighted film uploaded to YouTube is removed instantaneously, automatically, and preemptively. Companies can move at machine speed when they fear a lawsuit from a movie studio. But they do not do it for terrorist recruiting or fundraising, or for your personal data. Behavior follows penalties.
Data Breaches and National Security Risks
Nowhere is this clearer than with my own data. Equifax lost the Social Security numbers, birth dates, and addresses of 147 million Americans, mine included. Across 20 other breaches, I’ve lost credit card numbers, travel history, and health records. Even though I follow personal security best practices, my data was on someone else’s server, and when that server was compromised, I was, too. Like most Americans, at some point, I stopped feeling violated and started feeling the futility of trying to secure anything at all.
The stakes are higher for national security. Chinese intelligence exfiltrated 21.5 million federal workers’ security-clearance files from the Office of Personnel Management, including fingerprints. Chinese hackers breached defense contractors to steal stealth fighter blueprints. And in late July, attackers hit water utilities in 12 states, resulting in boil-water notices and operators being locked out of their own plants. Investigators suspect Iran.
AI-Powered Cyberattacks: How Artificial Intelligence Is Changing Hacking
What has changed in the past year is that the attackers are no longer only human. Last fall, Anthropic disclosed the first AI-orchestrated espionage campaign, in which a suspected Chinese state actor pointed its models at 30 targets and let them run. Last month, two of OpenAI’s models found a zero-day, broke out of their sandbox, and raided another company’s production systems for the answer key to their own benchmark. AI cheated on a hacking test by hacking someone.
For the internet’s whole history, testing was the bottleneck. An adversarial assessment meant hiring a scarce team of experts, and weeks of work accompanied by a large invoice. And so the Federal Trade Commission (FTC) and most state breach laws require only “reasonable” safeguards, a standard adjudicated only after a breach. Industry standards like the Payment Card Industry Data Security Standard (PCI DSS) require an annual penetration test, but the company determines the scope, schedule, and tester. No framework subjects a company to a test it did not arrange.
AI Removes the Cost Barrier to Defense
With artificial intelligence (AI), talent and cost are no longer bottlenecks to hardening our systems. A frontier model can probe a network with speed, scale, and persistence that no human team can match, run continuously instead of annually, and write the fixes as well.
Given these daunting capabilities, Congress is contemplating restricting Chinese open-weight models, a restriction that would not stop Tehran or Beijing from using them and would leave our own defenders with less than the attackers already have. When rogue OpenAI models hacked Hugging Face last month, the company’s engineers ran forensics with a Chinese model because guardrails blocked American ones. If we cannot keep the capability away from bad actors, we should point it at ourselves first.
Cybersecurity Regulation and Incentives: Why Companies Need a Reason to Act
But capability does not change behavior without incentive. Equifax’s flaw had a patch available. The Cybersecurity and Infrastructure Security Agency (CISA) had warned about exposed water controllers in 2023and again this April. Yet, in both cases, action came only after the attack.
Companies will act if there is a cost for inaction. Copyrighted films come down in seconds because Congress attached statutory damages to leaving them up, and automatic preemptive removal became the cheaper option. But customers do not wield the collective power to impose a comparable cost for losing their data. The government does.
Federal agencies should be able to break into the companies holding our most sensitive data without warning or permission, and failing should cost something. That cost could be a fine from the sector’s regulator, a finding that plaintiffs can carry into court, or something Congress has yet to invent.
Mandatory Security Audits: A Regulatory Precedent for Critical Infrastructure
We already follow this model everywhere else. The United States Department of Agriculture (USDA) doesn’t wait for an outbreak to inspect a slaughterhouse. The Federal Reserve doesn’t ask for a bank’s permission before stress-testing its balance sheet. The Federal Aviation Administration (FAA) doesn’t wait for a crash to audit maintenance logs. The Department of Homeland Security (DHS) smuggles mock weapons through Transportation Security Administration (TSA) checkpoints unannounced. In each case, the entity being checked doesn’t decide whether the check happens. But CISA penetration tests on critical infrastructure are by invitation only, on systems and at a time the target company selects, with no penalty attached. Only cybersecurity still runs on the honor system.
The next vulnerability is already exposed. I’d rather it be us who find it than China, Iran, or an AI model with no country at all.
About the Author: Pawan Deshpande
Pawan Deshpande is a machine learning researcher, founder, AI product leader, and tech investor. He holds a bachelor’s and a master’s in computer science from the Massachusetts Institute of Technology (MIT). All views expressed are his own.
The post Why We Should Hack Ourselves Before Someone Else Does appeared first on The National Interest.