Services Experience Recommendations Blog In the Media Contact Get in touch
← Back to Blog 27 Aug 2026

The Defender Is Wearing a 9mm Vest - Everyone Else Is a Sniper.

The Defender Is Wearing a 9mm Vest - Everyone Else Is a Sniper.


I worry that we are getting something fundamentally wrong in the way we think about AI and cybersecurity. We are so focused on restricting what AI can do, defining liability and making sure defensive systems operate within increasingly tight guardrails that we are losing sight of who those systems are actually supposed to defend us against.

Because the attacker doesn't have any of those restrictions.

There is a lot of good intent behind AI regulation. Of course there is. Nobody sensible is arguing that we should simply release autonomous AI systems into critical environments and hope for the best. But cybersecurity is different from many other applications of AI because there is somebody on the other side actively trying to defeat you. And that somebody is not particularly interested in responsible AI.

If attackers can use AI without guardrails, while defenders are required to operate within them, we are creating an imbalance that becomes more dangerous as the technology improves.

The analogy I keep coming back to is a bulletproof vest. Imagine somebody gives you a vest and tells you it will withstand a 9mm bullet. Great. Except you walk outside and discover that everybody shooting at you is a sniper. Suddenly the protection you've been given doesn't look quite so reassuring.

That is what worries me about the direction we're taking with defensive AI. We have extraordinary technology available to us, but we are creating a landscape in which the defensive side may never be allowed to use its full potential. Meanwhile, attackers will use whatever works.

You can already see the problem emerging with frontier AI models. Some of the most capable models can be used for vulnerability research, penetration testing, generating attack patterns and exploring how systems can be compromised. There are legitimate cyber validation programmes that allow approved researchers to work with models under much looser guardrails precisely because those capabilities are useful for defence.

But let's be realistic about what that means. A penetration test has a positive ring to it because somebody has given you permission to conduct it. Technically, many of the capabilities involved could just as easily be used in an attack. The technology doesn't know whether you're the good guy. The difference is intent and authorisation.

That leaves us with a very difficult question. If the threat landscape is going to use increasingly capable AI without the restrictions legitimate defenders face, how much capability are we prepared to remove from the defensive side before those restrictions themselves become a security problem?

This becomes even more important when we talk about autonomous response. If legislation makes the creator of defensive AI responsible for every possible consequence of an autonomous decision, vendors will naturally become more cautious. They will tune systems towards the lowest possible false-positive rate. They will limit what those systems can do without human approval. They will build additional checks into every consequential action because nobody wants to be on the receiving end of a multimillion-pound claim after an AI system takes a factory offline for six hours.

Commercially, I completely understand that. From a defensive perspective, however, it puts us right back where we started.

Attacks are already moving faster than humans can reasonably investigate and respond. As AI becomes more capable, that window will shrink further. If an AI system can identify an attack in seconds but still has to wait for a human being to approve the response, then we haven't really created autonomous defence. We've created an incredibly fast detection system attached to a very slow decision-making process.

And when an attack can unfold in under a minute, that is no longer a valid strategy. This is why I think we need to change the conversation from liability to responsible capability.

There is a difference between asking who should be blamed when AI gets something wrong and asking what capability defenders need in order to protect an organisation properly. At the moment, we spend far too much time on the first question and nowhere near enough on the second.

That doesn't mean vendors should have no responsibility. Of course they should. But organisations also have to accept responsibility for how they deploy these systems, what authority they give them and, crucially, what information they provide to allow them to make sensible decisions.

Take a production environment. An AI system detects an infiltration on a machine and decides the safest response is to isolate it. Technically, that may be exactly the right decision. But what if that machine controls a production line that generates a million pounds an hour? What if taking it offline creates more damage than allowing the threat to remain contained for another hour while it is remediated differently?

That isn't simply a cybersecurity decision. It is a business decision.

The AI can only understand that if the organisation has done the work to tell it what that asset is, what it does, how critical it is and what the impact of taking it offline would be. If the company doesn't know those things itself, how can it expect an AI system to know them?

This is where responsibility needs to become much more balanced. The vendor provides the capability. The organisation provides the context, sets the mandate and decides how much authority the technology should have. You cannot give an AI incomplete information, refuse to define what it is allowed to do and then simply point at the vendor when something goes wrong.

If we do that, vendors will inevitably play safe. And the uncomfortable truth is that the safest defensive AI may not be the AI capable of defending us against what is coming.

We keep saying that AI is changing the threat landscape. We keep saying attacks are becoming faster and that security teams cannot respond quickly enough. We talk about skills shortages and alert fatigue and the impossibility of humans processing everything happening across modern environments. Then, when we finally have technology capable of responding at machine speed, we become terrified of allowing it to act.

Something in that logic doesn't work.

We absolutely need responsible AI. We need governance, oversight and clear boundaries. But we also need to recognise that cybersecurity is adversarial. Every restriction we place on defensive capability has to be considered in the context of an attacker who will not voluntarily accept the same restriction.

Regulation cannot make malicious AI behave responsibly. It can only regulate those willing to follow the rules.

And this is the part I think policymakers need to understand much better. If we become so focused on preventing defensive AI from ever making the wrong decision that we prevent it from making meaningful decisions at all, we haven't reduced risk. We have simply moved it somewhere else.

We have given the defender a 9mm vest, but the problem is that everyone else is becoming a sniper.