I remember the exact moment I realized we were in deep trouble. It was 3 AM on a Tuesday, and I was staring at a screen, my heart pounding. One of my portfolio companies, a promising startup in the fintech space, was under attack. But this wasn't just any attack. It was a sophisticated, AI-driven assault that was unlike anything we had ever seen before. Our existing security measures, which we thought were state-of-the-art, were failing. It felt like we were trying to fight a swarm of intelligent hornets with a fly swatter.
That night, I didn't get any sleep. I spent hours with the team, trying to understand what was happening. We eventually managed to contain the breach, but the experience left a deep scar. It was a brutal lesson in the new reality of cybersecurity. The game has changed. And most people, even in the tech world, haven't realized it yet.
The AI Arms Race in Cybersecurity
For years, we've been hearing about how AI is going to revolutionize cybersecurity. And it has, but not in the way most people think. The truth is, we're in an AI arms race. For every new AI-powered security tool we develop, there's a new AI-powered attack vector being created by malicious actors. It's a constant game of cat and mouse, and the stakes are getting higher every day.
I’ve seen this firsthand. I’ve invested in over 200 companies, including some of the biggest names in AI like Anthropic, OpenAI, and Scale AI. I’ve seen how these technologies are being used to build incredible products. But I’ve also seen how they can be twisted and used for nefarious purposes.
Take phishing, for example. We used to be able to spot phishing emails from a mile away. Bad grammar, generic greetings, suspicious links. But now, with generative AI, attackers can create highly personalized and convincing phishing emails at scale. They can scrape your LinkedIn profile, your social media, your company website, and use that information to craft a message that looks like it came from your boss or a trusted colleague. It’s terrifyingly effective.
Adversarial AI: The New Boogeyman
One of the biggest threats we're facing right now is adversarial AI. This is where attackers manipulate AI models to make them do things they're not supposed to do. For example, they can create "adversarial examples" – slightly modified inputs that cause an AI model to make a wrong prediction. Think of a self-driving car that misidentifies a stop sign as a speed limit sign because of a few carefully placed stickers. That’s adversarial AI in action.
In the context of cybersecurity, adversarial AI can be used to bypass AI-powered threat detection systems. An attacker could create a piece of malware that is specifically designed to evade detection by a particular AI model. This is a huge problem, because many companies are becoming increasingly reliant on these AI-powered security tools. They have a false sense of security, thinking that their AI is a silver bullet. But it’s not.
I learned this the hard way. After the attack on my portfolio company, we did a deep dive into our security stack. We found that the attackers had used adversarial techniques to bypass our AI-based intrusion detection system. Our system, which we had paid a fortune for, was effectively blind to the attack. It was a wake-up call.
The Rise of Zero-Day AI
Another thing that keeps me up at night is the prospect of "zero-day AI". A zero-day vulnerability is a flaw in a piece of software that is unknown to the vendor. This means there is no patch available, and attackers can exploit the vulnerability to their heart's content. A zero-day AI would be a novel AI-powered attack that has never been seen before. It would be the cybersecurity equivalent of a black swan event.
Imagine an AI that can autonomously discover and exploit zero-day vulnerabilities in software. It could wreak havoc on a global scale, causing billions of dollars in damage. This might sound like science fiction, but it’s not as far-fetched as you might think. The same AI technologies that are being used for good can also be used for evil. And as these technologies become more powerful and more accessible, the risk of a zero-day AI event increases.
So, What Can We Do About It?
It’s easy to get discouraged when you think about all the ways that AI can be used to harm us. But I’m not a pessimist. I’m a builder. And I believe that we can build a future where AI is used to make us safer, not more vulnerable. But it’s not going to be easy. It’s going to require a fundamental shift in how we think about cybersecurity.
First, we need to move away from a reactive security posture to a proactive one. We can’t just wait for attacks to happen and then try to clean up the mess. We need to be constantly hunting for threats, looking for vulnerabilities, and patching them before they can be exploited. This means investing in things like threat intelligence, penetration testing, and bug bounty programs.
Second, we need to embrace a defense-in-depth strategy. There is no single silver bullet that will protect you from all threats. You need to have multiple layers of security, so that if one layer fails, you have others to fall back on. This includes things like firewalls, intrusion detection systems, endpoint protection, and data encryption.
Third, we need to get serious about AI security. This means developing new tools and techniques for detecting and mitigating AI-powered attacks. It also means developing new standards and best practices for building secure AI systems. We need to treat AI security as a first-class citizen, not as an afterthought.
The Road Ahead
I’m not going to lie to you. The road ahead is going to be tough. The bad guys are getting smarter, and the attacks are getting more sophisticated. But I’m optimistic. I’ve seen what happens when you get a group of smart, passionate people together to solve a hard problem. And I believe that we can solve this one too.
I’m putting my money where my mouth is. I’m actively investing in companies that are working on the future of AI cybersecurity. I’m looking for founders who are as obsessed with this problem as I am. Founders who are not just building another security product, but who are building a new paradigm for security.
This is not a problem that can be solved by one person or one company. It’s going to take a village. It’s going to take all of us – entrepreneurs, investors, researchers, and policymakers – working together. But if we do, I’m confident that we can build a future where we can all sleep a little more soundly at night. Even me.
Frequently Asked Questions
What's the most common pushback you get on this?
People often push back by citing exceptions or edge cases. And they're usually right that exceptions exist. But building a strategy around exceptions rather than patterns is a losing game for most founders.
How can I apply this thinking to my own situation?
Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.