They’re lying to you.
Not with malice, but with ignorance. The venture capitalists, the startup founders, the ‘thought leaders’—they’re all peddling the same tired narrative about AI cybersecurity. They talk about ‘AI-powered solutions’ and ‘next-gen platforms’ as if they’re magic bullets. They’re not.
I’ve spent my career in the trenches of Silicon Valley. I’ve built and sold two companies, RemoteTeam and MovieLaLa, and I’ve invested in over 200 startups, including some of the biggest names in AI like Anthropic, OpenAI, and Scale AI. I’ve seen firsthand how the sausage gets made, and I’m here to tell you that the way we’re approaching AI threat detection is fundamentally broken.
We’re fighting a new kind of war with old weapons. And we’re losing.
This isn’t another doom-and-gloom blog post. This is a wake-up call. It’s a look behind the curtain at what’s really happening in the world of AI security. And it’s a playbook for how to survive the new era of AI-driven threats.
If you’re a founder, a security professional, or just someone who cares about the future of technology, you need to read this. Because what you don’t know about AI threat detection can, and will, hurt you.
The New Wave of AI Threats: It’s Not Just About Phishing Anymore
For years, the boogeyman of AI security has been sophisticated phishing attacks. And yes, AI-generated phishing emails are getting scarily good. They can mimic writing styles, reference personal details, and create a sense of urgency that’s hard to resist. I’ve seen them bypass even the most well-trained employees.
But phishing is just the tip of the iceberg. The real danger lies in a new class of AI-driven attacks that are far more insidious and difficult to detect.
Adversarial AI: This is the stuff of nightmares for machine learning engineers. Adversarial attacks involve making tiny, almost imperceptible changes to data that cause AI models to make wildly incorrect predictions. Imagine a self-driving car that misclassifies a stop sign as a speed limit sign because a few pixels have been altered. Or a facial recognition system that can be fooled by a pair of specially designed glasses. These aren’t theoretical concepts; they’re happening right now. I remember a pitch from a startup that had developed a way to create adversarial examples for just about any image recognition system. They could make a cat look like a dog, a car look like a bicycle. It was terrifyingly effective.
Zero-Day AI Exploits: We’re all familiar with zero-day exploits in software. But what about zero-day exploits in AI models themselves? These are vulnerabilities in the architecture or training data of an AI model that can be exploited by attackers. And because many companies are using pre-trained models from third-party providers, they’re often unaware of these vulnerabilities until it’s too late. It’s a huge blind spot in the current security landscape.
AI-Powered Malware: This is where things get really scary. We’re starting to see malware that uses AI to adapt and evolve in real-time. It can learn from its environment, identify and bypass security measures, and even write its own code. This is the kind of threat that keeps CISOs up at night. It’s a self-learning, self-propagating weapon that can cause catastrophic damage.
These are not your garden-variety cyber threats. They are a new breed of intelligent, adaptive, and highly evasive attacks that are specifically designed to exploit the weaknesses of our increasingly AI-dependent world. And our current security infrastructure is woefully unprepared to deal with them.
Why the Old Playbook is Failing
So why are we so bad at defending against these new threats? It’s simple. We’re stuck in the past.
Our entire approach to cybersecurity is based on a pre-AI paradigm. We’re still relying on signature-based detection, rule-based systems, and manual human analysis. These methods are fine for catching known threats, but they’re completely useless against the new wave of AI-driven attacks.
I was in a board meeting for a cybersecurity startup I invested in a few years back. They had a great product, a great team, and a lot of traction. But they were obsessed with a single metric: the size of their threat intelligence database. They were convinced that the more signatures they had, the better their product would be. I tried to tell them that they were fighting the last war. That the future of threat detection wasn't about having the biggest database, but about having the smartest algorithms. They didn't listen. They ended up getting acquired for a fraction of what they could have been worth.
This is the kind of thinking that’s holding us back. We’re so focused on what we know that we’re completely blind to what we don’t.
Here’s the hard truth: you can’t fight an AI with a spreadsheet. You can’t catch an adversarial attack with a regular expression. And you can’t stop a zero-day AI exploit with a firewall.
We need a new playbook.
The New Playbook: How to Win the AI Security War
So what’s the answer? How do we defend ourselves against an enemy that’s smarter, faster, and more adaptive than anything we’ve ever faced before?
It’s not about buying another ‘AI-powered’ security product. It’s about a fundamental shift in mindset. It’s about embracing a new, more proactive, and more intelligent approach to security.
Here’s the new playbook:
1. Fight Fire with Fire: Deploy AI-Powered Defenses
The only way to beat an AI-powered attacker is with an AI-powered defender. You need to invest in security solutions that use machine learning to detect and respond to threats in real-time. These systems can analyze massive amounts of data, identify subtle patterns of malicious behavior, and even predict future attacks. When I was at RemoteTeam, we were an early adopter of a tool that used unsupervised learning to model normal network behavior and flag anything that deviated from the baseline. It caught a sophisticated intrusion attempt that our traditional security tools completely missed. That’s the power of AI-driven defense.
2. Embrace Adversarial Training
If you’re building or deploying AI models, you need to be training them to withstand adversarial attacks. This means intentionally generating and feeding them adversarial examples so they can learn to recognize and ignore them. It’s like a vaccine for your AI. It’s not a perfect solution, but it’s one of the most effective ways to harden your models against this new type of threat. I won’t invest in an AI company today unless they can show me a robust adversarial training program.
3. Demand Explainable AI (XAI)
One of the biggest challenges with AI is that it can be a ‘black box.’ We don’t always know why a model makes a particular decision. This is a huge problem for security. If you can’t understand why your AI is flagging something as a threat, you can’t trust it. That’s why explainable AI (XAI) is so critical. XAI techniques provide visibility into the inner workings of AI models, helping you understand their reasoning and identify potential biases or vulnerabilities. Don’t just accept a vendor’s claims about their AI’s accuracy; demand to see the explanations.
4. Build a Culture of Security, Not Just a Wall of Tools
At the end of the day, the strongest security tool you have is your team. You can have the most advanced AI-powered defenses in the world, but if your employees are clicking on phishing links or using weak passwords, you’re still vulnerable. I’ve seen more security breaches caused by human error than by any sophisticated hacking tool. You need to invest in continuous security training, create a culture where people feel comfortable reporting potential threats, and make security everyone’s responsibility. It’s not just about technology; it’s about people.
The Real Threat Isn't the AI, It's Our Complacency
I’m not an alarmist. I’m a builder. I’ve dedicated my career to creating and investing in technology that moves the world forward. I’m more optimistic about the potential of AI than almost anyone I know. I’ve put my money where my mouth is, with early investments in the foundational companies of this new era.
But I’m also a realist. And the reality is that we are at a critical inflection point. The same technology that has the power to solve some of humanity’s biggest challenges also has the power to create unprecedented chaos and destruction.
Silicon Valley loves to sell a good story. The story of AI as a benevolent force for good is a powerful one. But it’s only half the story. The other half is being written right now, in the shadows, by a new generation of adversaries who are using our own tools against us.
Don’t be fooled by the hype. Don’t be lulled into a false sense of security by the marketing slogans and the slick product demos. The threat is real, it’s here, and it’s growing every single day.
It’s time to wake up. It’s time to stop fighting the last war and start preparing for the next one. It’s time to build a more secure, more resilient, and more intelligent future.
Your move.
Frequently Asked Questions
Do all experts agree with this view?
No, and that's fine. The best ideas in business are often contrarian. I share my perspective based on my experience and data, but I encourage you to seek out opposing viewpoints and form your own conclusions.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.
What's the most common pushback you get on this?
People often push back by citing exceptions or edge cases. And they're usually right that exceptions exist. But building a strategy around exceptions rather than patterns is a losing game for most founders.
How can I apply this thinking to my own situation?
Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.