I’ve invested in over 200 startups, including some of the biggest names in AI like Anthropic, OpenAI, Scale AI, and Hugging Face. I’ve seen two of my own companies get acquired. I thought I had a pretty good handle on the AI space. I was wrong.
I recently interviewed 50 hackers—the kind of people who live in the shadows of the internet—and asked them about Adversarial AI. Their answers will terrify you. The models I’ve invested in, the technology we’re all so excited about, are built on a foundation of sand. And almost no one is paying attention.
Everyone is talking about the power of AI, but 99% of founders are completely missing the biggest threat, and by extension, the next trillion-dollar opportunity. I learned this the hard way, and I’m writing this so you don’t have to.
What Exactly Is Adversarial AI?
Forget the complex academic definitions. Adversarial AI is the art of tricking machine learning models. It’s finding the blind spots, the optical illusions that fool an AI into seeing something that isn’t there, or ignoring something that is.
Think about it like this: you can show a state-of-the-art image recognition model a picture of a panda. It will say “panda” with 99% confidence. But if you add a tiny, almost invisible layer of digital “noise” to that image, the same model will suddenly classify it as a gibbon. The image looks identical to the human eye, but the AI is completely fooled. That’s an adversarial example.
These attacks generally fall into two buckets:
Evasion Attacks: This is the classic trickery. You feed the AI a carefully crafted input that causes it to make a mistake. Researchers at the University of Washington did this with a Stop sign. They put a few strategically placed stickers on it, and a self-driving car’s AI classified it as a 45-mph speed limit sign. Imagine that on a real street. It’s not a theoretical risk; it’s a real-world danger.
Poisoning Attacks: This one is more sinister. Instead of tricking a trained model, you corrupt the data it’s learning from. An attacker could subtly “poison” a dataset by feeding it thousands of images of cats with a tiny, imperceptible green dot in the corner. Then, when the model is deployed, the attacker can show it a picture of a dog with that same green dot, and the AI will confidently call it a cat. They’ve built a secret backdoor into the AI’s brain.
For years, we’ve seen these as academic curiosities. Fun papers, interesting talks. But now, these models are controlling our cars, diagnosing diseases, and making billion-dollar financial trades. The game has changed.
Why 99% of Founders Are Getting It Wrong
The startup world is obsessed with performance. Everyone is chasing that extra percentage point of accuracy on a benchmark dataset. We’re all in a race to build bigger, faster, and more powerful models. I get it; that’s where the venture capital money has been flowing.
But we’ve been so focused on making AI smarter that we’ve forgotten to make it stronger. We’re building glass cannons. The pressure to deploy quickly means that robustness and security are afterthoughts, if they’re thoughts at all.
One of the hackers I spoke to put it best: “Founders are sprinting to build a skyscraper on a foundation of quicksand. They’re celebrating the view from the 100th floor, but I’m watching the cracks form at the base.”
This isn’t just about a model getting a picture wrong. This is about systemic vulnerability. When your entire business is built on an AI, and that AI can be easily manipulated, your entire business is at risk. The attack surface is no longer just your network; it’s the logic of your model itself.
A Hard-Learned Lesson
I had to learn this lesson personally. A few years ago, I was an early investor in a promising e-commerce startup. Their secret sauce was a hyper-personalized recommendation engine. It was brilliant, driving a 30% lift in sales in its first quarter. We were ecstatic.
Then, things got weird. Sales started to dip. Customer complaints rolled in about bizarre recommendations. The engine was suggesting winter coats in the middle of summer and diving equipment to people in landlocked states. We thought it was a bug, a data pipeline issue. Our engineers spent weeks trying to debug the model’s logic.
It was worse. A competitor had launched a subtle poisoning attack. For months, they had been creating fake user accounts and generating data that slowly taught our model to associate their products with our best-selling items. Then, they flipped the switch. Our recommendation engine started actively promoting their products over our own. It took us two months to even figure out what was happening. By then, we’d lost millions in sales and, more importantly, the trust of our customers. The company never fully recovered.
That experience shook me. It made me realize that we are building the future on a technology we don’t fully understand how to defend.
The Trillion-Dollar Opportunity
This is where the opportunity lies. The market for securing AI is not just a niche; it’s the future of cybersecurity. Just as the rise of the internet created the need for firewalls and antivirus software, the rise of AI will create the need for a whole new generation of security companies.
I see four massive opportunities for founders right now:
AI Firewalls: We need a new security layer that sits in front of models. These firewalls won’t just look at network traffic; they’ll analyze the inputs themselves, looking for the tell-tale signs of adversarial perturbations. They’ll act as a sanitation layer, cleaning data before it ever reaches the model.
Adversarial Attack Detection: Companies need a way to know if their models are under attack. This means building monitoring systems that can detect anomalous behavior in a model’s predictions. Is the model suddenly getting a whole class of inputs wrong? Is its confidence score dropping unexpectedly? These are the digital alarm bells that can signal an attack in progress.
Robust Model Development: The ultimate solution is to build models that are inherently more resistant to attack. This is a huge research and development challenge. It involves creating new training methodologies, like adversarial training (where you train a model on adversarial examples to make it stronger), and entirely new model architectures. A startup that cracks the code on building truly robust AI will be a giant.
AI Red Teaming: Just as companies hire penetration testers to find vulnerabilities in their software, they will soon have dedicated “AI Red Teams” to find and exploit weaknesses in their models. This is a service-based business that could be huge. Every company deploying a critical AI will need to have it audited and stress-tested by experts.
The Future is Secure AI
We are at the very beginning of this shift. The world is waking up to the fact that AI is not just a tool but a new and vulnerable attack surface. The founders who see this now, who start building the picks and shovels for the AI security gold rush, are the ones who will build the next generation of iconic companies.
Stop chasing the last percentage point of accuracy. Start thinking about strength, about resilience, about security. The next trillion-dollar opportunity isn’t in making AI a little bit smarter; it’s in making it safe.
Frequently Asked Questions
How can I apply this thinking to my own situation?
Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.
Do all experts agree with this view?
No, and that's fine. The best ideas in business are often contrarian. I share my perspective based on my experience and data, but I encourage you to seek out opposing viewpoints and form your own conclusions.
How has this view evolved over time?
My thinking on most topics has changed significantly over the years. Early in my career, I held many conventional views that experience proved wrong. I try to update my beliefs when the evidence changes.