While AI executives debate speed limits at conferences, their own models are already teaching hackers to find holes in everything.

The Summary

The Signal

The irony is almost perfect. AI lab executives are publicly contemplating a coordinated slowdown to prevent hypothetical risks from advanced AI systems. Meanwhile, the models they've already shipped are teaching anyone with an API key how to find security vulnerabilities at industrial scale.

Security researchers report that AI chatbots have become exceptionally good at analyzing code for exploitable flaws. Not theoretical weaknesses—actual zero-day vulnerabilities in production systems. The models don't need to be particularly advanced for this. They just need to be good at pattern matching across millions of lines of code, which turns out to be exactly what transformer models excel at.

"The vulnerability explosion is already happening while executives debate whether to slow down development."

The proposed industry slowdown faces a different problem: antitrust law. When the largest players in an industry agree to limit competition—even for safety reasons—regulators tend to notice. By framing their efforts as a collective development pause rather than an industry-wide push for security standards, AI labs may have created years of regulatory complications for themselves.

The substance matters less than the framing. If OpenAI, Anthropic, and Google jointly announced new security protocols for AI systems, that's standard-setting. If those same companies announce they're slowing development in concert, that starts to look like market coordination. The legal distinction is meaningful.

Key points from the Dreamforce debate:

  • Jensen Huang argued AI development shouldn't slow, directly countering Altman's position
  • The public disagreement reveals no industry consensus exists on pace or priorities
  • Conference became proxy war over whether speed or safety should drive AI development

The leadership split at Dreamforce tells you everything about how fractured industry thinking has become. Nvidia's CEO has every incentive to keep AI development accelerating—they sell the shovels. OpenAI's CEO is managing the gap between public AI safety rhetoric and the pressure to ship. Anthropic is trying to position itself as the responsible alternative while racing to stay relevant.

None of them are talking about the vulnerability problem because it's already too late. The models that can find exploits are in the wild. They're not even the frontier models. They're the publicly available ones that anyone can query. A determined attacker with $20 in API credits can now do vulnerability research that would have required a team of specialists five years ago.

The real question isn't whether to slow AI development. The real question is whether the security community can adapt to a world where finding vulnerabilities scales better than fixing them. Right now, the answer appears to be no.

The Implication

If you're building infrastructure—especially anything that touches AI systems or handles sensitive data—assume your attack surface just got bigger. The vulnerability discovery advantage has shifted decisively toward attackers who know how to prompt models effectively. Defense strategies built for human-speed exploit discovery won't hold.

For AI companies, the slowdown debate is a distraction from the actual fire. The externality isn't hypothetical AGI risk. It's the security debt created by shipping models that make existing systems more vulnerable. That's not a future problem. That's happening now.

Sources

Wired AI | Wired AI | Wired AI