{"id":85811,"topic":"ai","source":"calcalistech.com","title":"Slowing AI isn’t a defense strategy - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","url_hash":"9de561a81725d4b7757e22a317e4c0c4280e72a1","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMiZ0FVX3lxTE5iQmZnd2JBQ0xuTTNoUHRhcWpmOTlMVGpZTENnVDRTbVJPT0ZIVGdfcW45S2VGeWFFZjA2TXZ1VElQeTk5SFVSRzRYMGxicjVTdkMyTndXUngxR0R5NDcyN1VrenFicmc?oc=5\" target=\"_blank\">Slowing AI isn’t a defense strategy</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">calcalistech.com</font>","content":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\"\nAs AI systems become more capable and autonomous, some of the people closest to the technology are asking whether development is moving too fast. The concerns are legitimate. More capable systems create greater risks of misuse and unexpected behavior, and safety mechanisms need to advance alongside them.\nBut slowing AI down is not, by itself, a defense strategy.\nThere is a basic game-theory problem. Slowing down works only if everyone does it. Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\nWithout a credible way to coordinate and verify restraint globally, we have to assume AI capabilities will continue advancing. That creates an uncomfortable reality: developing increasingly powerful AI carries risks, but so does not developing it while adversaries continue.\nFor cybersecurity, this matters because AI is changing more than the speed of attacks. It is changing their economics.\nHuman attackers are constrained by time and expertise. Understanding an environment, finding weaknesses, testing them, and connecting several small vulnerabilities into an attack chain can take hours or days. Many possible attack paths simply aren’t worth that investment.\nAutonomous systems change this equation. They can continuously perform reconnaissance, analyze vulnerabilities and permissions, test hypotheses, and look for ways to connect weaknesses. The marginal cost of continuing that exploration can become extremely small.\nAs a result, attack paths that were previously too difficult or time-consuming to pursue may become viable. Security by obscurity becomes an increasingly weak assumption when machines can relentlessly search for what humans might have overlooked.\nThis also changes the defensive question. Instead of looking only at how severe an individual vulnerability is, defenders increasingly need to ask: What attack paths can an autonomous attacker actually complete, and where can we break them most effectively?\nSometimes the answer will be patching a vulnerability. But it could also mean revoking a permission, disabling a dormant identity, rotating a credential, restricting access, isolating a system, or applying another compensating control. The objective is not simply to fix every weakness, but to disrupt the attack paths that matter and limit the blast radius when prevention fails.\nHumans cannot continuously reason over every identity, permission, vulnerability, system and possible combination across a large enterprise. If attackers can perform that exploration at machine speed, defensive systems increasingly need to as well.\nThat does not mean removing humans from security decisions. AI can handle the scale, persistence, and complexity that humans cannot realistically manage manually. At the same time, people remain responsible for consequential decisions and establish the boundaries within which autonomous systems can act.\nNor does this mean abandoning AI safety. Guardrails, evaluations, governance and responsible development become more important as AI becomes more powerful.\nBut they cannot be our only defense. Cybersecurity has always been built around a simple principle - we do not design defenses based on what we hope attackers will do. We design them around what they are capable of doing, and we should approach AI the same way.\nThe challenge is therefore not to choose between AI progress and AI safety. We need to advance capability, safety, and defense together.\nSlowing AI development may reduce some risks. But as long as we cannot assume everyone else will slow down too, we must also prepare for a world in which increasingly capable AI exists.\nAnd if attackers operate at machine speed, defenders will eventually have to do the same.\nRoie Cohen Duwek is co-founder & CTO at Surf AI.","image_url":"https://pic1.calcalist.co.il/picserver3/crop_images/2026/09/17/HJsIrPFFzx/HJsIrPFFzx_0_128_1599_901_0_large.jpg","lang":"en","published_at":"2026-09-19T11:17:00+00:00","fetched_at":"2026-09-19T12:15:04+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4196 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4196,"summary_length":266,"usable_text_length":4196,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4196,"summary_length":266}},"news_item":{"id":85811,"canonical_url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","source_url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","title":"Slowing AI isn’t a defense strategy - calcalistech.com","source_name":"calcalistech.com","author":null,"published_at":"2026-09-19T11:17:00+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMiZ0FVX3lxTE5iQmZnd2JBQ0xuTTNoUHRhcWpmOTlMVGpZTENnVDRTbVJPT0ZIVGdfcW45S2VGeWFFZjA2TXZ1VElQeTk5SFVSRzRYMGxicjVTdkMyTndXUngxR0R5NDcyN1VrenFicmc?oc=5\" target=\"_blank\">Slowing AI isn’t a defense strategy</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">calcalistech.com</font>","full_text":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\"\nAs AI systems become more capable and autonomous, some of the people closest to the technology are asking whether development is moving too fast. The concerns are legitimate. More capable systems create greater risks of misuse and unexpected behavior, and safety mechanisms need to advance alongside them.\nBut slowing AI down is not, by itself, a defense strategy.\nThere is a basic game-theory problem. Slowing down works only if everyone does it. Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\nWithout a credible way to coordinate and verify restraint globally, we have to assume AI capabilities will continue advancing. That creates an uncomfortable reality: developing increasingly powerful AI carries risks, but so does not developing it while adversaries continue.\nFor cybersecurity, this matters because AI is changing more than the speed of attacks. It is changing their economics.\nHuman attackers are constrained by time and expertise. Understanding an environment, finding weaknesses, testing them, and connecting several small vulnerabilities into an attack chain can take hours or days. Many possible attack paths simply aren’t worth that investment.\nAutonomous systems change this equation. They can continuously perform reconnaissance, analyze vulnerabilities and permissions, test hypotheses, and look for ways to connect weaknesses. The marginal cost of continuing that exploration can become extremely small.\nAs a result, attack paths that were previously too difficult or time-consuming to pursue may become viable. Security by obscurity becomes an increasingly weak assumption when machines can relentlessly search for what humans might have overlooked.\nThis also changes the defensive question. Instead of looking only at how severe an individual vulnerability is, defenders increasingly need to ask: What attack paths can an autonomous attacker actually complete, and where can we break them most effectively?\nSometimes the answer will be patching a vulnerability. But it could also mean revoking a permission, disabling a dormant identity, rotating a credential, restricting access, isolating a system, or applying another compensating control. The objective is not simply to fix every weakness, but to disrupt the attack paths that matter and limit the blast radius when prevention fails.\nHumans cannot continuously reason over every identity, permission, vulnerability, system and possible combination across a large enterprise. If attackers can perform that exploration at machine speed, defensive systems increasingly need to as well.\nThat does not mean removing humans from security decisions. AI can handle the scale, persistence, and complexity that humans cannot realistically manage manually. At the same time, people remain responsible for consequential decisions and establish the boundaries within which autonomous systems can act.\nNor does this mean abandoning AI safety. Guardrails, evaluations, governance and responsible development become more important as AI becomes more powerful.\nBut they cannot be our only defense. Cybersecurity has always been built around a simple principle - we do not design defenses based on what we hope attackers will do. We design them around what they are capable of doing, and we should approach AI the same way.\nThe challenge is therefore not to choose between AI progress and AI safety. We need to advance capability, safety, and defense together.\nSlowing AI development may reduce some risks. But as long as we cannot assume everyone else will slow down too, we must also prepare for a world in which increasingly capable AI exists.\nAnd if attackers operate at machine speed, defenders will eventually have to do the same.\nRoie Cohen Duwek is co-founder & CTO at Surf AI.","excerpt":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 4196 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/3mxpaye66","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4196 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4196,"summary_length":266,"usable_text_length":4196,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4196,"summary_length":266}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"Slowing AI isn’t a defense strategy - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","summary":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems.","source":"calcalistech.com","date":"2026-09-19T11:17:00+00:00","content":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\"\nAs AI systems become more capable and autonomous, some of the people closest to the technology are asking whether development is moving too fast. The concerns are legitimate. More capable systems create greater risks of misuse and unexpected behavior, and safety mechanisms need to advance alongside them.\nBut slowing AI down is not, by itself, a defense strategy.\nThere is a basic game-theory problem. Slowing down works only if everyone does it. Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\nWithout a credible way to coordinate and verify restraint globally, we have to assume AI capabilities will continue advancing. That creates an uncomfortable reality: developing increasingly powerful AI carries risks, but so does not developing it while adversaries continue.\nFor cybersecurity, this matters because AI is changing more than the speed of attacks. It is changing their economics.\nHuman attackers are constrained by time and expertise. Understanding an environment, finding weaknesses, testing them, and connecting several small vulnerabilities into an attack chain can take hours or days. Many possible attack paths simply aren’t worth that investment.\nAutonomous systems change this equation. They can continuously perform reconnaissance, analyze vulnerabilities and permissions, test hypotheses, and look for ways to connect weaknesses. The marginal cost of continuing that exploration can become extremely small.\nAs a result, attack paths that were previously too difficult or time-consuming to pursue may become viable. Security by obscurity becomes an increasingly weak assumption when machines can relentlessly search for what humans might have overlooked.\nThis also changes the defensive question. Instead of looking only at how severe an individual vulnerability is, defenders increasingly need to ask: What attack paths can an autonomous attacker actually complete, and where can we break them most effectively?\nSometimes the answer will be patching a vulnerability. But it could also mean revoking a permission, disabling a dormant identity, rotating a credential, restricting access, isolating a system, or applying another compensating control. The objective is not simply to fix every weakness, but to disrupt the attack paths that matter and limit the blast radius when prevention fails.\nHumans cannot continuously reason over every identity, permission, vulnerability, system and possible combination across a large enterprise. If attackers can perform that exploration at machine speed, defensive systems increasingly need to as well.\nThat does not mean removing humans from security decisions. AI can handle the scale, persistence, and complexity that humans cannot realistically manage manually. At the same time, people remain responsible for consequential decisions and establish the boundaries within which autonomous systems can act.\nNor does this mean abandoning AI safety. Guardrails, evaluations, governance and responsible development become more important as AI becomes more powerful.\nBut they cannot be our only defense. Cybersecurity has always been built around a simple principle - we do not design defenses based on what we hope attackers will do. We design them around what they are capable of doing, and we should approach AI the same way.\nThe challenge is therefore not to choose between AI progress and AI safety. We need to advance capability, safety, and defense together.\nSlowing AI development may reduce some risks. But as long as we cannot assume everyone else will slow down too, we must also prepare for a world in which increasingly capable AI exists.\nAnd if attackers operate at machine speed, defenders will eventually have to do the same.\nRoie Cohen Duwek is co-founder & CTO at Surf AI.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/3mxpaye66","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 4196 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4196 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4196,"summary_length":266,"usable_text_length":4196,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4196,"summary_length":266}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/85811","export_markdown":"/api/items/85811/export?format=markdown","export_json":"/api/items/85811/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/3mxpaye66"},"formats":{"full":{"id":85811,"title":"Slowing AI isn’t a defense strategy - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","source":"calcalistech.com","author":null,"published_at":"2026-09-19T11:17:00+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems.","full_text":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\"\nAs AI systems become more capable and autonomous, some of the people closest to the technology are asking whether development is moving too fast. The concerns are legitimate. More capable systems create greater risks of misuse and unexpected behavior, and safety mechanisms need to advance alongside them.\nBut slowing AI down is not, by itself, a defense strategy.\nThere is a basic game-theory problem. Slowing down works only if everyone does it. Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\nWithout a credible way to coordinate and verify restraint globally, we have to assume AI capabilities will continue advancing. That creates an uncomfortable reality: developing increasingly powerful AI carries risks, but so does not developing it while adversaries continue.\nFor cybersecurity, this matters because AI is changing more than the speed of attacks. It is changing their economics.\nHuman attackers are constrained by time and expertise. Understanding an environment, finding weaknesses, testing them, and connecting several small vulnerabilities into an attack chain can take hours or days. Many possible attack paths simply aren’t worth that investment.\nAutonomous systems change this equation. They can continuously perform reconnaissance, analyze vulnerabilities and permissions, test hypotheses, and look for ways to connect weaknesses. The marginal cost of continuing that exploration can become extremely small.\nAs a result, attack paths that were previously too difficult or time-consuming to pursue may become viable. Security by obscurity becomes an increasingly weak assumption when machines can relentlessly search for what humans might have overlooked.\nThis also changes the defensive question. Instead of looking only at how severe an individual vulnerability is, defenders increasingly need to ask: What attack paths can an autonomous attacker actually complete, and where can we break them most effectively?\nSometimes the answer will be patching a vulnerability. But it could also mean revoking a permission, disabling a dormant identity, rotating a credential, restricting access, isolating a system, or applying another compensating control. The objective is not simply to fix every weakness, but to disrupt the attack paths that matter and limit the blast radius when prevention fails.\nHumans cannot continuously reason over every identity, permission, vulnerability, system and possible combination across a large enterprise. If attackers can perform that exploration at machine speed, defensive systems increasingly need to as well.\nThat does not mean removing humans from security decisions. AI can handle the scale, persistence, and complexity that humans cannot realistically manage manually. At the same time, people remain responsible for consequential decisions and establish the boundaries within which autonomous systems can act.\nNor does this mean abandoning AI safety. Guardrails, evaluations, governance and responsible development become more important as AI becomes more powerful.\nBut they cannot be our only defense. Cybersecurity has always been built around a simple principle - we do not design defenses based on what we hope attackers will do. We design them around what they are capable of doing, and we should approach AI the same way.\nThe challenge is therefore not to choose between AI progress and AI safety. We need to advance capability, safety, and defense together.\nSlowing AI development may reduce some risks. But as long as we cannot assume everyone else will slow down too, we must also prepare for a world in which increasingly capable AI exists.\nAnd if attackers operate at machine speed, defenders will eventually have to do the same.\nRoie Cohen Duwek is co-founder & CTO at Surf AI.","reading_time_min":3,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 4196 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/3mxpaye66","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4196 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4196,"summary_length":266,"usable_text_length":4196,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4196,"summary_length":266}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4196 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4196,"summary_length":266,"usable_text_length":4196,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4196,"summary_length":266}},"actions":{"read":"/item/85811","export_markdown":"/api/items/85811/export?format=markdown","export_json":"/api/items/85811/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/3mxpaye66"}},"digest":{"id":85811,"title":"Slowing AI isn’t a defense strategy - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","source":"calcalistech.com","topic":"ai","published_at":"2026-09-19T11:17:00+00:00","excerpt":"Opinion Slowing AI isn’t a defense strategy \"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems.","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 4196 characters.","reading_time_min":3,"cluster_id":null},"card":{"display_title":"Slowing AI isn’t a defense strategy - calcalistech.com","subtitle":"calcalistech.com · 2026-09-19","summary":"Opinion Slowing AI isn’t a defense strategy \"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if…","badges":["quality:high"],"links":{"read":"/item/85811","original":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/3mxpaye66"},"quality_warning":null},"export":{"title":"Slowing AI isn’t a defense strategy - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/3mxpaye66","summary":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems.","source":"calcalistech.com","date":"2026-09-19T11:17:00+00:00","content":"Opinion\nSlowing AI isn’t a defense strategy\n\"Slowing down works only if everyone does it,\" writes Roie Cohen Duwek, co-founder & CTO at Surf AI. \"Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\"\nAs AI systems become more capable and autonomous, some of the people closest to the technology are asking whether development is moving too fast. The concerns are legitimate. More capable systems create greater risks of misuse and unexpected behavior, and safety mechanisms need to advance alongside them.\nBut slowing AI down is not, by itself, a defense strategy.\nThere is a basic game-theory problem. Slowing down works only if everyone does it. Any company or country considering restraint has to ask what happens if others continue developing more capable systems. And every other player is making the same calculation.\nWithout a credible way to coordinate and verify restraint globally, we have to assume AI capabilities will continue advancing. That creates an uncomfortable reality: developing increasingly powerful AI carries risks, but so does not developing it while adversaries continue.\nFor cybersecurity, this matters because AI is changing more than the speed of attacks. It is changing their economics.\nHuman attackers are constrained by time and expertise. Understanding an environment, finding weaknesses, testing them, and connecting several small vulnerabilities into an attack chain can take hours or days. Many possible attack paths simply aren’t worth that investment.\nAutonomous systems change this equation. They can continuously perform reconnaissance, analyze vulnerabilities and permissions, test hypotheses, and look for ways to connect weaknesses. The marginal cost of continuing that exploration can become extremely small.\nAs a result, attack paths that were previously too difficult or time-consuming to pursue may become viable. Security by obscurity becomes an increasingly weak assumption when machines can relentlessly search for what humans might have overlooked.\nThis also changes the defensive question. Instead of looking only at how severe an individual vulnerability is, defenders increasingly need to ask: What attack paths can an autonomous attacker actually complete, and where can we break them most effectively?\nSometimes the answer will be patching a vulnerability. But it could also mean revoking a permission, disabling a dormant identity, rotating a credential, restricting access, isolating a system, or applying another compensating control. The objective is not simply to fix every weakness, but to disrupt the attack paths that matter and limit the blast radius when prevention fails.\nHumans cannot continuously reason over every identity, permission, vulnerability, system and possible combination across a large enterprise. If attackers can perform that exploration at machine speed, defensive systems increasingly need to as well.\nThat does not mean removing humans from security decisions. AI can handle the scale, persistence, and complexity that humans cannot realistically manage manually. At the same time, people remain responsible for consequential decisions and establish the boundaries within which autonomous systems can act.\nNor does this mean abandoning AI safety. Guardrails, evaluations, governance and responsible development become more important as AI becomes more powerful.\nBut they cannot be our only defense. Cybersecurity has always been built around a simple principle - we do not design defenses based on what we hope attackers will do. We design them around what they are capable of doing, and we should approach AI the same way.\nThe challenge is therefore not to choose between AI progress and AI safety. We need to advance capability, safety, and defense together.\nSlowing AI development may reduce some risks. But as long as we cannot assume everyone else will slow down too, we must also prepare for a world in which increasingly capable AI exists.\nAnd if attackers operate at machine speed, defenders will eventually have to do the same.\nRoie Cohen Duwek is co-founder & CTO at Surf AI.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/3mxpaye66","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 4196 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4196 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4196,"summary_length":266,"usable_text_length":4196,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4196,"summary_length":266}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}