In the last several years AI has progressed rapidly but predictably, and in that time the cyber community learns the bitter lesson over and over again. We’ve collectively sleep walked into the current state of things and now I see emotionally driven responses when those outside the community try to address it. “Do nothing” and continuing down the same path isn’t a counter proposal.
These models are far more capable and scaleable than any of us. And they cannot be deterred like a human adversary. Why would we reject the possibility that an agentic swarm could take down vast swaths of the internet, including critical infrastructure? This is rather ironic considering I've seen virtually no push back to L0pht's Senate testimony 28 years ago (or any of the panels celebrating its anniversary since) where they claimed they could take down the internet in 30 minutes.
We all know how broken things are, how so many in leadership never respond beyond moral support despite the overwhelming evidence. I'm no AI doomer, quite the opposite, but the current state of cyber stands in the way of realizing all of AI's benefits. The old way isn't going to work anymore and its time to abandon it. Abandon the complex risk management spreadsheets, the performative training, the compliance regimes, and yes remove humans in the loop for every decision. None of this will survive the speed and sophistication of agents driven by frontier models.