Every conversation about AI in cybersecurity lands on the same promise: give defenders their own AI agents and let them fight the attackers’ agents at machine speed.
I believe in that promise. I also think most of the companies that need it most will refuse it. This essay is about both of those things, and about what it would take to get from one to the other.
01 · The setting
Two economies running on two different clocks
To see the problem clearly, split the economy in two.
The AI economy is everything being built from scratch right now. New companies, new products, internal tools that went live last quarter on modern cloud platforms with AI built in from day one. Not much of it is old, and not much of it is load-bearing yet. If something breaks, you roll it back and ship again before lunch. This economy rewards speed. The winners are the people who try more things, faster.
The legacy economy is every business that makes real money today. The regional bank. The hospital system. The trucking company, the water utility, the plant that stamps out brackets for somebody else’s cars. Their systems were built over twenty or thirty years, one layer on top of another, and some of the most important ones are older than the people running them. They run payroll on Friday. Customers expect them open on Monday.
Built this year
The AI economy
- Rewards
- Speed and new ideas
- Systems
- Modern, automated, easy to replace
- A bad release
- Costs an afternoon
Built over decades
The legacy economy
- Rewards
- Stability and predictability
- Systems
- Layered, fragile, hard to touch
- A bad release
- Costs revenue, paychecks, sometimes lives
The legacy economy rewards stability, and it has good reason to. When a system goes down there, trucks don’t leave the yard, patients wait, and paychecks don’t clear. A startup that breaks production has a bad afternoon. A hospital that breaks production has a very different kind of day.
Most of the excitement about AI and security quietly assumes the first economy. Most of the country actually runs on the second.
02 · The idea
What defensive coscaling is
Coscaling means the defense grows as fast as the offense. And the offense is growing very fast.
Last November, Anthropic reported a state-sponsored espionage campaign in which AI did 80 to 90 percent of the hacking against roughly thirty organizations, firing off thousands of requests, often several per second. Mandiant found that the average time between a vulnerability going public and attackers exploiting it dropped from 63 days in 2018–19 to five days in 2023. That was before attackers had agents doing the work.
Defensive coscaling is the answer in kind: swarms of defensive AI agents running 24/7/365, doing everything a security team would do if it had a thousand people who never slept. In practice, that looks like this:
- Patch everythingTest, stage, and roll out fixes on every server, laptop, and network device, not just the ones that fit in this month’s window.
- Know everythingKeep a live inventory of every device, app, cloud account, and forgotten test server.
- Watch everythingRead every log and every alert, all night, every night, and escalate what matters.
- Hunt everywhereAssume someone is already inside and go looking for them before they make their move.
- Lock down identitiesFind stale accounts, missing multi-factor login, shared passwords, and people with far more access than their job needs.
- Catch driftSpot the firewall rule someone opened “temporarily” in 2019 and the storage bucket that went public last Tuesday.
- See the outsideLook at the company the way an attacker does: exposed services, leaked passwords, lookalike web domains.
- Vet the vendorsTrack the software and suppliers you depend on, and flag the moment one of them is compromised.
- Triage phishingTake apart every reported email and pull the bad ones out of every inbox.
- Prove the backupsRestore from them on a schedule, so you learn they’re broken before a ransom note tells you.
- Contain in secondsIsolate an infected laptop or shut off a hijacked account right away, not after the morning meeting.
- Show the workKeep the evidence auditors, insurers, and the board ask for, without anyone building a spreadsheet by hand.
Everything, everywhere, all at once.
A lot of this is closer than people think. At DEF CON in August 2025, the finalists in DARPA’s AI Cyber Challenge ran fully autonomous systems against 54 million lines of real open-source code. They found 54 planted vulnerabilities, patched 43 of them, and turned up 18 real ones nobody had put there.
The machines can do the work. The question is whether anyone will let them.
03 · The resistance
Why it won’t work
Salim Ismail, who brings this up often on the Moonshots podcast, has a name for what happens next. He calls it the corporate immune system. When something new and disruptive shows up inside a large organization, the organization treats it like an infection. Legal finds a risk. Procurement finds a process. Operations finds a reason. The antibodies swarm, and the new thing dies. Nobody has to be the villain. The system is doing what it was built to do, which is protect a business that already works.
In security, the immune system has its own name. It’s called change control.
Every change to a production system at a legacy company goes through a process. Someone writes up what will change, why, what could break, and how to undo it. A review board looks it over. The business owners sign off. Then the change waits for a maintenance window, and there aren’t many of those.
What “good at cybersecurity” actually looks like
It’s 2 a.m. on the third Sunday of the month. That’s the only patch window the COO will allow, because it’s the only time the business can survive being down. One guy is at a keyboard. For the last three weeks he has fought to get as many patches as he could through change control. Some got approved. Some got pushed to next month because an application owner was nervous. Now he’s installing what he got, and rebooting servers that haven’t been rebooted since the last time he did this. Then he waits for them to come back up, praying with every ounce of his soul.
A typical patch night
- Maintenance window opens.
- 31 of 44 patches approved this month. Installing.
- Rebooting the ERP database server.
- Waiting.
- Still waiting.
- Server responding. Checking the application.
- Payroll is up. Warehouse is up.
- 13 patches carried over to next month.
If you ever want to find Jesus, be that guy once.
Sit there watching the server that runs the plant, knowing that if it doesn’t come back, you’re the one getting walked out on Monday. Nobody will remember the thirty patches that went fine.
That is what being good at cybersecurity looks like in the legacy economy. It isn’t a fancy new model that finds ten thousand vulnerabilities. It’s the guy at 2 a.m. who gets thirty-one of them fixed without breaking anything.
Now pitch him a swarm
Walk into that company and propose a swarm of AI agents that patches everything, all the time, with no window.
They’ve seen this movie. On July 19, 2024, one faulty update from the security company CrowdStrike crashed about 8.5 million Windows computers. Flights were grounded. Hospitals postponed procedures. Banks and broadcasters had outages. That was a single update from a trusted vendor, pushed automatically, which is exactly what security updates are supposed to do. Every COO in America remembers that Friday.
So the immune system kicks in, and honestly, it has a point.
Every incentive in the legacy economy points the same direction. Operations is measured on uptime. IT is measured on uptime. Executives are paid on this quarter’s results, and a breach that didn’t happen never shows up in the results. If a patch breaks production, everyone knows whose fault it is by breakfast. If skipping a patch leads to a breach eighteen months later, the trail is so long that nobody really owns it.
Under those rules, saying no to the swarm is the rational choice. That’s why it won’t work.
Finding vulnerabilities was never the bottleneck. The bottleneck is how many changes a business will let you make. Point a faster scanner at a once-a-month patch window and all you get is a bigger backlog.
04 · The stakes
Why it must work
Now picture the attackers getting their swarms while the defenders don’t.
Start with Live Free or Die Hard, where hackers run a “fire sale” and knock over transportation, finance, and utilities one after another. Take out Bruce Willis. Add Mr. Robot, except fsociety isn’t going after one Evil Corp. It’s going after every one of them on the same night. Then add WarGames, except this time nobody teaches the computer tic-tac-toe, so it never figures out that the only winning move is not to play.
That sounds like a movie pitch. The ingredients are already in the public record.
The legacy economy is where the country actually runs. It’s where the power, water, food, medicine, and money come from. It is also full of known holes, patched on a monthly schedule, and defended by people who are already working nights. Attackers who move in days, soon hours, will win that race every time.
We don’t get to skip this because change control is uncomfortable. Either the defense scales with the offense, or the legacy economy ends up belonging to the attackers.
05 · The path
How it succeeds
If the immune system rejects defensive coscaling because every incentive points toward stability, then asking nicely won’t fix it. We’ve had twenty years of frameworks, guidance documents, and awareness months. The incentives have to change, and I think that takes a law with teeth.
We’ve done this before. After Enron and WorldCom, Congress didn’t publish best practices for honest accounting. It passed Sarbanes-Oxley, which made CEOs and CFOs personally certify their companies’ financial statements and exposed them to criminal penalties for signing numbers they knew were false. Corporate finance got serious in a hurry.
Equifax is a useful contrast. The fix for the flaw that exposed 147 million people had been out for two months. The CEO retired. The criminal charges that followed went to the Chinese military hackers who broke in and to two employees who sold stock before the breach went public. Nobody was charged for leaving the door open.
Security needs its Sarbanes-Oxley moment. Here’s how I’d build it.
-
The law
Congress makes ignoring a known vulnerability a crime.
Boards and senior executives become criminally liable when a breach runs through a known vulnerability they were warned about and chose not to fix or plan around. Getting hacked isn’t the crime. Ignoring the warning is.
-
Always on
The government scans every public IP address in the country.
A federal system continuously checks every internet-facing address in the U.S. for known vulnerabilities and catalogs what it finds. A small version of this already exists: CISA scans internet-facing systems for free, for organizations that sign up. The change is that it stops being optional. Enforcement belongs with the FBI, not the NSA. The NSA’s job is foreign intelligence, and pointing it at American companies would kill the bill on day one.
-
Day 90
Anything unpatched after 90 days gets flagged.
If a vulnerability is still exposed 90 days after the fix was published, it goes on the list. The number isn’t arbitrary. It’s the same deadline Google’s Project Zero gives software makers before it goes public with a bug. Vulnerabilities that attackers are already exploiting (CISA keeps a list) jump the line on a shorter clock.
-
The knock
An FBI agent calls the person the IRS already knows.
Every business in America has a “responsible party” on file with the IRS: the person who controls the business and answers to the IRS for it. That’s who gets the call, whether it’s the CEO or the CFO. It ends the “we didn’t know who to contact” problem, and it puts the notice on the desk of someone who can’t hand it off to IT and forget about it.
-
Day 120
30 days to fix it or commit to a date.
The company either cleans it up or files a remediation plan with a named owner and a committed completion date. Systems that are genuinely hard to patch, like a hospital’s imaging equipment or a plant’s control systems, get a plan. They don’t get a pass.
-
Missed date
Then the charges come.
If the company ignores the notice, or blows through its own committed date, prosecutors can bring charges against the executives and board members who let it happen.
Good cop, bad cop
Critical infrastructure goes first: energy, water, health care, finance, communications, transportation, and the other sectors InfraGard is already organized around. Those are the places where the Die Hard scenario stops being a movie.
InfraGard is the good cop. It’s the FBI’s long-running partnership with the private sector, and its members already know the executives, plant managers, and IT directors in their region. Before anyone gets a formal notice, InfraGard should be in the room explaining the law, showing companies what the scanner sees, and helping them get ahead of it. The first knock should be friendly. The second one shouldn’t be.
Guardrails, because this could be done badly
- Scanners are sometimes wrong. Every notice needs a person to verify it, and companies need a fast way to say “that’s not ours” or “that’s already handled.”
- The scan data is a map of every unlocked door in the country. It has to be protected like one.
- Companies that come forward, file a plan, and hit their dates get safe harbor. The stick is for the people who ignore the warning.
That last one is the only carrot I think matters. I’d like to believe tax credits and best-practice guides would get us there. They haven’t so far. In circumstances this extreme, I think only sticks will move the legacy economy fast enough.
What the law actually changes
The law does more than scare boards. It changes the math for the guy at 2 a.m.
Today, the risk of a patch breaking production belongs to him. The risk of not patching belongs to nobody. Once a board member can be charged for ignoring a known vulnerability, that second risk has an owner, and it’s the most powerful person in the building. The COO who allowed one patch window a month suddenly wants to know why there isn’t one every night.
And the only way to patch every night, across thousands of systems, safely, with testing and rollback and a record of every change, is the swarm. That’s how defensive coscaling gets past the immune system. The business finally has a reason to want it.
Defensive coscaling won’t work in the legacy economy the way that economy is wired today.
It has to work anyway. So change the wiring.
Sources
- Anthropic, “Disrupting the first reported AI-orchestrated cyber espionage campaign” (November 2025).
- Mandiant / Google Cloud, “How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends.”
- DARPA, “AI Cyber Challenge marks pivotal inflection point for cyber defense” (August 2025).
- Microsoft, “Helping our customers through the CrowdStrike outage” (July 2024).
- Federal Trade Commission, Equifax Data Breach Settlement.
- U.S. Department of Health and Human Services, Change Healthcare Cybersecurity Incident FAQ.
- CISA, Cyber Hygiene Services and the Known Exploited Vulnerabilities Catalog.
- Google Project Zero, Vulnerability Disclosure FAQ.
- IRS, Responsible Parties and Nominees.
- InfraGard National Members Alliance.
- Salim Ismail on the corporate immune system: Exponential Organizations and the Moonshots podcast with Peter Diamandis.