Hammock Notes · 05
Build the Monster Yourself
Hammock Notes, no. 5: offense, defense, and the weapon you keep in the house
The debate about AI in security is stuck on the wrong question. Everyone wants to know whether AI favors the attacker or the defender. It is a natural question and it has produced a lot of confident answers, and I think it misses what actually matters.
The thing that decides outcomes is not which side of the wall you are on. It is whether you lean forward or stand still. A defender who plays offense wins. An attacker who sits still loses. AI rewards the ones who move, on either side, and it punishes the one waiting for the technology to become reliable before touching it, worried about the risk of moving while the real risk walks up behind them.
That last part is where people get nervous, and they should, because it sits one careless sentence away from something dangerous. "Stop worrying about reliability and go" is exactly what every seller of every immature technology has always said. It is how people get talked into reckless things. So I want to be precise about the difference, because the difference is the whole point.
The passive party does not lose because they care about reliability. They lose because their caring is passive. They wait for a guarantee that never comes, treating reliability as a gate to pass before starting rather than a discipline to practice while moving. The offensive party cares about reliability just as much. They pursue it while running. They measure, they watch, they intervene. Reliability is something you reach offensively, not something you wait for, and the one who waits for it never gets it and loses the race as well.
So passivity is not the safe choice in security. Your adversary is already offensive and does not wait. A static defender trusting last year's threshold is a stationary target. In this domain, standing still is not safety. It is just a slower death.
Now, how do you actually be offensive as a defender, without turning into the reckless thing I just warned about? Here is where an old observation earns its place. The observation everyone makes about AI and security, so obvious it has become background noise, is that the same capability attacks and defends. A model good at finding vulnerabilities to close them is, by definition, good at finding them to exploit them. Dual use. Most people say this with a sigh, as a problem to be managed.
Turn it around and it stops being a problem and becomes a method.
Because the same capability cuts both ways, you point it inward, on purpose. You build robustness to raise the wall, and then you build a standing offensive capability whose job is to attack that wall. Continuously. From the inside. Not an annual audit by an outside firm, and not a penetration test scheduled for the third quarter. A permanent internal function whose work is to break what you built, before someone who means it does.
That internal attacker is your measuring instrument. This is the same discipline as verification, moved into security: your defense is not something you assert, it is a hypothesis your own offense is constantly trying to falsify. Robustness you never attack is wishful thinking wearing armor. You do not know your wall holds. You know nobody has pushed on it lately, which is a different and much weaker thing.
Now the hard part, and this is where the honest version of this idea separates from the naive one. When you build a standing offensive AI capability aimed at your own systems, you have built, in technical terms, exactly the weapon an attacker would want. And it now lives inside your walls, with insider access.
You have made a monster in the house.
The naive version of this chapter would stop before that sentence, sell you the red team, and move on. But the monster is real. The disgruntled employee. The compromised internal agent. The tool that leaks out. You have concentrated attack capability inside your perimeter, and pretending otherwise is how you solve one threat by building a worse one.
So the internal attacker has to be held under stricter control than anything else you run. Every guardrail this series has talked about, permission, traceability, reversibility, a human on the irreversible, applies to it in its most severe form. The offensive function must be the single most observed, most logged, most tightly scoped thing in the organization. If you cannot control it that tightly, you are not ready to have it.
And here is why I still think you should build it anyway, despite all of that. A monster in the house is one whose how, when, and where you know. You built it, you watch it, you can turn it off. The alternative is not a world with no monster. The alternative is hoping one never shows up outside, on someone else's schedule, with none of your instrumentation and all of the surprise. Knowing is a managed risk. Hoping is denial wearing the costume of caution.
That is the real choice. Not whether the capability exists. It exists, and your adversary is already building it. The choice is whether you would rather meet it for the first time as something you made and understand, or as something someone else made and aimed at you.
So the position, stated without the sigh people usually attach to dual use. The only honest defense is one that is constantly attacked from within. But whoever cultivates that offense has built a weapon in the house, and it has to be kept on a shorter leash than anything else they own. Robustness without internal offense is wishful thinking. Internal offense without the strictest possible governance is becoming your own worst attacker. Both mistakes kill you, from opposite directions, and the whole craft is refusing to make either one.
There is a version of security that is quiet, static, and feels safe right up until the morning it isn't. And there is a version that is loud, self-attacking, and never comfortable, because something inside it is always trying to prove it wrong. The second one looks more dangerous. It is the safe one.