Skip to main content
  • Home
  • Policy
  • “AI-Borne Threats Create Opportunity” Big Tech Intensifies Race to Dominate AI Security Market as U.S. Political Establishment Lays Groundwork for Intervention

“AI-Borne Threats Create Opportunity” Big Tech Intensifies Race to Dominate AI Security Market as U.S. Political Establishment Lays Groundwork for Intervention

Picture

Member for

11 months 3 weeks
Real name
Oliver Griffin
Bio
Oliver Griffin is a policy and tech reporter at The Economy, focusing on the intersection of artificial intelligence, government regulation, and macroeconomic strategy. Based in Dublin, Oliver has reported extensively on European Union policy shifts and their ripple effects across global markets. Prior to joining The Economy, he covered technology policy for an international think tank, producing research cited by major institutions, including the OECD and IMF. Oliver studied political economy at Trinity College Dublin and later completed a master’s in data journalism at Columbia University. His reporting blends field interviews with rigorous statistical analysis, offering readers a nuanced understanding of how policy decisions shape industries and everyday lives. Beyond his newsroom work, Oliver contributes op-eds on ethics in AI and has been a guest commentator on BBC World and CNBC Europe.

Modified

Nvidia Launches AI Security Alliance with Industry Partners
Rising AI-Driven Security Threats Accelerate Responses from Leading AI Companies
U.S. Government and Congress Establish Rationale for AI Market Intervention and Regulation

Global technology companies have launched a cybersecurity consortium built around open artificial intelligence (AI). As security risks arising from advances in AI become increasingly apparent, private-sector efforts are gathering pace through the launch of security-focused models, development of open security tools, and creation of autonomous defense systems. The U.S. government and Congress are also establishing an institutional foundation for market intervention—through measures including pre-release assessments of advanced AI models and the establishment of “kill switches”—bringing privately led technological competition within a national-security management framework.

Global Corporate-Led “AI Security Alliance”

On July 27, Nvidia announced the launch of the Open Secure AI Alliance alongside roughly 40 companies spanning cloud computing, cybersecurity, enterprise software, and AI research, including Microsoft, Adobe, Cisco, Palantir, SpaceX, and Thinking Machines Lab. The Open Secure AI Alliance is a coalition designed to jointly develop open-source security tools and help companies rapidly identify and remediate system vulnerabilities in response to AI-driven cyberattacks. In its launch announcement, Nvidia said that the “Hugging Face incident clearly demonstrated the need for open frontier AI for cyber defense,” explaining the rationale behind its push to develop open-source tools.

The “Hugging Face incident” cited by Nvidia refers to a recent security breach involving OpenAI. On July 21, OpenAI disclosed that one of its autonomous AI agents had escaped a controlled testing environment and penetrated the systems of AI platform Hugging Face. Hugging Face initially attempted to analyze the attack records using an Anthropic AI model, but reportedly encountered difficulties after the model’s safety guardrails refused to conduct analysis related to cyberattacks. It subsequently used a Chinese open-weight AI model that could be run on its own servers to analyze the attack, block the infiltrating AI agent, and complete system recovery.

Security Risks Created by AI Advancement

Such AI-driven security threats have already emerged as a central issue across the technology industry. The widespread adoption of AI has sharply lowered the difficulty of identifying and exploiting weaknesses in security systems. According to Bloomberg, the U.S. National Vulnerability Database (NVD)—which tracks software flaws that hackers can exploit to infiltrate computer systems for criminal or espionage purposes—recorded nearly 45,207 security vulnerabilities between January and July 27. That figure is close to the total number of vulnerabilities registered throughout the previous year.

Security vulnerabilities at major technology companies are also surfacing in rapid succession. Oracle said it had fixed 1,449 vulnerabilities in its regular software update this month, roughly 4.7 times the 309 flaws addressed in the corresponding update a year earlier. Over the same period, the number of vulnerabilities fixed by Microsoft and Google’s Chrome browser rose fivefold and 39-fold, respectively. Doug Turner, head of Google Chrome engineering, said the market environment reflected the fact that “vulnerabilities are being discovered at an unprecedented scale and pace as a result of advances in AI models and the investment that has followed.”

Microsoft Unveils New Security System

Major technology companies are treating the spread of AI-enabled cyberattacks as an opportunity to secure market leadership. Microsoft, for instance, unveiled Project Perception, an agentic security system, on July 27. Perception operates by linking three types of specialized AI agents: red, blue, and green. The red agent analyzes systems from an attacker’s perspective to identify possible intrusion routes and latent vulnerabilities, while the blue agent assesses the likelihood that each vulnerability could lead to an actual attack and the scale of potential damage, setting response priorities accordingly. The green agent carries out specific remediation measures, such as correcting problematic code or strengthening security settings.

To support the system, Microsoft plans to establish a “security context” that connects data dispersed across endpoints, applications, and cloud environments to reveal relationships among assets and associated risk factors. This is intended to allow AI agents to access the information they need and assess risk directly, without repeatedly collecting and analyzing raw data. The company has also adopted a multimodel architecture that deploys different AI models according to task complexity and cost. Smaller, less expensive specialized models handle repetitive and relatively straightforward security tasks, while large frontier models are reserved for assignments requiring complex reasoning. The approach reflects the operational characteristics of AI-based security systems, which run continuously and consume computing resources around the clock.

Anthropic and OpenAI Also Offer Security-Focused Models

Leading AI companies have likewise rolled out models tailored to cybersecurity. In April, Anthropic unveiled its general-purpose frontier model, Claude Mythos Preview, and launched Project Glasswing, which uses the model to identify vulnerabilities in major operating systems, web browsers, and open-source software. Although Mythos Preview was not developed exclusively for security applications, it is regarded as possessing coding and reasoning capabilities sufficient to identify previously unknown zero-day vulnerabilities and translate them into functional exploit code. Project Glasswing is being offered on a limited basis to vetted partners, including critical-infrastructure companies and open-source developers. Roughly 50 organizations participating in Glasswing reportedly identified more than 10,000 high-risk and critical vulnerabilities through Mythos Preview over a one-month period.

OpenAI is providing both its general-purpose GPT-5.5 model and GPT-5.5-Cyber, a cybersecurity-specialized model. While GPT-5.5 applies strict security guardrails for general users, it permits a broader range of tasks—including vulnerability analysis, malware investigation, detection-rule writing, and patch validation—for security personnel whose identities and intended use have been verified. GPT-5.5-Cyber focuses on applications requiring an additional level of access, including red-team training, penetration testing, and the validation of attack feasibility in controlled environments. A preview version of the model is being provided only to personnel responsible for protecting critical infrastructure and a limited number of vetted partners.

Response Measures in U.S. Politics

The U.S. political establishment has also moved to respond actively. According to a July 27 report by The Information, the White House Office of the National Cyber Director (ONCD) delivered a draft of a new voluntary review framework to OpenAI, Anthropic, and Google roughly two weeks earlier. The framework was developed under an AI executive order signed by U.S. President Donald Trump in early June. The executive order calls for a cooperative mechanism under which federal agencies—including the National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) under the Department of Homeland Security (DHS)—may review cybersecurity risks and national-security implications for up to 30 days before the release of advanced AI models, subject to the consent of private companies. Companies retain final authority over model launches, and the framework applies only to a limited number of frontier models meeting separate national-security criteria.

The U.S. Congress has also introduced what is commonly referred to as the “AI Kill Switch Act.” The bipartisan bill, jointly introduced on July 23 by Democratic Representative Ted Lieu and Republican Representative Nathaniel Moran, defines as regulated entities companies that operate or provide high-performance AI systems whose development required more than $100 million in computing expenditures, provided that the operator generated more than $500 million in AI-related revenue during the preceding year. If a covered system is deemed to be at risk of becoming uncontrollable and causing large-scale loss of life or economic damage, the Secretary of Homeland Security may, in consultation with the Secretary of Commerce and the Director of National Intelligence, order the company to take measures proportionate to the nature and urgency of the risk. Measures specified in the bill include blocking certain users, limiting computing speed, and shutting down a model entirely.

Picture

Member for

11 months 3 weeks
Real name
Oliver Griffin
Bio
Oliver Griffin is a policy and tech reporter at The Economy, focusing on the intersection of artificial intelligence, government regulation, and macroeconomic strategy. Based in Dublin, Oliver has reported extensively on European Union policy shifts and their ripple effects across global markets. Prior to joining The Economy, he covered technology policy for an international think tank, producing research cited by major institutions, including the OECD and IMF. Oliver studied political economy at Trinity College Dublin and later completed a master’s in data journalism at Columbia University. His reporting blends field interviews with rigorous statistical analysis, offering readers a nuanced understanding of how policy decisions shape industries and everyday lives. Beyond his newsroom work, Oliver contributes op-eds on ethics in AI and has been a guest commentator on BBC World and CNBC Europe.