AI Guardrails Slow Cybersecurity Research as Experts Warn of Unintended Consequences

Share

Artificial intelligence safety measures designed to prevent cybercrime are increasingly creating obstacles for the very experts tasked with defending digital systems, according to leading offensive cybersecurity researchers. While AI companies such as OpenAI and Anthropic have introduced strict guardrails and verification programs to stop malicious actors from abusing advanced models, many security professionals argue that these restrictions are making it harder to identify and fix vulnerabilities before cybercriminals can exploit them. The debate has intensified following recent U.S. export restrictions on Anthropic’s advanced AI models, which were partly linked to concerns over bypassing the systems’ built-in safety protections.

Several cybersecurity experts believe the current approach treats legitimate researchers the same as potential attackers. Veteran security researcher Mark Dowd criticized major AI companies for making what he described as arbitrary decisions about what users should be allowed to do. Others echoed his concerns, explaining that testing whether software flaws can actually be exploited is a critical part of confirming security weaknesses and ensuring they are patched. Without the ability to perform these tasks, they argue, defenders lose valuable tools needed to stay ahead of increasingly sophisticated cyber threats.

Chris Anley, Chief Scientist at NCC Group, compared AI models to a hammer—a tool that can be used for both construction and destruction. According to him, the same prompts that help security teams discover and fix vulnerabilities can also be misused by attackers, making it difficult to separate defensive and offensive use cases. When AI models refuse to assist because of strict safeguards, researchers often turn to open-source alternatives that offer fewer restrictions. Others, including Crowdfense Chief Technology Officer Paolo Stagno, said their teams already rely on locally hosted open-source AI models to avoid exposing sensitive vulnerability data while maintaining greater flexibility during research.

Not every researcher sees the restrictions as a major setback. Security researcher Giuseppe Cali said he primarily uses AI to speed up reverse engineering and code analysis rather than discovering software flaws or creating exploits. He believes the core work of identifying vulnerabilities still depends on human expertise and creativity. However, researchers from other organizations say the limitations are severe enough to make some commercial AI systems almost unusable for security testing, forcing them to abandon leading AI platforms altogether.

Industry leaders warn that if trusted researchers continue facing these obstacles, innovation in cybersecurity could shift toward unrestricted foreign AI models instead of regulated Western platforms. Chris Thompson, CEO of RemoteThreat and founder of Offensive AI Con, argued that responsible researchers are spending more time negotiating with AI guardrails than investigating security threats. He called on AI companies to expand access for verified professionals while enforcing accountability for misuse, warning that excessive restrictions could weaken global cyber defenses at a time when AI-powered attacks are expected to grow rapidly in speed and scale.

source: techcrunch 

Leave a Reply

Your email address will not be published. Required fields are marked *