Offensive cybersecurity experts report that AI barriers prevent them from doing their jobs
In one of his latest publications, TechCrunch addresses an interesting and necessary debate. AI laboratories have designed verification programs and strict security barriers to prevent their models from being used for malicious purposes. However, these same restrictions are beginning to become an obstacle for cybersecurity professionals themselvesboth defenders and researchers specialized in finding vulnerabilities before attackers.
The debate has been revived after the controversy surrounding Anthropic’s Mythos and Fable models. In June, the US government imposed export restrictions on both systems after a report warned that it was possible to bypass barriers designed to prevent computer attacks. The restrictions have already been lifted. For example, Fable 5 regained general access on July 1, while Mythos 5 is only available to US organizations verified within the government review process.
Researchers report that barriers stop offensive cybersecurity
The security researcher Mark Dowdwith decades of experience locating and selling zero-day vulnerabilities to Western governments, was critical during a specialized podcast. He assured that he is not comfortable with “private companies making arbitrary decisions about what is safe in the field of security and what is not,” although he acknowledged that his perspective may be conditioned by his own work.
Chris Anley, chief scientist at NCC Group, explained that asking a model to try to exploit a flaw is a key step in confirming whether a vulnerability is real. When the security barrier directly blocks the response, the damage also falls on the defenders. According to Anley, the “fix this code” instruction works both as defense mechanism and as a roadmap to find critical flaws, so he compares these tools to a hammer: essential for building, but also, inevitably, a weapon.
Professionals turn to unrestricted models to avoid barriers
Paolo Stagno, chief technology officer at Crowdfense, agrees with Dowd and believes that AI companies “treat their customers like children who need a babysitter” with their verification programs. Your team uses open source models run locally for reverse engineering tasks, avoiding cloud models when searching for vulnerabilities or building exploits, precisely so as not to leak sensitive information or end up integrated into future training.
Now, not all researchers share the same frustration. Giuseppe Cali, specialized in finding zero-day bugs, ensures that the barriers do not affect his work because he does not use AI for offensive tasks, only for initial reverse engineering or to build support tools. “I want to continue to be the one who discovers and exploits the bug,” he said, adding that that would not change even if all restrictions were removed.
A researcher at a smartphone component company, who asked to remain anonymous, said his company is not part of Anthropic’s verification program, making its tools almost useless in detecting vulnerabilities due to the rigidity of the barriers. Chris Thompson, CEO of RemoteThreat, added that these restrictions are also inconsistent and change from day to dayforcing teams to “negotiate with the model” rather than focusing on the security analysis itself. According to Thompson, this situation pushes responsible researchers towards Chinese open source models like GLM, which can run locally without any verification or usage limitations.
Thompson called on big AI companies to, instead of tightening their restrictions further, open your responsible access programs and punish those who abuse them. In his opinion, otherwise, defense teams will lose the race to attackers who are already preparing to launch automated attacks on a scale never seen before.
