I think this is a useful frame. When discussing AI and cybersecurity, we’re often faced with the question of whether AI benefits attackers more than defenders (or vice versa), but perhaps the more interesting question is who actually receives the defensive benefits. Even if defensive AI advances more quickly than offensive AI, many vulnerable targets, small organizations, open-source maintainers, local governments, and individuals, may not have access to the same tools, expertise, or response capacity. In that world, the overall security may improve while the risk is more concentrated with weaker actors. This suggests from an impact standpoint that deploying defensive capabilities may be as important as upgrading them. But a world where only a few institutions can effectively defend themselves may still be a much riskier world overall. The “dual-use gap” is an appealing notion because it shifts the attention from average outcomes to the differential distribution of protection and risk.
I think this is a useful frame. When discussing AI and cybersecurity, we’re often faced with the question of whether AI benefits attackers more than defenders (or vice versa), but perhaps the more interesting question is who actually receives the defensive benefits.
Even if defensive AI advances more quickly than offensive AI, many vulnerable targets, small organizations, open-source maintainers, local governments, and individuals, may not have access to the same tools, expertise, or response capacity. In that world, the overall security may improve while the risk is more concentrated with weaker actors.
This suggests from an impact standpoint that deploying defensive capabilities may be as important as upgrading them. But a world where only a few institutions can effectively defend themselves may still be a much riskier world overall.
The “dual-use gap” is an appealing notion because it shifts the attention from average outcomes to the differential distribution of protection and risk.