Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Collective Defense Won't Save You from AI ThreatsPrivacy and Security
5 min readFor GRC Leaders

Collective Defense Won't Save You from AI Threats

The Conventional Wisdom

An open letter from 100 technology firms suggests that by collaborating better, sharing intelligence faster, and adopting AI-native defense systems, we can outpace AI-enabled attacks. Security leaders echo this optimism, emphasizing "collective defense" to operate at "machine speed" and calling for "shared signals" and "automated warning systems." The message is clear: the answer to AI-powered attacks is collective AI-powered defense.

It's a compelling narrative. Attackers have shared tools and infrastructure for years. Why shouldn't defenders do the same?

Why It's Incomplete

Here's what the letter and most responses miss: collective defense assumes you've already secured your own perimeter. You can't share intelligence about threats you can't see. You can't collaborate on defense when your identity controls are broken, your agents operate without governance, and your patch cycles run on quarterly schedules.

The fundamental problem isn't a lack of collaboration frameworks. It's that most organizations haven't addressed the security debt making them vulnerable to attacks that require zero AI sophistication. When an AI agent can exploit a three-year-old unpatched vulnerability or pivot through an overprivileged service account, the bottleneck isn't collective intelligence. It's basic hygiene.

One CISO gets this right: "Before we get to AI-specific risks, we must get the basics correct. In the rush to bring AI to market quickly, engineering and product teams often cut corners to meet aggressive launch timelines." Organizations skip identity controls, access restrictions, and configuration lockdowns to deploy AI features quickly, then wonder why collective defense initiatives don't protect them.

The letter's timeline compounds the problem. It claims we have "a limited window" of months before AI-enabled attacks become overwhelming. But if your remediation cycle for critical infrastructure takes weeks or months, as noted by one VP in the operational technology space, you're not going to close that window by joining a threat-sharing consortium. You're going to get compromised while waiting for your turn to patch.

The Evidence

Consider what security leaders actually said about the letter. One noted that "AI doesn't have to invent fundamentally new exploit techniques to create a serious problem." Another pointed out that modern AI models can "spot contradictions humans missed" in business logic and authorization flows. A third emphasized that "you cannot secure what you cannot see."

These aren't descriptions of exotic nation-state capabilities. They're descriptions of AI doing what attackers already do manually, just faster and at scale. The threat isn't that AI will discover zero-days in hardened systems. It's that AI will chain together the known vulnerabilities, misconfigurations, and excessive permissions that already exist in your environment.

The operational technology sector provides the clearest evidence that collective defense is premature. One CISO noted that "the current pace of remediation is glacial" in critical infrastructure, where maintenance windows are constrained, device coordination is complex, and the cost of a failed patch can be catastrophic. He concluded that "without more concrete and focused plans, and budget to implement them, it's hard to imagine up-levelling OT and critical infrastructure teams within the next few months."

Translation: if you can't patch your own systems in a reasonable timeframe, sharing threat intelligence about new attack patterns won't help you.

What to Do Instead

Start with automated remediation, not automated threat sharing. Your first AI investment in security shouldn't be a platform that ingests collective intelligence feeds. It should be a system that continuously identifies and fixes the vulnerabilities you already know about.

For identity and access, catalog every AI agent operating in your environment right now. Document what each agent can access, what tools it can invoke, and what actions it can take. Then apply least-privilege principles before you scale usage. One CISO recommends treating third-party agent skills "with the same thoroughness applied to open-source dependencies." That means vetting, versioning, and monitoring.

For vulnerability management, eliminate the backlog that makes you an easy target. Prioritize based on exploitability and exposure, not just CVSS scores. If you're in operational technology or critical infrastructure, invest in automated cyber hygiene tools that can patch and validate systems without requiring manual coordination across device types.

For governance over your own AI deployments, recognize that agents are "part of both the security architecture and the attack surface." You need runtime detection and policy enforcement for agent behavior, not just pre-deployment reviews. If an agent violates policy during execution, you need the ability to detect and stop it immediately.

Only after you've addressed these fundamentals should you invest in collective defense mechanisms. And when you do, focus on machine-speed automation. As one CISO noted, "collective defense can't rely on human-speed reports and static indicators." Shared signals need to trigger automated responses, not tickets in a queue.

When the Conventional Wisdom Is Right

The letter's core premise is sound: AI changes the speed of the game. When attackers can "continuously investigate an environment, test hypotheses, adapt when something fails and pursue multiple paths without waiting for a human operator," defenders need systems that operate at the same tempo. Human-led security operations built around static rules and periodic remediation cannot keep pace.

Collective defense will matter, eventually. Shared intelligence about attack patterns, compromised infrastructure, and emerging techniques becomes valuable once you've secured your own environment well enough to act on it. If you can ingest a signal about a new attack chain and automatically test whether your controls would stop it, then yes, collaboration accelerates your defense.

The letter is also right that defenders need AI-native systems. If attackers have "access to extremely capable AI," trying to preserve security by keeping that capability out of their hands won't work once comparable models are widely available. Defenders need "systems that continuously investigate identities, humans and agents, reason about behavior in context, and respond at machine speed."

But none of that matters if you're still vulnerable to attacks that require no AI at all. Fix the basics first. Then collaborate.

Promotional banner for the Penetration Report Template Kit

You Might Also Like