Microsoft said the spread of AI has broken down the scarcity of cyberattack capability and that security responses should shift from after-the-fact patching to developing safer software.
SiliconANGLE reported on Aug. 6 that David Weston (데이비드 웨스턴), Microsoft's vice president for AI security, urged the shift in a keynote speech at Black Hat USA.
Weston said existing security systems were built on the assumption that strong security perimeters would be maintained, but the economics of scarcity no longer holds as AI spreads attack capability more widely.
He said there are limits to simply speeding up patches. Even fast patches are still a post-incident response, leaving openings for attackers to exploit. Attackers need to succeed only once, while defenders are structurally disadvantaged because they must also cope with constraints such as regulations and internal procedures, he said.
Microsoft has therefore set as a priority an approach to make software safer from the start. Examples include memory-safe languages such as Rust and formal verification. Weston said AI is boosting engineer productivity in particular, and that this productivity should be used to build safer software architectures.