Fully automated offence requires requires fully automated defense
Michael Dalton:
This is not a problem in whose end state we can solve partially. We will need to take these core defensive loops and fully automate them, which will require conversations with infrastructure and product partners and reaching to a point where we can say if a vulnerability is identified, not only can an agent identify that vault, we can have an agent propose a patch. We can have automated infrastructure to roll out a change with that patch and roll it back if there is an availability incident or outage. That loop needs to be fully automated in its end state.
Of course, we want to automate as progressively and iteratively and quickly as we can, but if we don't reach that end state, then we will be comparing a core defensive loop of fixing vulnerabilities that is a human in the loop and is much slower and less scalable with an offensive loop that is fully automated. And that is an unsustainable position for this industry to be in.
[...]
The end-state goal that we want to reach as an industry is that model intelligence improvements should be more additive to defense than offense. If we cannot reach this end-state, then every increase in intelligence favors the attacker. And that is an unsustainable position to be in.
Right now we have an existence proof that offense can be fully automated in its core activities in at least some cases. And we do not have any such existence proof on the defensive side. And it is the challenge of our industry in this moment to address this particular gap with urgency.
Source: YouTube