I remember a board meeting for one of my early-stage investments, a promising SaaS company in the logistics space. The mood was grim. The CEO, usually energetic and optimistic, looked like he hadn't slept in a week. They’d been hit by a phishing attack that was terrifyingly sophisticated. This wasn't your typical fake login page with bad grammar and a suspicious URL. The email, sent to their CFO, referenced internal project codenames from a confidential M&A discussion that had happened only days before. It looked like an inside job, a disgruntled employee with high-level access. The panic in the room was palpable.
But it wasn't an insider. It was an AI-powered spear-phishing campaign that had waltzed right past their top-tier, very expensive security stack. The AI had likely scraped public data, correlated it with social media activity, and perhaps even found a subtle vulnerability in a third-party vendor's system to get those project names. It built a perfect, trusted persona and used it to strike at the most vulnerable point. That was my wake-up-call. The game had changed, permanently. The old rules were dead.
If you're running a company today, you're probably using security tools based on rules and signatures. They’re designed to look for threats we already know, the digital fingerprints of past attacks. But the new threats are generated by AI, constantly morphing, learning, and adapting in real-time. Your old playbook is not just outdated; it's useless. It’s like bringing a knife to a gunfight, and the other guy has a self-guiding missile.
I’ve seen this from every angle. As a founder who built and sold two tech companies, RemoteTeam and MovieLaLa, I lived the daily, gut-wrenching fear of a breach. As an angel investor in over 200 companies—including foundational AI players like Anthropic, OpenAI, and Scale AI—I see the security arms race from the front lines. I’m not a security vendor trying to sell you a shiny new box. I’m a builder and an investor who has to protect his portfolio, and I’m sharing what I’ve learned from the trenches.
So let's be clear. Stop buying AI security tools that just slap "AI" on the box. Most of them are selling you a false sense of security. I'm going to show you the dark side of this market and give you a framework for finding the few tools that actually work.
The New Threat: Adversarial AI is Here
Forget the complex academic definitions. Adversarial AI is about teaching machines to lie and deceive. It's AI built specifically to trick other AIs. Think of it as digital camouflage for malware or attacks that actively learn your defenses to find a way around them. It’s not about brute force; it’s about malicious creativity at machine scale.
We've already talked about data poisoning, the slow, insidious corruption of a model's training data. But there are other, more direct attacks happening every day. Consider model evasion. This is where an AI attacker probes your security model, learning its boundaries and blind spots. It's like a burglar testing every window and door, but on a digital, automated level. The attacking AI makes thousands of tiny modifications to a piece of malware until it creates a version that your security AI simply doesn't recognize. It slips past, completely invisible, because the attacker found the perfect optical illusion to fool the machine.
Then there's model extraction. An attacker can essentially steal your proprietary model by sending it a large number of queries and observing the outputs. Over time, they can reconstruct a functionally identical version of your model. This means your multi-million dollar R&D investment in a custom security AI can be stolen and used against you or your customers. They don't need to breach your servers; they just need to use your public-facing API.
Why does this matter so much? Your Security Operations Center (SOC) team is already drowning. They're looking for needles in a haystack. Adversarial attacks are like haystacks that generate their own needles, on demand, faster than any human team could ever hope to keep up with. The sheer volume, and the novel, unpredictable nature of these attacks, is overwhelming.
The "AI-Powered" Lie: Deconstructing the Hype
I've sat through hundreds of pitches from security startups. The moment I hear the phrase "AI-powered," my guard goes way up. For probably 90% of the vendors I see, it's just a marketing wrapper on a simple machine learning model that’s been around for a decade. It's not true, adaptive AI. It's a buzzword used to justify a higher price tag.
Then you have the "black box" problem. The vendor will tell you their AI is a proprietary "secret sauce." That is a massive red flag. If they can't explain how their model makes decisions, how it's trained, and most importantly, how it's hardened to resist adversarial attacks, you're buying a black box that will inevitably fail. You need explainability, not just a promise. You need to be able to ask the machine why it flagged a certain activity as malicious, and get a clear, human-understandable answer.
I have a story about this. I was meeting with the founder of a hot "AI security" startup a couple of years ago. They had a great sales deck and serious buzz. I asked him a simple question: "How do you protect your own models from data poisoning?" He just stared at me with a blank expression. He didn't even really know what it was. He started talking about their anomaly detection algorithms, but he was missing the point entirely. His model was a sitting duck. I passed on the investment, obviously. About a year later, that company was acquired for pennies on the dollar after a major, public breach that their tool completely failed to stop. They were selling a promise, not a product.
The Investor's Playbook: How to Spot Real AI Security
So how do you find the real deal? After looking at so many companies, I’ve developed a playbook. It’s not about the marketing, it’s about the fundamentals. This is the framework I use when I'm considering an investment in this space.
First, focus on the data. This is the single most important factor. I ask teams where their training data comes from. How massive and diverse is the dataset? How is it cleaned, labeled, and—crucially—protected? I want to see a clear data lineage and a robust strategy for continuous, real-world data ingestion. Without world-class data, the best algorithm in the world is garbage. A model trained only on lab-generated data will fail the instant it encounters the chaos of the real world. I look for companies that have unique access to data, perhaps from a consortium of partners or from a large existing user base.
Second, the team is everything. I don't invest in slick sales teams; I invest in deeply technical founders with serious expertise in both machine learning and security. Look for teams that publish research, contribute to open-source security projects, and have a background in offensive AI, not just defensive. You need the poachers-turned-gamekeepers. They know how the attackers think because they’ve been there. They build their systems with an adversarial mindset from day one.
Finally, I look for three pillars in any tool that claims to be a real AI security solution:
Adaptive Learning: The tool absolutely must learn from your specific environment in real-time. It's not enough to use a generic, pre-trained model. It needs to build a dynamic baseline of what's 'normal' for your network, your users, and your applications. The real value is in flagging the subtle deviations from that baseline. The system should get smarter and more tailored to you every single day.
Adversarial Resistance: You have to ask the hard questions directly. "How do you defend against model inversion, data poisoning, and evasion attacks?" Don't accept a hand-wavy answer. They should have a clear, technical response. The best companies are using techniques like generative adversarial networks (GANs) to constantly have their AIs attack each other, making them stronger and more resilient every single day. They are, in effect, running a continuous, automated red team against their own systems.
Explainability & Control: The tool cannot be a black box. It must provide clear, understandable reasons for its alerts. It should augment your human experts, not try to replace them. Your team needs the ability to tune, query, and even override its decisions. It's a partnership between human and machine. The AI should provide the signal, but the human expert should always have the final say.
Your New Mandate
If you're a founder, a CEO, or a board member, the mandate is clear. Don't renew that contract with the security vendor who can't answer these questions. Start a pilot with a company that can. The cost of doing nothing is a breach you might not recover from. The reputational damage alone can be a company-killer.
The biggest risk in security today isn't the AI attackers. It's your own complacency. It's believing that the old tools and the old ways of thinking will still work. It's buying into the marketing hype from vendors who are more focused on their sales funnel than on your security.
The dark side of AI security isn't just the new wave of threats—it's the vendors selling you a false sense of hope. I’ve made my biggest returns as an investor by betting on foundational technological shifts. This is one of them. The future of security isn't just 'AI-powered'; it's AI-native. Your job is to find the builders who truly understand that difference. It's the only way to survive what's coming.
Frequently Asked Questions
How has this view evolved over time?
My thinking on most topics has changed significantly over the years. Early in my career, I held many conventional views that experience proved wrong. I try to update my beliefs when the evidence changes.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.
Do all experts agree with this view?
No, and that's fine. The best ideas in business are often contrarian. I share my perspective based on my experience and data, but I encourage you to seek out opposing viewpoints and form your own conclusions.
How can I apply this thinking to my own situation?
Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.