Connect with us

News

How AI guardrails are impeding the work of offensive cybersecurity researchers

info

Published

on

Claude mythos logo.jpg

For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. 

In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

NPFL Transfer: Kano Pillars Complete Signing of Midfielder Abdulraheem Shola from Kwara United

info

Published

on

By

WhatsApp Image 2026 07 24 at 8.46.54 AM.jpeg

Nigeria Premier Football League (NPFL) side Kano Pillars FC have strengthened their squad ahead of the 2026/27 season with the signing of attacking midfielder Abdulraheem Shola from Kwara United on a two-year contract.

Sports247 reports that the Sai Masu Gida officially unveiled the talented playmaker, adding another creative option to their midfield as the club intensifies preparations for the new campaign under Technical Adviser Daniel Ogunmodede.

READ ALSO: Kano Pillars, Plateau United Lead Confirmed Teams for 2026 Gusau/Ahlan Cup Pre-Season Tournament

Expressing his excitement after completing the move, Shola took to his social media platforms to share an emotional message, describing the transfer as the beginning of a new chapter in his career.

“A new chapter begins today. I leave the past behind and step forward with faith, courage, and determination. I will keep working, keep believing, and keep growing. This dream is worth fighting for, and I know my best is yet to come.

“This is my new beginning. Let’s see at the top. SAI MASU GIDA.”

Shola arrives in Kano with valuable NPFL experience, having previously featured for Wikki Tourists, Niger Tornadoes, and Kwara United. His consistent performances across the domestic league have established him as one of the country’s dependable attacking midfielders.

One of the highlights of his career came during the 2025/26 season, when he played a pivotal role in helping Kwara United secure a historic President Federation Cup triumph. His creativity, work rate, and influence in midfield were instrumental in the club’s memorable cup-winning campaign, further enhancing his reputation in Nigerian football.

Kano Pillars will be hoping Shola’s experience, technical quality, and attacking instincts add a new dimension to their squad as they target a successful league campaign and challenge for major honours.

For the midfielder, the move represents an opportunity to embrace a fresh challenge at one of Nigeria’s most successful clubs while continuing his development and contributing to Pillars’ ambitions.

With preparations for the new season gathering momentum, Kano Pillars supporters will be eager to see their latest signing make an immediate impact in the famous Sai Masu Gida colours.

Continue Reading

Business

Nigeria Steps Up Smart Meter Deployment with Installer Training Programme

info

Published

on

By

‎Nigeria’s efforts to scale up delivery of seven million smart electricity meters and close its metering gap received a boost on Thursday, with the flag-off in Abuja of POWER FORCE, a training programme that will produce 5,000-meter installers across the country.

‎The Power Force programme is being implemented under the Presidential Metering Initiative (PMI), launched by President Bola Ahmed Tinubu in 2023. The flag-off ceremony, held at the headquarters of the National Power Training Institute of Nigeria (NAPTIN), also featured the unveiling of the first batch of selected applicants, who will undergo a three-week intensive practical and classroom training in Abuja.

‎Close to 220,000 submissions were received from interested young Nigerians across the country during the application period.

‎Dignitaries in attendance at the event included the Minister of Power, Joseph Tegbe; the Minister of Youth Development, Ayo Olawande; the Executive Secretary of the Presidential Metering Initiative and Special Adviser to the President on Oil and Gas, Olu Arowolo Verheijen; and the Project Director of the PMI, Obafemi Solebo. The Governor of Kwara State and Chairman of the Nigeria Governors’ Forum (NGF), who also chairs the PMI Board, His Excellency Abdulrahman Abdulrazaq, was represented at the event by Mr Edmund Obiora Nnaji, Executive Director, Finance and Administration at the NGF.

‎Other attendees included the Director-General of the Bureau of Public Enterprises (BPE), Mr Ayo Gbeleyi; the Managing Director of NAPTIN, Mr Ahmed Bolaji Nagode; and the Managing Director of the Nigerian Electricity Management Services Agency (NEMSA), Mr Adesayo Olusegun Michael.

‎In his address, Governor Abdulrazaq said, “PMI is not just about fixing the finances of the power sector through metering. It is also about impacting the lives of young Nigerians, through training and skills development.” He called on fellow governors to explore “supporting this Power Force initiative with a view to expanding the pool beyond the initial five thousand trainees being targeted.”

‎Power Minister Tegbe said, “Behind every successful metering programme must stand thousands of competent, certified and dedicated technicians. The 5,000 young Nigerians being trained under this initiative will become the backbone of Nigeria’s smart metering workforce.”

‎The Power Force initiative, he added, “demonstrates that our electricity reforms are not merely about equipment and technology; they are equally about creating opportunities, building human capital and securing livelihoods.”

‎He commended the Association of Meter Manufacturers of Nigeria (AMMON) for withdrawing a court action it had instituted against the meter deployment programme, noting that “that singular decision has removed a significant obstacle to the accelerated deployment of electricity meters across the country.”

‎Youth Minister Olawande said Power Force is directly supporting his Ministry’s “One Youth, Two Skills” initiative. “This is not just the launch of a training programme; it is about creating jobs and opportunities for Nigerian youths to contribute to national development,” he said.

‎He added, “President Tinubu’s administration has demonstrated that Nigeria’s federal ministries, departments and agencies can have the force of collaboration in making sure the dividends of democracy get to everybody in the country.”

‎Special Adviser Verheijen described the PMI as the largest metering programme in the history of Nigeria, established under the leadership of President Bola Ahmed Tinubu “to solve one of the biggest barriers to a reliable electricity sector: ensuring that every Nigerian pays only for the electricity they actually use.”

‎She added, “One young installer cannot transform Nigeria. But five thousand can inspire fifty thousand. And fifty thousand can inspire millions more. That is how movements begin. One opportunity. One person. One act of service at a time.”

‎Following the Abuja launch, the Power Force training will expand to various centres across Nigeria’s six geopolitical zones. Upon completion, trainees will receive formal certification by NEMSA as qualified meter installers who have met national and international competence and safety standards.

The post Nigeria Steps Up Smart Meter Deployment with Installer Training Programme appeared first on Business Today NG.

Continue Reading

Trending