For months, tech giants have been implementing strict guardrails on their AI models to prevent malicious use. However, these same measures are now hindering legitimate cybersecurity researchers and defenders.
The U.S. government's recent export control restrictions on Anthropic’s AI models Mythos and Fable highlight the tension between security concerns and research freedoms. Critics argue that such gatekeeping undermines the work of those who seek to uncover vulnerabilities before they can be exploited by criminals.
Mark Dowd, a well-known security researcher, expressed discomfort with 'random large companies' making arbitrary decisions about what is safe in cybersecurity. Researchers like Chris Anley and Paolo Stagno contend that these guardrails limit their ability to use AI effectively for identifying vulnerabilities and exploits, preferring instead open-source models without restrictions.
Giuseppe Cali, who uses AI only for initial reverse engineering, maintains that the guardrails do not impede his work significantly. However, others find them too strict, leading some to resort to less controlled tools despite the risks involved.
The inconsistency in how these guardrails operate can also be frustrating. Chris Thompson notes that this unpredictability means researchers often spend more time negotiating with AI models than working on core security issues.







