The Anthropic Shock: Will AI Really Kill the Cybersecurity Industry as We Know It?

Anant Shrivastava (Cyfinoid Research), Saikat Datta (DeepStrat)

Nullcon Goa 2026 · Day 1

Overview

In a thought-provoking session at Nullcon, Anant Shrivastava and Saikat Datta tackled the pervasive question of whether Artificial Intelligence (AI) poses an existential threat to the cybersecurity industry. Titled "The Anthropic Shock," the talk delved beyond market speculation, which often drives initial reactions to technological shifts, to examine the ground realities of AI adoption in enterprise security. The speakers emphasized that while market sentiment can be heavily influenced by hype and FOMO (Fear Of Missing Out), the fundamental challenges and opportunities presented by AI require a nuanced, analytical approach.

Watch on YouTube

Visual summary for The Anthropic Shock: Will AI Really Kill the Cybersecurity Industry as We Know It? by Anant Shrivastava, Saikat Datta
Visual summary for The Anthropic Shock: Will AI Really Kill the Cybersecurity Industry as We Know It? by Anant Shrivastava, Saikat Datta

Key moments

  1. 0:00 Introduction: AI's impact on market and building
  2. 2:00 AI enables in-house building, reducing software feature use
  3. 4:00 Vendors use AI; FOMO drives CISO adoption
  4. 5:15 AI models: compressed human knowledge, speed advantage and adversary
  5. 6:15 Geopolitical pressures, black box problem, human in loop
  6. 7:45 Liability and indemnification for AI-generated code

The Anthropic Shock: Will AI Really Kill the Cybersecurity Industry as We Know It?

Speakers: Anant Shrivastava (Cyfinoid Research); Saikat Datta (DeepStrat)

Conference: Nullcon

YouTube: https://www.youtube.com/watch?v=kTlIx48PJFU

Overview

In a thought-provoking session at Nullcon, Anant Shrivastava and Saikat Datta tackled the pervasive question of whether Artificial Intelligence (AI) poses an existential threat to the cybersecurity industry. Titled "The Anthropic Shock," the talk delved beyond market speculation, which often drives initial reactions to technological shifts, to examine the ground realities of AI adoption in enterprise security. The speakers emphasized that while market sentiment can be heavily influenced by hype and FOMO (Fear Of Missing Out), the fundamental challenges and opportunities presented by AI require a nuanced, analytical approach.

The discussion critically assessed the evolving landscape where AI-powered tools are making code generation and feature development significantly easier, challenging traditional software development paradigms and the vendor-client relationship. Shrivastava and Datta argued that while AI promises unprecedented speed and efficiency, it also introduces complex questions around liability, the reliability of AI-generated content, and the potential for increased complacency within development and security teams. Their insights provide a crucial framework for CISOs and security professionals to navigate the AI revolution, urging a focus on robust defense strategies rather than succumbing to the allure of a perceived panacea.

This article explores the core arguments presented by Shrivastava and Datta, dissecting the immediate and long-term implications of AI on cybersecurity. It aims to provide a detailed technical and strategic overview of the challenges and defensive measures necessary for organizations to adapt to this rapidly changing technological environment, ensuring that the integration of AI enhances security posture rather than eroding it.

Background

▶ Watch: Introduction: AI's impact on market and building (0:00)

The advent of powerful large language models (LLMs) like Chat GPT and Claude has fundamentally altered perceptions of software development. Historically, the adage "ideas are cheap, execution is everything" held true, underscoring the significant effort required to translate concepts into functional products. AI tools, however, have begun to flip this equation. As Shrivastava noted, "Building something is easier. You just have to give instructions and something can be built." This shift means that organizations can now rapidly prototype and even deploy applications or features with minimal human coding effort, leading to a re-evaluation of the traditional "build vs. buy" dilemma.

A critical observation highlighted by Shrivastava is the underutilization of features in commercial software. He posited that most organizations use only 25% to 50% of the functionalities available in the products they purchase. This inefficiency, combined with AI's ability to quickly generate specific code, empowers companies to build bespoke solutions in-house for niche requirements. For instance, instead of buying an elaborate Security Assertion Markup Language (SAML) or Single Sign-On (SSO) solution offering myriad options, an organization might use an LLM to generate just the specific SSO code it needs, theoretically reducing cost and complexity.

However, this rapid adoption is not without its perils. Saikat Datta drew parallels to previous technological hype cycles, such as the Revolution in Military Affairs (RMA) and network-centric warfare, where initial enthusiasm often outpaced practical implementation and real-world impact. He cautioned against the FOMO marketing tactics employed by AI vendors, which pressure CISOs into hasty adoption. Datta also emphasized that current AI models are essentially "human knowledge compressed into some sort of a data set," implying that their intelligence is derived from existing, often publicly available, information. While AI excels at speed, adversaries can leverage the same tools, turning the arms race into a contest of who is smarter on any given day. Furthermore, geopolitical pressures and the inherent black box problem of AI models raise concerns about trustworthiness and potential exploitation by nation-state or non-state actors, making the complete removal of "human in the loop" a risky proposition, especially in critical security contexts.

Key Findings

▶ Watch: Vendors use AI; FOMO drives CISO adoption (4:00)

The talk unveiled several critical findings regarding AI's impact on cybersecurity:

  1. Ease of Development vs. Usability/Value: AI significantly lowers the barrier to entry for software development, making it easy to generate code. However, the usability, maintainability, and inherent value of this AI-generated code remain distinct challenges that require human oversight. While 70-80% of AI-generated code might appear to work, the remaining percentage can introduce significant vulnerabilities or operational issues.
  2. The Shifting "Build vs. Buy" Paradigm: Organizations can now consider building specific functionalities in-house, especially for features that represent a small fraction of a large vendor product's capabilities. This can potentially reduce reliance on monolithic vendors and cut costs, but it shifts the burden of maintenance, compliance, and liability to the in-house team.
  3. Vendor AI Adoption is Ubiquitous: Even if an organization consciously avoids direct AI integration, its vendors are almost certainly using AI internally for code generation and product development. This means that AI-generated code, with its inherent risks, is likely to be present in the supply chain, making it an unavoidable factor for end-users. As Shrivastava pointed out, "If you are not doing it, your vendor is doing it."
  4. Complexities of Liability and Indemnification: AI vendors are increasingly offering "unlimited indemnification" for issues arising from their AI models. However, this comes with stringent clauses requiring clients to prove the problem originated from the AI, creating a legal quagmire. As Datta noted, insurance companies "specialize in rejecting claims," and the true extent of liability will ultimately be decided by lawyers, not just CISOs. This makes offloading risk incredibly complex and potentially exposes organizations to new forms of legal and financial vulnerability.
  5. Risks of AI Integration and Exposure: The talk highlighted a critical example: Google's recent acknowledgment that enabling Gemini at an organizational level, while also using Google Maps API keys, could expose the Gemini environment if the API key was treated as public information. This illustrates how seemingly innocuous integrations can create unexpected attack surfaces when AI is woven into existing infrastructure.
  6. The "Draft 1" Nature of AI Code: Even AI developers, like those behind Claude, advise treating AI-generated code as "draft one" rather than an oracle. It requires extensive human review and refinement, yet the temptation to skip rigorous code reviews due to business pressures or complacency is high, potentially propagating errors and vulnerabilities.
  7. The Cyclical Nature of Hype: Saikat Datta contextualized the current AI fervor within historical cycles of technological hype, referencing RMA and network-centric warfare. He argued that while AI is powerful, its transformative impact on "war fighting" or cybersecurity may not align with the initial, often exaggerated, conference room narratives. A measured, cautious approach is essential.

Technical Deep Dive

▶ Watch: AI models: compressed human knowledge, speed advantage and adversary (5:15)

The technical implications discussed during the talk primarily revolve around the practical application of AI in software development and the resulting security challenges. The core technical shift is the ability of LLMs like Chat GPT and Claude to generate functional code from natural language prompts. This capability allows organizations to bypass the traditional development cycle for certain functionalities. For example, instead of purchasing an enterprise-grade SSO solution with hundreds of features, an in-house team could theoretically prompt an AI to "write an SSO module that integrates with Active Directory for our specific application." The AI can rapidly produce code that appears to work for the required 25-50% of functionality, potentially reducing development time and vendor lock-in.

However, this introduces several technical complexities. The quality and security of AI-generated code are paramount. Speakers emphasized that AI-generated code should be treated as a "draft one," requiring meticulous human code review and refinement. Without this, organizations risk propagating errors, insecure coding practices, or even subtle backdoors into their systems. The sheer volume of AI-generated code, and the difficulty of reviewing it line-by-line, can negate the time savings AI initially provides.

A significant technical vulnerability highlighted was the interaction between different services and AI environments. Shrivastava cited a recent development where Google Maps API keys, previously considered public information, could, if enabled at an organizational level alongside Gemini, provide unauthorized access to the Gemini environment. This scenario underscores how the integration of AI capabilities into existing ecosystems, especially when default configurations or assumptions about API key security are not re-evaluated, can create novel and unforeseen attack vectors. The problem arises because environments are now being "built and maintained" with AI making decisions, potentially linking disparate services in ways that were not anticipated by legacy security models.

Furthermore, the "black box problem" of AI models means that the exact reasoning or internal mechanisms behind AI-generated code or decisions are often opaque. This lack of transparency makes it challenging to debug issues, understand potential biases, or even definitively prove the origin of a vulnerability. When an AI generates code, it's not always clear why certain constructs or libraries were chosen, making thorough security auditing a more complex task than with human-written code. The speakers also alluded to the potential for geopolitical influence, where AI models might be subtly manipulated or contain vulnerabilities introduced by nation-state actors during their training or development, a concern that is amplified by the black box nature of these systems.

Demo / Proof of Concept

▶ Watch: Geopolitical pressures, black box problem, human in loop (6:15)

The talk did not feature a specific live demonstration or a detailed proof of concept. Instead, the speakers relied on conceptual examples and recent news to illustrate the capabilities and risks associated with AI code generation and integration. For instance, the discussion around building an SSO module in-house using AI and the specific vulnerability concerning Google Maps API keys and Gemini served as illustrative cases rather than direct demonstrations.

Defensive Implications

▶ Watch: Liability and indemnification for AI-generated code (7:45)

The insights shared by Anant Shrivastava and Saikat Datta offer crucial guidance for cybersecurity defenders in the age of AI. Navigating the "Anthropic Shock" requires a multi-faceted and strategic approach:

  1. Rigorous Code Review for AI-Generated Code: CISOs must implement stringent policies mandating that all AI-generated code, regardless of its apparent functionality, undergoes thorough human code review. This means treating AI output as a "draft one" and not an oracle. Developers must be trained to identify potential vulnerabilities, insecure patterns, and logical flaws that AI models might introduce. Automated static and dynamic application security testing (SAST/DAST) tools should also be integrated into the CI/CD pipeline to scan AI-generated code.
  2. Reduce Attack Surface by System Simplification: A core recommendation from Shrivastava is to actively work towards reducing the attack surface. He posed the question: "Why do you need 200 different systems to just achieve one single task?" Organizations should prioritize rationalizing their IT infrastructure, consolidating functionalities, and decommissioning redundant systems. This not only simplifies management but also limits the potential points of exploitation, making the environment more resilient to both traditional and AI-driven attacks.
  3. Scrutinize Vendor AI Usage and Supply Chain Risk: Given that vendors are already extensively using AI, organizations must proactively inquire about their vendors' AI adoption policies, code generation practices, and security controls. This extends to supply chain risk management, where due diligence should include assessing how AI is impacting the security posture of third-party software and services. Contracts should clearly define liability and indemnification terms, understanding that "unlimited indemnification" often comes with significant caveats.
  4. Resist FOMO and Adopt a Measured Approach: Defenders should avoid succumbing to the FOMO marketing tactics of AI vendors. Instead, a cautious, evidence-based approach is necessary. This involves thorough testing, understanding the specific risks of integrating AI into critical systems, and waiting for the technology to mature and for best practices to emerge, much like previous technology waves (e.g., RMA).
  5. Maintain Human in the Loop and Combat Complacency: The "human in the loop" remains indispensable. Organizations must actively combat developer complacency that might arise from over-reliance on AI tools. This includes fostering a culture of continuous learning, critical thinking, and disciplined security practices. Human expertise is vital for handling edge cases, understanding complex attack scenarios, and providing the ethical and contextual judgment that AI currently lacks.
  6. Re-evaluate Integration Security: The Google Maps API / Gemini example serves as a stark reminder to re-evaluate how existing systems and APIs interact with new AI environments. Organizations must conduct comprehensive security assessments of all AI integrations, paying close attention to authentication, authorization, data flow, and potential privilege escalation pathways that might emerge from unexpected interdependencies.
  7. Engage with Policy and Regulatory Discussions: As Datta highlighted, policy and regulatory decisions regarding AI are being made by individuals often far removed from the front lines of cybersecurity. CISOs and security professionals must actively engage in these discussions, providing reasoned pushback and advocating for policies that prioritize security, transparency, and accountability rather than unbridled adoption.
  8. Focus on Fundamentals: Despite the hype, the fundamentals of cybersecurity remain critical. Strong identity and access management, robust network segmentation, continuous monitoring, incident response planning, and employee training are more important than ever. AI should be seen as a tool to enhance these fundamentals, not replace them.

Key Takeaways

  • AI significantly eases code generation, shifting the "ideas are easy, execution is hard" paradigm, but introduces new complexities regarding code quality and security.
  • Organizations must treat AI-generated code as a "draft one" requiring extensive human code review to mitigate the risk of vulnerabilities and maintainability issues.
  • The ubiquitous use of AI by vendors means organizations must account for AI-related risks in their supply chain, even if they don't directly adopt AI.
  • Liability and indemnification for AI-related incidents are complex legal challenges, with vendor promises often containing significant caveats that CISOs must scrutinize.
  • New AI integrations, like the Google Maps API / Gemini example, can create unexpected attack surfaces, necessitating thorough security assessments of all interconnected systems.
  • CISOs should resist FOMO and adopt a measured, analytical approach to AI adoption, focusing on reducing their overall attack surface and engaging in policy discussions to shape responsible AI governance.

About the Speaker(s)

Anant Shrivastava is associated with Cyfinoid Research, indicating a background in cybersecurity research and development. His contributions to the talk highlight an understanding of practical software development challenges and the evolving landscape of AI-driven code generation within organizations.

Saikat Datta is affiliated with DeepStrat, suggesting expertise in strategic analysis, policy, and the broader geopolitical implications of technology. His insights in the talk drew parallels from historical technology cycles and emphasized the importance of policy, liability, and critical evaluation in the face of technological hype. Together, their perspectives offered a balanced view of AI's technical capabilities and its wider strategic and organizational impact.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A panel-style discussion that mistakes concern-cataloguing for analysis. The speakers identify real tensions — AI-generated code quality, supply chain risk, liability theater — but never go deeper than what any CISO already absorbed from their LinkedIn feed six months ago. The Google Maps/Gemini anecdote is the closest thing to a concrete technical datapoint, and it's presented second-hand with no exploitation detail.

Heather Calloway (CISO) — WEAK

Shrivastava and Datta identify real friction points — supply chain AI exposure, liability gaps, integration attack surface — but never move past the problem statement. The talk is a reasonable survey of concerns dressed up as analysis, and the defensive recommendations collapse into generic guidance that any security-aware practitioner already knows.

→ Top-rated talks at Nullcon Goa 2026

All talks from Nullcon Goa 2026