Thank you for this analysis: dense, lucid, and refreshingly free of absolutism. I agree with most of it, particularly your call to reduce harms rather than deny them. It is precisely that principle that leads me to point out one angle that, unless I missed it, remains absent from the article: the energy and environmental cost of the cyber/AI arms race.
You describe a dynamic in which both attackers and defenders run models in parallel, where Hugging Face can switch to GLM 5.2 at short notice, where organizations are advised to "keep an open-weight model on the shelf," automate Tier 1 and Tier 2 SOC functions, and scan code in real time. From a security perspective, all of this is defensible. From an energy perspective, however, it amounts to a carbon-intensive arms race that goes unnamed, even though the 2026 numbers suggest it is now structural rather than anecdotal: roughly 565 TWh consumed by datacenters this year, a 26% increase year-over-year, with projections reaching 950 TWh by 2030. In the United States alone, datacenters could account for between 6.7% and 12% of national electricity consumption by 2028, depending on the scenario, with the latter being the upper bound rather than the central forecast.
The paradox can be summarized in a single sentence: your recommendation to multiply on-premises models for cyber resilience is technically sound, but it also tends to duplicate hardware and reduce some of the efficiency gains that come from shared cloud infrastructure, precisely at the moment when energy constraints are becoming a geopolitical factor. And when you describe a ransomware group renting "eight B300s plus an Ultra cluster to run Kimi K3," you are, perhaps unintentionally, describing an infrastructure whose power consumption can quickly reach tens of kilowatts, or more depending on the scale of the cluster, deployed in service of criminal activity and matched, in one form or another, by its targets. The escalation is therefore twofold: capabilities and watts.
Your own framework, however, suggests a broader obligation. If we want to protect open-weight models and defensive AI from future regulatory backlash, we need to reduce harms rather than simply argue that they do not exist. Energy consumption is a collective harm: delayed, diffuse, and lacking an identifiable victim. That makes it politically weak today, but also a likely candidate for future regulatory intervention if the industry continues to ignore it. The reputational "doom loop" you describe for AI labs applies equally well to environmental impact: deny the problem until it becomes impossible to ignore, then face a punitive overcorrection.
Concretely, I would add three extensions to your recommendations:
Integrate energy cost into cybersecurity standards. A cyber evaluation that ignores the energy cost of a defensive query is missing half of the trade-off. The benchmark should not only be model accuracy, but also watts per detection.
Mutualize defense rather than endlessly duplicate it. Where you advocate systematic on-prem deployment, a middle ground might be regionally shared defensive infrastructure, similar to an ISAC with dedicated compute capacity. Such an approach could reduce hardware redundancy without sacrificing sovereignty.
Stop treating energy as a mere operational expense. It is increasingly becoming a security variable in its own right. AI enables new forms of cyberattack, while the energy sector itself is becoming an increasingly attractive target. The loop closes on itself, and it deserves to be named as such.
Beyond energy, two additional dimensions seem absent from an otherwise comprehensive analysis.
First, bias and fairness in defensive AI. Who is being monitored, by which models, and with what discriminatory false-positive rates? Automating Tier 1 SOC functions through AI has downstream effects on employees and customers that remain largely unmeasured.
Second, hardware supply chain dependency. The cyber/AI race is not only fought in software. It is also fought through silicon, HBM memory, advanced GPUs, and the manufacturing capacity of companies such as TSMC. The software resilience you advocate ultimately collides with a hardware bottleneck whose contours are continuously reshaped by export controls, industrial policy, and geopolitical competition.
Far be it from me to suggest that a single article should cover everything. But because you argue for a systemic rather than absolutist view of the problem, these are not peripheral concerns. They are part of the conditions required for the roadmap you propose to remain sustainable over the long term.
Wow. So much to take in here, but really good read. And it is changing so fast. From NZ I think this is a problem we have down here - we are so small and don't have the knowledge grunt. We need to see how we can partner with USA and take advantage of development in open weight models. There are a few people trying to take smaller models and then train them for specific use cases, but feel like from a cyber-sec point of view we are not ready.
Thank you for this analysis: dense, lucid, and refreshingly free of absolutism. I agree with most of it, particularly your call to reduce harms rather than deny them. It is precisely that principle that leads me to point out one angle that, unless I missed it, remains absent from the article: the energy and environmental cost of the cyber/AI arms race.
You describe a dynamic in which both attackers and defenders run models in parallel, where Hugging Face can switch to GLM 5.2 at short notice, where organizations are advised to "keep an open-weight model on the shelf," automate Tier 1 and Tier 2 SOC functions, and scan code in real time. From a security perspective, all of this is defensible. From an energy perspective, however, it amounts to a carbon-intensive arms race that goes unnamed, even though the 2026 numbers suggest it is now structural rather than anecdotal: roughly 565 TWh consumed by datacenters this year, a 26% increase year-over-year, with projections reaching 950 TWh by 2030. In the United States alone, datacenters could account for between 6.7% and 12% of national electricity consumption by 2028, depending on the scenario, with the latter being the upper bound rather than the central forecast.
The paradox can be summarized in a single sentence: your recommendation to multiply on-premises models for cyber resilience is technically sound, but it also tends to duplicate hardware and reduce some of the efficiency gains that come from shared cloud infrastructure, precisely at the moment when energy constraints are becoming a geopolitical factor. And when you describe a ransomware group renting "eight B300s plus an Ultra cluster to run Kimi K3," you are, perhaps unintentionally, describing an infrastructure whose power consumption can quickly reach tens of kilowatts, or more depending on the scale of the cluster, deployed in service of criminal activity and matched, in one form or another, by its targets. The escalation is therefore twofold: capabilities and watts.
Your own framework, however, suggests a broader obligation. If we want to protect open-weight models and defensive AI from future regulatory backlash, we need to reduce harms rather than simply argue that they do not exist. Energy consumption is a collective harm: delayed, diffuse, and lacking an identifiable victim. That makes it politically weak today, but also a likely candidate for future regulatory intervention if the industry continues to ignore it. The reputational "doom loop" you describe for AI labs applies equally well to environmental impact: deny the problem until it becomes impossible to ignore, then face a punitive overcorrection.
Concretely, I would add three extensions to your recommendations:
Integrate energy cost into cybersecurity standards. A cyber evaluation that ignores the energy cost of a defensive query is missing half of the trade-off. The benchmark should not only be model accuracy, but also watts per detection.
Mutualize defense rather than endlessly duplicate it. Where you advocate systematic on-prem deployment, a middle ground might be regionally shared defensive infrastructure, similar to an ISAC with dedicated compute capacity. Such an approach could reduce hardware redundancy without sacrificing sovereignty.
Stop treating energy as a mere operational expense. It is increasingly becoming a security variable in its own right. AI enables new forms of cyberattack, while the energy sector itself is becoming an increasingly attractive target. The loop closes on itself, and it deserves to be named as such.
Beyond energy, two additional dimensions seem absent from an otherwise comprehensive analysis.
First, bias and fairness in defensive AI. Who is being monitored, by which models, and with what discriminatory false-positive rates? Automating Tier 1 SOC functions through AI has downstream effects on employees and customers that remain largely unmeasured.
Second, hardware supply chain dependency. The cyber/AI race is not only fought in software. It is also fought through silicon, HBM memory, advanced GPUs, and the manufacturing capacity of companies such as TSMC. The software resilience you advocate ultimately collides with a hardware bottleneck whose contours are continuously reshaped by export controls, industrial policy, and geopolitical competition.
Far be it from me to suggest that a single article should cover everything. But because you argue for a systemic rather than absolutist view of the problem, these are not peripheral concerns. They are part of the conditions required for the roadmap you propose to remain sustainable over the long term.
Wow. So much to take in here, but really good read. And it is changing so fast. From NZ I think this is a problem we have down here - we are so small and don't have the knowledge grunt. We need to see how we can partner with USA and take advantage of development in open weight models. There are a few people trying to take smaller models and then train them for specific use cases, but feel like from a cyber-sec point of view we are not ready.
Really excellent collection of thoughts on the landscape and challenges.
Add the UK’s AISI’s disclosure yesterday about a model impacting third parties, social engineering, malicious packages and more to the list as well..
It’s impossible to finish any writing because you can’t keep it up to date!