×
Judge sides with Anthropic to temporarily block the Pentagon’s ban

Judge sides with Anthropic to temporarily block the Pentagon’s ban

After Anthropic’s weeks-long standoff with the Pentagon, the company won one milestone: A judge granted Anthropic a preliminary injunction in its lawsuit, which sought to reverse its government blacklisting while the judicial process plays out.

“The Department of War’s records show that it designated Anthropic as a supply chain risk because of its ‘hostile manner through the press,’” Judge Rita F. Lin, a district judge in the northern district of California, wrote in the order, which will go into effect in seven days. “Punishing Anthropic for bringing public scrutiny to the government’s contracting position is classic illegal First Amendment retaliation.”

A final verdict could be weeks or months out.

Anthropic spokesperson Danielle Cohen said in a Thursday statement, “We’re grateful to the court for moving swiftly, and pleased they agree Anthropic is likely to succeed on the merits. While this case was necessary to protect Anthropic, our customers, and our partners, our focus remains on working productively with the government to ensure all Americans benefit from safe, reliable AI.”

“I do think this case touches on an important debate,” Judge Lin said during the Tuesday hearing. “On the one hand, Anthropic is saying that its AI product, Claude, is not safe to use for autonomous lethal weapons and domestic mass surveillance. Anthropic’s position is that if the government wants to use its technology, the government has to agree not to use it for those purposes. On the other hand the Department of War is saying that military commanders have to decide what is safe for its AI to do.”

On Tuesday, Judge Lin went on to say, “It’s not my role to decide who’s right in that debate… The Department of War decides what AI product it wants to use and buy. And everyone, including Anthropic, agrees that the Department of War is free to stop using Claude and look for a more permissive AI vendor.” She added, “I see the question in this case as being … whether the government violated the law when it went beyond that.”

It all started with a memo sent by Defense Secretary Pete Hegseth on Jan. 9, calling for “any lawful use” language to be written into any AI services procurement contract within 180 days, which would include existing contracts with companies like Anthropic, OpenAI, xAI, and Google. Anthropic’s negotiations with the Pentagon stretched on for weeks, hinging on two “red lines” that the company did not want the military to use its AI for: domestic mass surveillance and lethal autonomous weapons (or AI systems with the power to kill targets with no human involvement in the decisionmaking process). The rollercoaster series of events that followed has included a barrage of social media insults, a formal “supply chain risk” designation with the potential to significantly handicap Anthropic’s business, competing AI companies swooping in to make deals, and an ensuing lawsuit.

With its lawsuit, Anthropic argues that it was punished for speech protected under the First Amendment, and it’s seeking to reverse the supply chain risk designation.

It’s rare, and potentially even unheard of until now, for a US company to be named a supply chain risk, a designation typically reserved for non-US companies potentially linked to foreign adversaries. Anthropic’s designation as such raised eyebrows nationwide and caused bipartisan controversy due to concerns that disagreeing with a presidential administration could potentially lead to outsized retribution for a business in any sector.

Anthropic’s own business has been significantly affected by the designation, according to its court filings, which say that it has “received outreach from numerous outside partners … expressing confusion about what was required of them and concern about their ability to continue to work with Anthropic” and that “dozens of companies have contacted Anthropic” for guidance or information about their rights to terminate usage. Depending on the level to which the government prohibits its contractors’ work with Anthropic, the company alleged that revenue adding up to between hundreds of millions and multiple billions could be at risk.

During Tuesday’s hearing, both companies had a chance to respond to Judge Lin’s questions, which were released in a document the day prior and hinged on matters like whether Hegseth lacked authority to issue certain directives and why Anthropic was named a supply chain risk. The judge also asked, in her pre-released questions, about the circumstances under which a government contractor could face termination for using Anthropic’s technology in their work — for instance, “if a contractor for the Department uses Claude Code as a tool to write software for the Department’s national security systems, would that contractor face termination as a result?”

On Tuesday, the judge also seemed to admonish the Department of War for Hegseth’s X post that caused a lot of widespread confusion per Anthropic’s earlier court filings, stating that “effective immediately, no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic.”

“You’re standing here saying, ‘We said it but we didn’t really mean it,’” Judge Lin said during the hearing, later pressing on the question of why Hegseth wrote the above barring contractors from working with Anthropic instead of just simply designating Anthropic as a supply chain risk.

In a series of questions on Tuesday, Judge Lin asked whether the Department of War plans to terminate contractors on the basis of their work with Anthropic if it’s separate from their work with the department, and a representative for the Department of War responded, “That is my understanding.”

Judge Lin asked, “Let’s say I’m a military contractor. I don’t provide IT to the military. I provide toilet paper to the military. I’m not going to be terminated for using Anthropic — is that accurate?” The representative for the Department of War responded, “For non-DoW work, that is my understanding.” But when the judge asked whether a military contractor providing IT services to the Department of War, but not for national security systems, could be terminated for using Anthropic, the representative for the Department of War did not give a concrete answer.

During the hearing, Judge Lin cited one of the amicus briefs, which she said used the term “attempted corporate murder.” She said, “I don’t know if it’s ‘murder,’ but it looks like an attempt to cripple Anthropic.”

“We are continuing to be irreparably injured by this directive,” a lawyer for Anthropic said during the hearing, citing Hegseth’s nine-paragraph X post.

In a recent court filing, the Department of Defense alleged that Anthropic could ostensibly “attempt to disable its technology or preemptively alter the behavior of its model either before or during ongoing warfighting operations” in the event it felt the military was crossing its red lines — a theoretical situation that the Pentagon said it deemed an “unacceptable risk to national security.” The judge’s pre-released questions seem to challenge that statement, or at least request more information on it, stating, “What evidence in the record shows that Anthropic had ongoing access to or control over Claude after delivering it to the government, such that Anthropic could engage in such acts of sabotage or subversion?”

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.


Source link
#Judge #sides #Anthropic #temporarily #block #Pentagons #ban

For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. 

In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days">How AI guardrails are impeding the work of offensive cybersecurity researchers | TechCrunch
For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. 

In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.







Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program. 

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.


Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses  — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said. 

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.” 







It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 







Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”


When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days

slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days">How AI guardrails are impeding the work of offensive cybersecurity researchers | TechCrunch

For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. 

In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days
BGMI Pro Series (BMPS) 2026 a month back, KRAFTON India has revealed what’s next for the country’s competitive BGMI scene. There will be two major tournaments for the second half of the year: the return of the BGMI International Cup (BMIC) and an all-new BGMI Showdown (BMSD).

While BMIC will once again pit India’s best teams against top squads from across Asia, the newly introduced BGMI Showdown is an invite-only championship reserved for the country’s highest-performing teams. Both tournaments will feature a ₹1 crore prize pool.

BGMI International Cup Returns This October

BGMI International Cup Returns To Mumbai & KRAFTON Announces New BMSD Tournament for India
	
After wrapping up the super exciting BGMI Pro Series (BMPS) 2026 a month back, KRAFTON India has revealed what’s next for the country’s competitive BGMI scene. There will be two major tournaments for the second half of the year: the return of the BGMI International Cup (BMIC) and an all-new BGMI Showdown (BMSD).



While BMIC will once again pit India’s best teams against top squads from across Asia, the newly introduced BGMI Showdown is an invite-only championship reserved for the country’s highest-performing teams. Both tournaments will feature a ₹1 crore prize pool.



BGMI International Cup Returns This October







The second edition of the BGMI International Cup (BMIC) is scheduled to take place from October 30 to November 1 at the Dome, SVP Indoor Stadium in Mumbai. The tournament will feature 16 teams, including six from India, five from South Korea, and five from Japan. They’ll compete for a ₹1 crore prize pool, with the event bringing some of Asia’s strongest BGMI teams to India for the first time. For Indian fans, BMIC will be one of the rare opportunities to watch domestic teams take on international opponents on home soil in front of a live audience.



Alongside BMIC, KRAFTON has also announced the BGMI Showdown (BMSD), a brand-new tournament focused entirely on India’s top-performing teams. Unlike BGIS or BMPS, there won’t be any open qualifiers. Instead, the tournament will feature 48 invited teams, selected based on their performances across the KIE Leaderboard, BGIS, and BMPS. The competition begins on September 22 and will progress through Promotion & Relegation rounds, Survival stages, Semi-Finals, and a Last Chance stage before culminating in the LAN Grand Finals.



BGMI Showdown Schedule:




Week 1 (Promotion & Relegation): September 22–24



Week 2 (Promotion & Relegation): September 25–27



Week 3 (Promotion & Relegation): September 28–30



Upper Bracket Survival: October 1–3



Lower Bracket Survival: October 4–6



Semi Finals: October 8–11



Last Chance: October 12–13



LAN Grand Finals: October 16–18




Speaking about the announcement, Karan Pathak, Associate Director:




Every season should feel bigger than the last- not just in scale, but in the quality of competition it delivers. That’s what we’ve set out to achieve with this year’s H2 calendar. The BGMI International Cup brings some of Asia’s strongest teams to Mumbai, while the BGMI Showdown rewards the teams that have consistently proved themselves across the season.






#BGMI #International #Cup #Returns #Mumbai #KRAFTON #Announces #BMSD #Tournament #IndiaBGMI

The second edition of the BGMI International Cup (BMIC) is scheduled to take place from October 30 to November 1 at the Dome, SVP Indoor Stadium in Mumbai. The tournament will feature 16 teams, including six from India, five from South Korea, and five from Japan. They’ll compete for a ₹1 crore prize pool, with the event bringing some of Asia’s strongest BGMI teams to India for the first time. For Indian fans, BMIC will be one of the rare opportunities to watch domestic teams take on international opponents on home soil in front of a live audience.

Alongside BMIC, KRAFTON has also announced the BGMI Showdown (BMSD), a brand-new tournament focused entirely on India’s top-performing teams. Unlike BGIS or BMPS, there won’t be any open qualifiers. Instead, the tournament will feature 48 invited teams, selected based on their performances across the KIE Leaderboard, BGIS, and BMPS. The competition begins on September 22 and will progress through Promotion & Relegation rounds, Survival stages, Semi-Finals, and a Last Chance stage before culminating in the LAN Grand Finals.

BGMI Showdown Schedule:

  • Week 1 (Promotion & Relegation): September 22–24
  • Week 2 (Promotion & Relegation): September 25–27
  • Week 3 (Promotion & Relegation): September 28–30
  • Upper Bracket Survival: October 1–3
  • Lower Bracket Survival: October 4–6
  • Semi Finals: October 8–11
  • Last Chance: October 12–13
  • LAN Grand Finals: October 16–18

Speaking about the announcement, Karan Pathak, Associate Director:

Every season should feel bigger than the last- not just in scale, but in the quality of competition it delivers. That’s what we’ve set out to achieve with this year’s H2 calendar. The BGMI International Cup brings some of Asia’s strongest teams to Mumbai, while the BGMI Showdown rewards the teams that have consistently proved themselves across the season.

#BGMI #International #Cup #Returns #Mumbai #KRAFTON #Announces #BMSD #Tournament #IndiaBGMI">BGMI International Cup Returns To Mumbai & KRAFTON Announces New BMSD Tournament for India
	
After wrapping up the super exciting BGMI Pro Series (BMPS) 2026 a month back, KRAFTON India has revealed what’s next for the country’s competitive BGMI scene. There will be two major tournaments for the second half of the year: the return of the BGMI International Cup (BMIC) and an all-new BGMI Showdown (BMSD).



While BMIC will once again pit India’s best teams against top squads from across Asia, the newly introduced BGMI Showdown is an invite-only championship reserved for the country’s highest-performing teams. Both tournaments will feature a ₹1 crore prize pool.



BGMI International Cup Returns This October







The second edition of the BGMI International Cup (BMIC) is scheduled to take place from October 30 to November 1 at the Dome, SVP Indoor Stadium in Mumbai. The tournament will feature 16 teams, including six from India, five from South Korea, and five from Japan. They’ll compete for a ₹1 crore prize pool, with the event bringing some of Asia’s strongest BGMI teams to India for the first time. For Indian fans, BMIC will be one of the rare opportunities to watch domestic teams take on international opponents on home soil in front of a live audience.



Alongside BMIC, KRAFTON has also announced the BGMI Showdown (BMSD), a brand-new tournament focused entirely on India’s top-performing teams. Unlike BGIS or BMPS, there won’t be any open qualifiers. Instead, the tournament will feature 48 invited teams, selected based on their performances across the KIE Leaderboard, BGIS, and BMPS. The competition begins on September 22 and will progress through Promotion & Relegation rounds, Survival stages, Semi-Finals, and a Last Chance stage before culminating in the LAN Grand Finals.



BGMI Showdown Schedule:




Week 1 (Promotion & Relegation): September 22–24



Week 2 (Promotion & Relegation): September 25–27



Week 3 (Promotion & Relegation): September 28–30



Upper Bracket Survival: October 1–3



Lower Bracket Survival: October 4–6



Semi Finals: October 8–11



Last Chance: October 12–13



LAN Grand Finals: October 16–18




Speaking about the announcement, Karan Pathak, Associate Director:




Every season should feel bigger than the last- not just in scale, but in the quality of competition it delivers. That’s what we’ve set out to achieve with this year’s H2 calendar. The BGMI International Cup brings some of Asia’s strongest teams to Mumbai, while the BGMI Showdown rewards the teams that have consistently proved themselves across the season.






#BGMI #International #Cup #Returns #Mumbai #KRAFTON #Announces #BMSD #Tournament #IndiaBGMI

2026 a month back, KRAFTON India has revealed what’s next for the country’s competitive BGMI scene. There will be two major tournaments for the second half of the year: the return of the BGMI International Cup (BMIC) and an all-new BGMI Showdown (BMSD).

While BMIC will once again pit India’s best teams against top squads from across Asia, the newly introduced BGMI Showdown is an invite-only championship reserved for the country’s highest-performing teams. Both tournaments will feature a ₹1 crore prize pool.

BGMI International Cup Returns This October

BGMI International Cup Returns To Mumbai & KRAFTON Announces New BMSD Tournament for India
	
After wrapping up the super exciting BGMI Pro Series (BMPS) 2026 a month back, KRAFTON India has revealed what’s next for the country’s competitive BGMI scene. There will be two major tournaments for the second half of the year: the return of the BGMI International Cup (BMIC) and an all-new BGMI Showdown (BMSD).



While BMIC will once again pit India’s best teams against top squads from across Asia, the newly introduced BGMI Showdown is an invite-only championship reserved for the country’s highest-performing teams. Both tournaments will feature a ₹1 crore prize pool.



BGMI International Cup Returns This October







The second edition of the BGMI International Cup (BMIC) is scheduled to take place from October 30 to November 1 at the Dome, SVP Indoor Stadium in Mumbai. The tournament will feature 16 teams, including six from India, five from South Korea, and five from Japan. They’ll compete for a ₹1 crore prize pool, with the event bringing some of Asia’s strongest BGMI teams to India for the first time. For Indian fans, BMIC will be one of the rare opportunities to watch domestic teams take on international opponents on home soil in front of a live audience.



Alongside BMIC, KRAFTON has also announced the BGMI Showdown (BMSD), a brand-new tournament focused entirely on India’s top-performing teams. Unlike BGIS or BMPS, there won’t be any open qualifiers. Instead, the tournament will feature 48 invited teams, selected based on their performances across the KIE Leaderboard, BGIS, and BMPS. The competition begins on September 22 and will progress through Promotion & Relegation rounds, Survival stages, Semi-Finals, and a Last Chance stage before culminating in the LAN Grand Finals.



BGMI Showdown Schedule:




Week 1 (Promotion & Relegation): September 22–24



Week 2 (Promotion & Relegation): September 25–27



Week 3 (Promotion & Relegation): September 28–30



Upper Bracket Survival: October 1–3



Lower Bracket Survival: October 4–6



Semi Finals: October 8–11



Last Chance: October 12–13



LAN Grand Finals: October 16–18




Speaking about the announcement, Karan Pathak, Associate Director:




Every season should feel bigger than the last- not just in scale, but in the quality of competition it delivers. That’s what we’ve set out to achieve with this year’s H2 calendar. The BGMI International Cup brings some of Asia’s strongest teams to Mumbai, while the BGMI Showdown rewards the teams that have consistently proved themselves across the season.






#BGMI #International #Cup #Returns #Mumbai #KRAFTON #Announces #BMSD #Tournament #IndiaBGMI

The second edition of the BGMI International Cup (BMIC) is scheduled to take place from October 30 to November 1 at the Dome, SVP Indoor Stadium in Mumbai. The tournament will feature 16 teams, including six from India, five from South Korea, and five from Japan. They’ll compete for a ₹1 crore prize pool, with the event bringing some of Asia’s strongest BGMI teams to India for the first time. For Indian fans, BMIC will be one of the rare opportunities to watch domestic teams take on international opponents on home soil in front of a live audience.

Alongside BMIC, KRAFTON has also announced the BGMI Showdown (BMSD), a brand-new tournament focused entirely on India’s top-performing teams. Unlike BGIS or BMPS, there won’t be any open qualifiers. Instead, the tournament will feature 48 invited teams, selected based on their performances across the KIE Leaderboard, BGIS, and BMPS. The competition begins on September 22 and will progress through Promotion & Relegation rounds, Survival stages, Semi-Finals, and a Last Chance stage before culminating in the LAN Grand Finals.

BGMI Showdown Schedule:

  • Week 1 (Promotion & Relegation): September 22–24
  • Week 2 (Promotion & Relegation): September 25–27
  • Week 3 (Promotion & Relegation): September 28–30
  • Upper Bracket Survival: October 1–3
  • Lower Bracket Survival: October 4–6
  • Semi Finals: October 8–11
  • Last Chance: October 12–13
  • LAN Grand Finals: October 16–18

Speaking about the announcement, Karan Pathak, Associate Director:

Every season should feel bigger than the last- not just in scale, but in the quality of competition it delivers. That’s what we’ve set out to achieve with this year’s H2 calendar. The BGMI International Cup brings some of Asia’s strongest teams to Mumbai, while the BGMI Showdown rewards the teams that have consistently proved themselves across the season.

#BGMI #International #Cup #Returns #Mumbai #KRAFTON #Announces #BMSD #Tournament #IndiaBGMI">BGMI International Cup Returns To Mumbai & KRAFTON Announces New BMSD Tournament for India

After wrapping up the super exciting BGMI Pro Series (BMPS) 2026 a month back, KRAFTON India has revealed what’s next for the country’s competitive BGMI scene. There will be two major tournaments for the second half of the year: the return of the BGMI International Cup (BMIC) and an all-new BGMI Showdown (BMSD).

While BMIC will once again pit India’s best teams against top squads from across Asia, the newly introduced BGMI Showdown is an invite-only championship reserved for the country’s highest-performing teams. Both tournaments will feature a ₹1 crore prize pool.

BGMI International Cup Returns This October

BGMI International Cup Returns To Mumbai & KRAFTON Announces New BMSD Tournament for India
	
After wrapping up the super exciting BGMI Pro Series (BMPS) 2026 a month back, KRAFTON India has revealed what’s next for the country’s competitive BGMI scene. There will be two major tournaments for the second half of the year: the return of the BGMI International Cup (BMIC) and an all-new BGMI Showdown (BMSD).



While BMIC will once again pit India’s best teams against top squads from across Asia, the newly introduced BGMI Showdown is an invite-only championship reserved for the country’s highest-performing teams. Both tournaments will feature a ₹1 crore prize pool.



BGMI International Cup Returns This October







The second edition of the BGMI International Cup (BMIC) is scheduled to take place from October 30 to November 1 at the Dome, SVP Indoor Stadium in Mumbai. The tournament will feature 16 teams, including six from India, five from South Korea, and five from Japan. They’ll compete for a ₹1 crore prize pool, with the event bringing some of Asia’s strongest BGMI teams to India for the first time. For Indian fans, BMIC will be one of the rare opportunities to watch domestic teams take on international opponents on home soil in front of a live audience.



Alongside BMIC, KRAFTON has also announced the BGMI Showdown (BMSD), a brand-new tournament focused entirely on India’s top-performing teams. Unlike BGIS or BMPS, there won’t be any open qualifiers. Instead, the tournament will feature 48 invited teams, selected based on their performances across the KIE Leaderboard, BGIS, and BMPS. The competition begins on September 22 and will progress through Promotion & Relegation rounds, Survival stages, Semi-Finals, and a Last Chance stage before culminating in the LAN Grand Finals.



BGMI Showdown Schedule:




Week 1 (Promotion & Relegation): September 22–24



Week 2 (Promotion & Relegation): September 25–27



Week 3 (Promotion & Relegation): September 28–30



Upper Bracket Survival: October 1–3



Lower Bracket Survival: October 4–6



Semi Finals: October 8–11



Last Chance: October 12–13



LAN Grand Finals: October 16–18




Speaking about the announcement, Karan Pathak, Associate Director:




Every season should feel bigger than the last- not just in scale, but in the quality of competition it delivers. That’s what we’ve set out to achieve with this year’s H2 calendar. The BGMI International Cup brings some of Asia’s strongest teams to Mumbai, while the BGMI Showdown rewards the teams that have consistently proved themselves across the season.






#BGMI #International #Cup #Returns #Mumbai #KRAFTON #Announces #BMSD #Tournament #IndiaBGMI

The second edition of the BGMI International Cup (BMIC) is scheduled to take place from October 30 to November 1 at the Dome, SVP Indoor Stadium in Mumbai. The tournament will feature 16 teams, including six from India, five from South Korea, and five from Japan. They’ll compete for a ₹1 crore prize pool, with the event bringing some of Asia’s strongest BGMI teams to India for the first time. For Indian fans, BMIC will be one of the rare opportunities to watch domestic teams take on international opponents on home soil in front of a live audience.

Alongside BMIC, KRAFTON has also announced the BGMI Showdown (BMSD), a brand-new tournament focused entirely on India’s top-performing teams. Unlike BGIS or BMPS, there won’t be any open qualifiers. Instead, the tournament will feature 48 invited teams, selected based on their performances across the KIE Leaderboard, BGIS, and BMPS. The competition begins on September 22 and will progress through Promotion & Relegation rounds, Survival stages, Semi-Finals, and a Last Chance stage before culminating in the LAN Grand Finals.

BGMI Showdown Schedule:

  • Week 1 (Promotion & Relegation): September 22–24
  • Week 2 (Promotion & Relegation): September 25–27
  • Week 3 (Promotion & Relegation): September 28–30
  • Upper Bracket Survival: October 1–3
  • Lower Bracket Survival: October 4–6
  • Semi Finals: October 8–11
  • Last Chance: October 12–13
  • LAN Grand Finals: October 16–18

Speaking about the announcement, Karan Pathak, Associate Director:

Every season should feel bigger than the last- not just in scale, but in the quality of competition it delivers. That’s what we’ve set out to achieve with this year’s H2 calendar. The BGMI International Cup brings some of Asia’s strongest teams to Mumbai, while the BGMI Showdown rewards the teams that have consistently proved themselves across the season.

#BGMI #International #Cup #Returns #Mumbai #KRAFTON #Announces #BMSD #Tournament #IndiaBGMI

Post Comment