TLDRocket
Sign in

Why blocking AI models won’t stop the cyber threats they create

CSET Georgetown Jason Ly Covered by 74 sources

Opinion — commentary, not a factual news event.

Two Georgetown researchers say banning AI models won't fix cyber threats. Real fix: long-term defense strategy, not whack-a-mole bans on releases.

Based on reporting by CSET Georgetown, Jason Ly — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Jessica Ji and Andrew Lohn, both researchers at Georgetown's Center for Security and Emerging Technology, used a CyberScoop op-ed to push back on a policy instinct that's become almost reflexive in Washington: when an AI model looks dangerous, block it. Their argument is blunt. That approach treats a symptom while ignoring the disease.

The pair points out that cyber capabilities don't disappear just because one model gets restricted. Open-source alternatives proliferate, other countries keep building, and the underlying vulnerabilities in American networks stay exactly where they were before anyone typed a prompt. Ji and Lohn frame model-blocking as a quick fix that feels like action but doesn't actually shrink the attack surface hackers exploit.

Instead, they call for something less flashy and much harder to execute: a genuine national cybersecurity strategy, one that treats AI-enabled threats as an extension of existing defense gaps rather than a brand-new category requiring brand-new bans. That means federal leadership setting priorities and standards, paired with AI companies actually building in safeguards rather than reacting to headlines. The line they use, and it's the crux of the whole piece, is that what's needed is real long-term strategy, not quick-fixes like blocking individual model releases.

Underneath the policy talk is a more uncomfortable point. Banning a model is easy to announce and easy to photograph. Rewiring how federal agencies, critical infrastructure operators, and private companies actually defend their systems is slow, expensive, and politically unrewarding. Ji and Lohn are essentially betting that the harder path is the only one that works.

My take — AI-written commentary, not fact-checked reporting

Model bans make for good press releases and terrible cybersecurity, since the threat migrates to the next open model or the next country within weeks. Anyone serious about AI-enabled hacking should be spending political capital on patching legacy systems and funding actual defense infrastructure, not chasing headlines by outlawing individual releases. This is the same mistake regulators keep making with encryption and now AI: attack the tool instead of fixing the target.

Read more about this at: CSET Georgetown

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.