Pioneers Insight Method Research Author
AGI-Pilled Cyber Defense: Automating Digital Forensics w/ Asymmetric Security Founder Alexis Carlier
Back to Episodes

AGI-Pilled Cyber Defense: Automating Digital Forensics w/ Asymmetric Security Founder Alexis Carlier

Summary

  • Asymmetric Security’s core bet is that AGI will make continuous, expert-level digital forensics economically possible. Alexis Carlier asks what defenders would build with “100 x the intelligent labor at your disposal”: not merely cheaper incident response, but proactive investigations running near the cost of compute. The platform opportunity is to replace noisy static detection across a market he sizes at a few hundred billion dollars, “maybe 500 billion.”

  • Carlier’s AGI threshold is full substitution for long-horizon remote work, which today’s models still cannot reliably provide. Nathan Labenz points to Opus 4.5 repeatedly coding brittle heuristics when fluid judgment would work—“Use your fluid intelligence. Just read the file”—while Carlier attributes the broader jaggedness partly to reinforcement learning favoring verifiable domains such as coding and math. Carlier expects the economic signal to appear in output, while Labenz argues collapsing prices could leave GDP flat or even lower.

  • AI has not transformed cyberattacks yet, but Carlier expects it soon to lower the sophistication required for each attack class. Today, roughly 70-80% of attacks involve phishing or social engineering because criminals take “the path of least resistance,” while most technical exploitation targets known, unpatched vulnerabilities rather than zero-days. The implication is scale: moderately sophisticated ransomware capabilities could become available to many more attackers.

  • The initial product already compresses business-email investigations from roughly two days-to-a-week into a few hours, but 90% model accuracy is nowhere near autonomous-grade reliability. On simpler incidents, off-the-shelf models plus minimal scaffolding can perform a strong first pass; humans then quality-check the reasoning and materially revise a minority of cases. Cybersecurity demands “the nines of reliability,” leaving a potentially long human tail even when most analytical work appears complete.

  • The defensible asset is not merely the agent harness but access to private incidents, elite analysts and realistic evaluations. Breach logs rarely become public, and Carlier says CrowdStrike has only roughly 60 people capable of the deepest forensic investigations, leaving frontier labs “very constrained on talent and really constrained on data.” Asymmetric’s services model gives its investigators repeated real-case model evaluation and access to incident-derived blueprints for realistic training environments; analysts’ reasoning traces may also become a differentiated asset.

  • Cyber insurers provide an unusually concentrated distribution channel for the services wedge. Carriers maintain pre-approved incident-response panels and direct breached customers to trusted vendors, while Asymmetric’s faster investigations create the initial reason to switch. That trust-and-data flywheel matters because buyers cannot easily tell, “Am I not attacked or do I just not know about it?”

  • Digital forensics may offer a rare way to differentially accelerate defense without equivalently improving offense. Penetration testing and vulnerability discovery are plainly dual use, but forensics asks whether an attacker is already present; Carlier says human forensic specialists generally do not generalize much into offensive hacking. His broader call is to “pull out the jagged frontier” intentionally—building defensive datasets, environments and evaluations across cyber, biosecurity and AI safety before continual learning makes this opportunity less distinct.

Deep dive

1. AGI means replacing the remote worker, not winning isolated benchmarks

  • Carlier’s worldview predates ChatGPT: he joined the early Center for the Governance of AI team around 2020-2021, when advanced AI remained a niche concern. Asymmetric is another “big costly bet” premised on AGI; if that premise is wrong, he says the company could remain valuable, but “way less valuable” than under its intended future.

  • His operational definition is the “drop-in remote worker” that fully substitutes for humans across long-horizon tasks. Current models occupy a “weird jagged frontier of capabilities”: superhuman or “geniuses at some things,” yet unable to sustain enough coherent work to produce the sweeping economic effects he associates with AGI.

  • Labenz questions GDP as the scoreboard because his most impressive AI experiences have destroyed measured spending: software replaces work he otherwise would have hired someone to perform, often at dramatically lower prices. Carlier agrees that output is the more relevant measure; Labenz notes that abundant, cheap services could make dollar-based output difficult to interpret and might leave GDP flat or even lower.

2. Reinforcement learning may be sharpening the frontier unevenly

  • Labenz’s concrete jaggedness example comes from Claude Code with Opus 4.5: the model handles an extraordinary variety of work, then writes brittle Python heuristics for a transcript-backfilling task it could resolve by inspecting each file. His repeated instruction captures the gap: “Use your fluid intelligence. Just read the file.”

  • Carlier suspects reinforcement learning is a major cause. Pre-training absorbed much of the internet and delivered broad generality “kind of for free”; verifiable rewards now make coding and mathematics much easier to improve predictably than domains without clean scoring.

  • Without another major paradigm, he does not expect equivalent progress in something like poetry “for quite a while.” That unevenness creates a temporary opportunity to push selected defensive capabilities in ways that need not equally accelerate offensive ones.

3. Attack volume and attack consequence come from different adversaries

  • Carlier estimates that perhaps 80% of attacks come from relatively unsophisticated amateurs or financially motivated criminals. Their characteristic method is “spray and pray”: mass phishing, reused malicious programs and script-kiddie tooling directed at anyone likely to make a mistake.

  • Nation-states represent a small share of volume but pursue higher-value targets. His broad map has China focused heavily on Western R&D and IP, with AI “almost definitely” a major target; Russia emphasizes political disruption, including the 2016 US election; and North Korea seeks both secrets and revenue.

  • The North Korean remote-worker program combines infiltration with cash generation: operators obtain legitimate remote technology jobs, send money back to fund the regime and sometimes exfiltrate company IP. Labenz reduces the financial playbook to a dark joke: “Get the Brex card, get the Ramp card ASAP.”

  • Organized ransomware sits between amateurs and states. Attackers gain access, encrypt systems and announce themselves because payment requires discovery; sophisticated state operators instead try to “stay stealthy for as long as possible.”

4. Ransomware is massively negative-sum, while basic hygiene blocks most volume

  • Carlier cites a Jaguar Land Rover ransomware incident that halted operations for roughly one or two months and required a roughly $2 billion UK government loan to avoid collapse. He does not know the exact damage-to-ransom ratio, but says Labenz’s suggested order of 10:1 “sounds right”: the activity is “incredibly negative sum.”

  • Roughly 70-80% of attack volume is phishing or social engineering because attackers choose “the path of least resistance”; there is no reason to burn a valuable zero-day if a persuasive email works. Even technical attacks predominantly exploit known vulnerabilities that organizations simply have not patched.

  • For ordinary people and companies, MFA, regular updates, checking vendors’ security, automated monitoring and occasional compromise assessments go far against amateurs and some organized crime. Zero-days are rarer, mostly used by sophisticated actors and discussed far more often than their share of real-world attacks warrants.

  • Determined nation-state defense is a different regime: severe restrictions on software and hardware, unusually intrusive employee vetting, proactive zero-day hunting and constant compromise assessments. Some vetting might even be illegal in certain contexts, and most organizations accept ongoing intelligence theft rather than bear those costs.

5. Nation-state access is hard to observe and may persist for years

  • Asked whether he should take burner devices to China, Labenz argues he is merely a public “AI yapper,” not an obvious priority target. Carlier’s hedged answer is still stark: without precautions, people would “probably” read his material, and he should assume communications could remain monitored after returning home.

  • Persistence need not require a cinematic implant; it might come from physical access, compromised credentials or another mechanism. Carlier’s practical instruction is simply, “Assume they’ll have persistence,” while conceding that many ordinary travelers may decide the exposure is tolerable.

  • The apparent tension—why expend scarce zero-days on a middling target?—is unresolved because outsiders lack visibility into state arsenals. Carlier estimates that hundreds of thousands of people may contribute to CCP offensive capability, and notes that some forms of access were not publicly discovered until decades later.

6. AI is lowering the attacker skill threshold before changing attack types

  • Carlier sees little transformative offensive impact so far beyond better phishing automation. That may change imminently: laboratory measurements reportedly place models “on the precipice” of stronger offensive-security capabilities, although the feared step-change is “not coming online yet.”

  • His central mechanism is democratization. For any attack previously requiring moderate expertise—ransomware is the example—the model lowers the minimum sophistication needed, allowing far more actors to attempt it without necessarily inventing a novel exploit class.

  • Measuring that frontier is unusually difficult because real incident evidence is private. A compromised company will not publish its email logs, leaving model developers with “nothing to benchmark on” and little visibility into the attacks actually occurring.

  • Expertise is equally scarce. Carlier says CrowdStrike, among the leading incident-response firms, has only roughly 60 people capable of the deepest forensic investigations; frontier labs therefore need rare subject-matter experts merely to judge whether model answers are correct.

7. Static detection generates noise while missing patient intrusions

  • Existing monitoring systems largely encode static rules for suspicious behavior. The same signal may indicate compromise or ordinary life: a login from a new location could be an attacker, or “maybe you’re just traveling to Tibet this week”; late-night access and bulk downloads are similarly ambiguous.

  • The inverse failure is activity engineered to look normal. An attacker can exfiltrate tiny amounts over months, remaining below thresholds that would trigger conventional detection; a human investigator reasoning deeply across the full evidence might notice the pattern, but nobody has the time to do that continuously.

  • Security operations centers therefore triage alerts rapidly, discard false positives and reserve digital forensics for the minority judged genuinely suspicious. Forensics reconstructs entry, escalation, actions and persistence like detective work, but scarce experts make it too slow and “impossibly expensive” for routine proactive use.

  • Carlier’s alternative question is not which human workflow AI can automate, but what defenders would do with “100 x the intelligent labor at your disposal.” His answer is near-continuous forensic assessment, eventually approaching the cost of compute rather than remaining an emergency service after confirmed breaches.

8. Business email compromise is the tractable wedge into automated forensics

  • Asymmetric begins with business email compromise: an attacker acquires an account through phishing, stolen credentials or another route, then uses that trust to solicit money or information. The 2016 DNC breach illustrates that email attacks can serve political operations as well as straightforward financial theft.

  • Investigators ingest Microsoft or Google tenant logs, locate the first access and look for privilege escalation or movement into another account. Simultaneous logins from incompatible locations are useful evidence, but every anomaly must be evaluated within the user’s real behavior.

  • They then reconstruct what the attacker read, sent or deleted; whether inbox rules forwarded or concealed mail; which Drive files were accessed; whether persistence remains; and what caused the breach. The process has a sequence, yet advances through flexible judgments: “This looks funny. Let me pivot off this bit of evidence.”

  • Provider configuration materially changes incidence. Carlier thinks Google email compromises occur at least an order of magnitude less often than Microsoft’s; he cannot recall the exact cause, but describes it as a tractable difference Microsoft has bafflingly failed to close.

9. Ninety-percent automation still leaves humans guarding the nines

  • Asymmetric describes itself as a “full stack AI digital forensics and incident response company.” Its agent ingests logs and performs a first-pass investigation; human investigators usually quality-check its reasoning and materially change the result in a minority of cases.

  • On relatively simple email incidents, models with minimal scaffolding and no specialized training can reach something like 90% accuracy out of the box. That is already valuable for speed, but “totally insufficient” for autonomous delivery in a domain where the nines of reliability matter.

  • Labenz’s pushback—worth keeping—is that 90% of work completed does not imply a 90% time saving: the final 10% could consume half the original effort, while required reliability may be hard to measure. Carlier expects a “long tail of needing humans” to push up the nines, especially as investigations become more open-ended.

  • Reactive incident response contains little latent demand: after “you’re bleeding from the head, you need to deal with it,” but customers do not want substantially more reactive investigations. Proactive forensics could instead substitute for today’s detection market, worth a few hundred billion dollars and “maybe 500 billion,” with additional demand from AI labs and governments still uncertain.

10. Services, insurers and trust form the commercial flywheel

  • Labenz’s dentistry-versus-massages analogy separates fixed from elastic demand: nobody wants more dentistry merely because it is cheap, whereas nearly free massages might be consumed daily. Carlier says reactive response has limited latent demand, but sees continuous detection expanding where organizations protect unusually sensitive IP or national-security systems.

  • CrowdStrike provides the services-first precedent. Carlier says it began roughly 15 years ago as an incident-response provider, learning how attackers behaved and building enterprise relationships before productizing; in security, trust drives distribution because customers cannot answer, “Am I not attacked or do I just not know about it?”

  • Asymmetric’s immediate proof is reducing email investigations from roughly two days-to-a-week to a few hours. Carlier cites hourly billing and the fact that the relevant services market is small beside incumbents’ main detection businesses: he estimates it around $40 billion, compared with what he tentatively calls a roughly $200 billion CrowdStrike focused primarily on detection products.

  • Cyber insurers are the main route to customers. Carriers maintain pre-approved panels of incident-response firms and direct breached policyholders to them, so winning insurer trust generates crisis-time referrals and then direct enterprise relationships.

11. Real incidents can pull the defensive capability frontier outward

  • Asymmetric has hired investigators from CrowdStrike, Palo Alto Networks and other major security companies to work daily through cases using its AI platform. Their normal work becomes continuous model assessment, while observed incidents supply blueprints for “really high fidelity, really realistic” evaluations and training environments.

  • Defensive learning otherwise lags because sensitive incident data and qualified evaluators are scarce. Offensive evaluation has the opposite advantage: an agent can keep trying to hack something without needing sensitive customer data, providing a more direct way to test offensive capability.

  • The company’s technical sequence is deliberately conservative: test multiple models, take the “low hanging fruit out of the box,” add minimal scaffolding, build credible evaluations and only then consider fine-tuning or specialist models. Carlier would be “pretty shocked” if current systems performed nearly as well on more complex, long-horizon incidents.

  • Incident-derived evaluations and analysts’ reasoning traces could become a differentiated asset. Carlier is open to sharing evaluations—not delicate raw customer data—with foundation-model developers, because improved base models would gain “immediate instant distribution” across AI labs and governments; whether that sacrifices too much proprietary advantage remains an open question.

12. Digital forensics may be defense-biased enough to accelerate deliberately

  • Carlier draws on the alignment field’s “automated AI researcher” idea: instead of accepting capability progress as uniform, experts can curate datasets, evaluations and environments that “pull out the jagged frontier” toward cyber defense, biosecurity or selected AI-safety work.

  • He rejects the claim that all cybersecurity capability is inherently dual use. Penetration testing and vulnerability discovery can support either patching or exploitation, but digital forensics asks whether an attacker is already present and reconstructs what happened; it is a primarily defensive application.

  • Labenz expects human investigators to generalize into competent attackers because they know phishing methods and intrusion patterns. Carlier says that is “surprisingly” not what the labor market shows: forensic investigators and offensive white-hat hackers form distinct communities, with “not a ton of generalization” between them.

  • The opportunity may close once continual learning lets models acquire capabilities across the board rapidly. Labenz suggests that, until then, there is an opportunity to develop defense-biased capabilities; Carlier wants experts to catalog such tasks in multiple fields. His mask and vaccine-stockpiling examples are tentative, and he explicitly says he does not know biology well enough to offer a confident analogue.

13. Secure code cannot eliminate the need to detect successful breaches

  • Labenz proposes formal methods as another defensive flywheel: use formal verification as a reward signal so coding models eventually produce superhumanly secure software by default, reducing vulnerabilities before attackers encounter them. Carlier’s response is supportive—“People should totally do that”—but he doubts it could ever be sufficient.

  • Nation-states can enter through people, credentials, suppliers and operational systems, not only code defects. Strong hardening also reduces productivity: restricting how AI-lab employees interact with model weights may impede work even while reducing exfiltration risk, whereas automated forensics can run quietly in the background.

  • When Labenz catches Carlier calling hardening and detection substitutes, they refine the relationship: better detection can substitute for some hardening at a fixed security level, while deploying both makes them complements. The governing assumption remains that “stuff is going to get in.”

  • The envisioned endpoint is fully automated forensics across AI labs, the AGI supply chain, Western governments and systems such as autonomous weapon systems. Fewer breaches would remain undiscovered, and AI’s net cyber impact might favor defenders—but only if more teams treat defensive capability-shaping as “very tractable, very important to do” while time remains.