AGP Picks
View all

Heimdal CEO says defenders can’t wait for AI to slow down

12 hours ago
By AI, Created 10:37 UTC, Sep 30, 2026, AGP -

Heimdal CEO Jesper Frederiksen says frontier AI may be slowed by labs, but attackers will keep moving with open models and commercial tools. He ties the argument to new EU Cyber Resilience Act reporting rules and says security teams need tighter controls, clearer AI use and more transparency.

Why it matters: - Frederiksen says security teams cannot assume slower AI development will reduce attacks. - The stakes rise as AI tools make both offense and defense faster, while defenders still need accuracy, control and accountability. - The new EU Cyber Resilience Act reporting clock raises pressure on vendors to disclose actively exploited vulnerabilities quickly.

What happened: - Heimdal CEO Jesper Frederiksen responded to Anthropic CEO Dario Amodei's essay on pacing AI development. - Frederiksen published the piece, "Slow is a design principle, not a delay," one day after the essay appeared. - The article links the debate to the EU Cyber Resilience Act, whose vulnerability reporting obligations took effect on September 11. - On September 12, Amodei published his essay. - The Cyber Resilience Act now requires manufacturers of products with digital elements to send an early warning within 24 hours of learning about an actively exploited vulnerability. - The same rule requires a fuller notification within 72 hours.

The details: - Frederiksen says most security teams use digital products rather than make them, so the new reporting clock falls on the vendors those teams depend on. - He argues that technology is moving faster than the ability to understand, test and control it. - Frederiksen says attackers can already use open-weight models, commercial APIs and freely available orchestration tools. - Frederiksen says defenders do not get to choose their pace, so discipline has to come from security teams. - He points to an asymmetry in failure tolerance: an attack agent can fail often and still work if it can make thousands of cheap attempts. - A defensive agent that is wrong even 10% of the time can isolate the wrong device, revoke legitimate credentials or flood teams with false positives. - Frederiksen says better evaluations, clearer model behavior and stronger controls are defender requirements. - The article describes pacing as familiar security practice under other names. - Independent evaluators resemble separation of duties. - Capability gates resemble change control. - Staging before production mirrors standard deployment discipline. - Consequential actions should follow the four-eyes principle. - Frederiksen says Heimdal wants customers to know when AI is recommending and when it is acting. - Heimdal says consequential actions such as isolating hosts, revoking credentials and granting elevated privileges should follow the customer's own judgment on automation versus human approval. - Heimdal says customers should know which model providers are involved, which regions are used and what customer data leaves the environment. - Frederiksen adds that AI amplifies whoever has the data and the discipline to use it well, and it amplifies everyone else's mistakes just as fast. - The full article is available here.

Between the lines: - Frederiksen is framing AI pacing as a security governance issue, not just an AI policy issue. - The argument shifts attention from slowing model builders to tightening operational controls inside security teams. - The CRA reference suggests compliance deadlines and AI safety debates are converging in day-to-day cyber defense.

What's next: - Security vendors will face more pressure to document AI behavior, data flows and human oversight. - Defenders are likely to keep pushing for clearer evaluation standards and tighter approval gates before AI takes consequential actions. - The debate over AI pacing will probably continue, but Frederiksen argues the defensive response cannot wait for consensus at the frontier.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

EU Politics Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

EU Politics Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.