“Until now, security has fundamentally been a game favoring attackers. But thanks to artificial intelligence, defenders can now tirelessly scan vast amounts of attack code. For the first time, defenders are beginning to have capabilities on a scale comparable to attackers.”

In a written interview with Chosun Biz on the 7th, Microsoft Vice President Taesoo Kim (also a professor of computer science at Georgia Tech) made this assessment, stating that AI is fundamentally changing the cybersecurity game. He explained that within one to two years, an era will open where defenders with code can use AI to directly test attack scenarios and preemptively fix vulnerabilities.

Vice President Kim is a world-renowned authority in system security and AI-based cybersecurity who led “Team Atlanta” to first place globally at the AI Cyber Challenge (AIxCC) hosted by the U.S. Defense Advanced Research Projects Agency (DARPA) in 2025. He is currently on leave from his professorship at Georgia Tech, overseeing agent-based security research at Microsoft. He is scheduled to deliver a keynote speech at “Smart Cloud Show 2026,” South Korea’s largest tech conference, to be held at The Westin Josun Seoul in Sogong-dong on the 26th of this month.

The core of the change Vice President Kim is focusing on is that AI can become a “tool for restoring disappearing expertise,” going beyond a simple efficiency tool. “Code that no one can read is the most dangerous code,” he said, pointing out that “backbone networks, financial, and public systems contain a lot of legacy code where developers have already left the company or documentation is lacking.” Because AI can re-analyze this “code with no one left to read it,” it means that large-scale vulnerability audits, previously impossible, are becoming a reality.

However, Vice President Kim stressed that defense is not complete merely by finding many vulnerability candidates. “Discovery, verification, proof, and patching must be connected in a single loop to reduce false positives. A system is needed to confirm actual exploitability, set priorities, and take action,” he said. He warned that even if AI churns out thousands of vulnerability candidates, a new bottleneck could arise without a “closed loop” and prioritization system that verifies them and connects them to actual patches.

This philosophy is reflected in “M-DASH,” a vulnerability detection system recently unveiled by Microsoft. According to Vice President Kim, instead of entrusting judgment to a single massive model, M-DASH has a structure where multiple models and over 100 specialized agents divide roles to discover, verify, and confirm the reproducibility of vulnerabilities. This overcomes the limitations of a single model and can even find more complex structural vulnerabilities. “Going forward, AI security competition will hinge more on how to combine the strengths of each model and design a system suited to solving real problems, rather than simply securing the largest model,” he predicted. His advice is that South Korean security companies should also cultivate the capability to design efficient security systems by utilizing various AI models and agents, not just developing their own models.

Regarding the recent move by the U.S. government to restrict the release scope of Anthropic’s AI model “Mythos,” Vice President Kim urged a cautious approach. While the measure stems from concerns that AI could find software vulnerabilities faster than humans and be exploited for cyberattacks, he noted that limiting access only for defenders could create an asymmetry favoring attackers.

“Attackers will secure AI capabilities one way or another, so if only defenders’ access is restricted, it could create an asymmetry favoring attackers,” he said. “Rather than unconditionally blocking release, a sophisticated design is needed that broadly permits verified defensive use while controlling dangerous functions.” He added, “The U.S. has a much stronger tendency toward closure than China,” analyzing that “in a situation where no company or country has secured a stable, overwhelming lead, if the U.S. keeps closing off its technology while only Chinese technology opens up, there is a possibility that Chinese technology could become the benchmark for global research and development in the long term.”

His advice for South Korea was also specific. Vice President Kim identified “AI-based proactive auditing centered on legacy code” as the top priority for South Korea in responding to the Mythos situation. The idea is that defenders must apply AI to their own code before attackers analyze the system with AI. He explained that defenders should actively leverage their information advantage of knowing both the source code and the operating environment.

Second, he suggested building a closed loop from vulnerability discovery to patching, and finally, establishing a prioritization system to determine what to respond to first. “South Korea should also respond by building an integrated defense system that starts with AI-based proactive auditing and extends to verification, patching, and prioritization,” he emphasized.

Regarding the South Korean government’s push to develop its own independent AI foundation model, he pointed out, “I sympathize with the necessity, but it’s not a problem that ends with just making one model.” He added, “It is more important to have a defense system where defenders can first use AI to find, verify, and address vulnerabilities before attackers analyze our systems with AI.”

Vice President Kim also took a cautious stance on the South Korean government’s goal of becoming the “world’s 3rd in AI.” He noted that while the capabilities of South Korean-born security talent are second to none globally, the reality must be faced that talent is moving overseas where better compensation and research environments are offered. “Environmental differences exist for researching and advancing AI and security together,” he said. “What matters is how quickly a research and industrial ecosystem that can develop AI and security together is growing.”

To this end, Vice President Kim advised that policies are important for creating demand where the public and private sectors can verify and adopt new security technologies, and for expanding opportunities for security companies and researchers to solve real problems. “Whether in a company or academia, capabilities accumulate only when you can handle real systems and verify new technologies,” he stressed. “Policy direction must be geared toward creating a virtuous cycle where talent grows and the industry quickly absorbs those achievements.”

Vice President Kim also expressed an optimistic view on the competitiveness of South Korean companies. “If they combine proven defensive utilization capabilities, global collaboration, self-assessment ability, and industry-specific security operation experience, they can sufficiently create a competitive edge,” he said. “Ultimately, what matters is not whether you own a core model, but whether you have the operational systems and governance to safely utilize powerful AI.”

On the future of cybersecurity, Vice President Kim summarized, “An era has opened where attack and defense move at machine speed.” He also offered a forecast that AI must evolve to a stage where it conducts security research autonomously. The message is that amid the security paradigm shift AI will bring, the systems and governance operating it, rather than the model itself, will be the ultimate source of competitiveness.