Searchable transcript of GPT-Red: Can AI red teams stop prompt injections? — IBM Technology (31:30). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 GPT-Red does automated red teaming. ScamBuster does automated scam interception. Panelists, what do you think? Does that mean it's time to hand it all over to the bots? Kimmie, we'll start with you. No, it's not time to hand it over to the bots. Because who started the circle in the first place? I'm only ready to hand over cooking to the bots. If there's a tool for that, I'm all in.
00:22 I want to be different and say yes just because everyone said no. But no. Definitely no. Hello and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical takeaways that you can use. I'm your host, Matt Kosinski. And joining me this week, we've got Michelle Alvarez, manager, X-Force Strategic Threat Analysis.
00:51 We've got Nick Bradley, manager, X-Force Threat Intelligence and cat wrangler, and we've got Kimmie Farrington, security detection engineer. We're going to be talking about ScamBuster. It's an open source, tool that uses AI to scam the scammers. And we're going to be talking about the possible erosion of cybersecurity skills tied to some of these new AI tools.
01:09 But first, GPT-Red. OpenAI shared details last week of its internal automated red teaming model called GPT-Red. It's essentially trained to be a master prompt injector, and it performs even better than humans do. In one competition, for example, GPT-Red had an 84% success rate compared to 13% for human red teamers. OpenAI basically uses GPT-Red to red team its models, obviously, and then it uses those findings to train further models, which they say is why GPT 5.6 was so robust.
01:48 You know, to kind of illustrate the success they've had, there's a class of prompt injection attacks called fake chain of thought attacks. These were 95% effective on GPT 5.1, but they're only 10% effective on GPT 5.6. And they chalk that up to GPT-Red. Now, there's no suggestion that GPT-Red is going to come to the public ever. It's just a thing that OpenAI uses.
02:09 But I think it's still worth talking about AI red teaming in general, especially one that gets such good results. Kimmie, I'll start with you thoughts on AI red teaming, on setting the bots loose like this to test our systems. How do you feel about it? Well, I would say that it's not setting the bots loose necessarily, right? They have a configured mission that they're often, they're trying to solve.
02:33 Right? They're they're looking for ways in, they're, they're they're pretending to be a pen tester and they're very effective at it. That's awesome. The second part of that is OpenAI is using it to feed back into their models to, to make them more robust. And that is absolutely necessary in all models. So good job OpenAI. Michelle, how about you? How are you feeling about GPT-Red, about AI red teaming, the results that OpenAI has seen?
03:02 What's your take here? Yeah. So from what OpenAI has shared, I think the results suggest that models can now resist, or at least based on their evidence, many attacks that maybe previously succeeded at high rates. So I think any tools that are able to sort of lower, that attack rate against our AI systems could be very beneficial. Yeah. I think it's really telling that this is so successful with prompt injections in particular.
03:31 Right. Because this is a type of attack that ever since it was kind of formatted or formulated and developed, people have been saying, what do we do about this? How do we stop it? And this seems like maybe we're on to at least something that can go in that direction. Right? It was a pretty significant drop from, you know, 95% effective to 10% effective.
03:50 Nick, let's bring you in here, now. What are your thoughts on AI red teaming, GPT-Red, this conversation so far? Where are you going with it? Well, so first off, Matt, I expect nothing less than you to be flippant about your explanation of a question. I mean, I agree with everything that's been said so far, but what I will say is, I feel like this is the natural evolution of what we should have expected with frontier models doing what they do.
04:15 This, in my opinion, is almost like a specialist of frontier models, right? So instead of being a general practitioner, this is the brain surgeon or the heart surgeon. This one is specifically there to help with the LLMs being vulnerable to prompt injection. And that's what it does. It's not just another frontier model. It's very specialized, and I think it's the right direction to go.
04:40 Instead of having a jack of all trades. We have tools that, you know, focus on specific things that need to be remedied. But did anyone else jump on the idea that because it's so powerful for the good guys, it's going to be the immediate target for the bad guys? Yeah. Of course. Cobalt Strike, hello. I know like. Every time there is something developed for for for the greater good, it's definitely going to be used for the greater bad as well.
05:08 So it's just you have to go into it. 100%. Unfortunately, they have much more time to spend on focusing on how to use it for their goals than we do to defend ourselves from their goals. I agree, and I expect nothing less. I mean, it's going to continue to be the same race that we've been in since the start of this, and it's just going to continue. I think the Cobalt Strike, comparison is, is really apt, Kimmie.
05:34 And it's one that did not like jump to me when I was looking at this. But you're right. And Nick, as you put it, anything we develop for the good guys, the bad guys are going to develop something similar, right? They might not be able to get their hands on GPT-Red specifically, but they can make a master prompt injecting LLM of their own. Right. Like we can get there.
05:51 And especially we've been talking a lot recently about these increasingly sophisticated open-weight models like GLM-5.2, things that are becoming as good as the frontier models. But they're open. They're available with no safeguards. It seems like that's exactly the kind of thing you can adapt towards that end. But, you know, on the on the more positive side, maybe, potentially, one of the other things that's interesting here to me is the way that OpenAI contrasts GPT-Red with some of the other safety efforts we've
06:19 seen around models, kind of specifically contrasting it with classifiers. Right. One of the big kind of stories to come out of the release of Fable and Mythos was that, while Fable specifically, had these classifiers around it that would reject certain questions that were deemed, too risky, and some cybersecurity pros felt like it was too cautious, it rejected things that it shouldn't reject.
06:42 OpenAI kind of says like, hey, a red teaming model is a good way to bring in some safeguards without reducing the performance of the model. And I'm going to read a quote real quick from their release, because I think it explains it better than I could. "A model that does less is naturally harder to attack, but that is not useful robustness. Robustness gains come from better resistance to malicious instructions rather than refusing legitimate requests by default."
07:08 Michelle, I want to get your take there, on that angle. Do you feel like maybe this is like, a good way to build some safeguards without reducing usefulness for the rest of us? What are your thoughts? Yeah, I think there's always going to be a balance there between, user ability to interact with a tool and having those guardrails in place. Right. It's always a balance between security, and ethics and guardrails and governance.
07:36 And so I think being able to find a fine balance, there's going to be something that's going to be a challenge for some organizations. Well, you know, I mean, as long as it's got, you know, an end user license agreement on it, that says "meant for educational or red team purposes only" then you're good, right? 'Cause that works every time. You know, is that where you scroll and scroll and scroll and then check without reading?
08:00 Yes. It's that too. Well, hey, you know what? Can't the LLM read that for you? Now isn't that what it's supposed to do? But now, to close out this segment, folks, I just again, you know, GPT-Red is not a, it's not a publicly available thing. It's an internal tool. Only they have it. But I am wondering, given how we've seen the the sort of development here, the really good results that OpenAI has had, I'm wondering what the kind of takeaways are from the rest of us who aren't.
08:30 We don't have this model. But like, are there takeaways for us? Does this change anything for us or are we just kind of watching cool things OpenAI does? Kimmie, I'll start with you. What are your thoughts? Cheers to OpenAI. This is exactly what you should be doing with your model, right? This is what all model owners should be doing with their model.
08:45 You should be testing it. You should be poking it. You should be feeding that data back into it, making it more resilient. This was just prompt injections. That's a big pile. And it's wide open because words are code and code is words now, right? So how do you how do you rearrange the words to sneak through? But they've, but they've done a good job, I think of, of approaching that particular problem.
09:13 Now, are they going to start approaching some of the other problems? I mean, they've already found the vulnerabilities for us with the Fable and the Mythos, you know, so what's next? Yeah. And I think you're right, you know, prompt injections, they get a lot of the headlines because they're very interesting. They're new, but there are other issues. Right.
09:30 So it's like, do we develop those specialized tools? Like Nick said, you get a specialized model for each one of those different vulnerabilities. It could be a cool way to go. You know, I don't know. Nick, I hope I didn't take the words out of your mouth, though. Any takeaways here for the rest of us? Last thoughts on GPT-Red? I think that's spot on.
09:44 And again, it's it's the natural progression of things. And as we continue down this, this road that is learning everything we're going to be able to do with AI and not letting the bots have free rein, it's it's going to be like clearing the fog of war. It's it's all new for all of us. Yeah. And I do think again that that not free rein point is very, very important.
10:05 I'm glad folks are emphasizing it because this is this is a specialized application of this thing. It is not just set it and forget it pointed at the thing. Right. And that's that's how we're getting these good results. Michelle, close out the segment for us. Any last thoughts on GPT-Red here? I like what, you know, Nick and Kimmie had to kind of say with regards to the evolution of AI.
10:24 I mean, I do think it's another major advancement, or at least seemingly so based on what OpenAI has had to share so far. And but maybe it's not a final cure for prompt injection, but definitely steps towards, you know, something close to that. That's it for this, story here, folks, but the viewers and the listeners on YouTube, drop us a comment. Let us know your thoughts on GPT-Red, prompt injections, AI red teaming, any of the things we've said here today.
10:49 I do love to hear from you. I do read, I do respond, but we got to move on to our next story here. Folks. This is ScamBuster. Dark Reading published a fascinating story about this tool, ScamBuster. It's an open source tool that software engineer Laurent Giovanni he plans to unveil at the Black Hat Conference in August. ScamBuster uses an AI model to respond to scam emails, with the goal of basically scamming the scammer.
11:15 Right? Tricking them into thinking they've got a victim on the hook. But what it's actually doing is it's kind of subtly pumping the scammer for information about their tactics, their infrastructure, so it can feed that back to, you know, security teams, threat intelligence feeds, law enforcement, people who can use that to then go nab the scammer. I thought this was a really, really interesting, deployment of AI.
11:38 Talk about another specialized AI tool. Right? AI, sort of, you know, aiming outwards instead of at the model itself. But, Michelle, I'll start with you initial thoughts when you heard about ScamBuster, how are you feeling about this thing? Well, I like the name. I like the name ScamBuster. It has a nice ring to it. I can see, like, a maybe a jingle going with it.
11:57 And a commercial to to follow ScamBusters. And there you have it. Thanks, Kimmie. You should. You should sell that to them. Kimmie. No. I'm sorry. Go ahead. Well timed. So, yeah, I mean, my immediate thought, especially as I kind of read through and just see what can be gleaned, from this type of, tool in the interaction with attackers, is basically the threat intelligence.
12:24 The IOCs, like what type of infrastructure scammers are using, really intrigued me, of course, based on where I sit within X-Force Threat Intelligence. So I think that's a really great opportunity, to, work and collaborate with other organizations that are maybe also using or have the, potential future use of using ScamBuster in their organization, to see if we can't work together to see what we're gleaning from our various operations in talking with these scammers.
12:55 Absolutely. And I think a lot of people have been thinking about, you know, can LLMs play a role in addressing social engineering? And I've seen some, shall we say, less than convincing, takes on that. But this is the first one that I've seen where I've like, hey, you know what? Actually, maybe maybe that can do something here. Nick, I want to get your thoughts and especially, you know, to me, this seems like another one of those specialized models, applications you were talking about.
13:18 I'm wondering, do you see it in the same light, how are you feeling about ScamBuster? I definitely do, and the the little law enforcement officer hiding inside of me is just stoked to to hear about this, because hopefully something like this can. I know it's, very Beekeeper -esque, but I'd love to see this lead in that direction, right, where it builds the profiles, it investigates enough, it tracks them down, and then it can be turned over to law enforcement.
13:43 And somebody goes and kicks in a door and solves the problem, right? At least, at least let me dream. Let me dream. I like the idea. And, it kind of gives me a little bit of a throwback. A couple episodes ago of the Not the Situation Room podcast, I talked about a scammer that tried coming after me, not knowing who I was, and I had a little bit of fun playing with them as well.
14:08 And so taking this to the next level, it just makes me feel like what took us so long? Why did we wait this long to do something like this? Oh, because we didn't have AI before. So now, I'm all on board. I think anything we can do to shut these people down and make life harder for them is worth every minute or every token spent. Very good, very good.
14:29 Do you happen to offhand remember the episode number for that one? Because I'd love to, if people want to hear that story, I think it'd be fascinating to send them there. I think it was episode 39. Cool, folks, go, go look at Not the Situation Room. Episode 39. I'm going to go look because I want to hear about this story. Kimmie, let's, let's let's bring you in here.
14:48 Let's ask you your thoughts on ScamBuster. What does it look like to you? How are you feeling about this application of AI? The first thing I thought of was Nick. Because Nick is the kind of guy who would mess back with those people if they hit him up, and so, I find it perfectly normal that there is an episode about this already. I did think to myself, oh, there are certain number of people in my world that would, you know, take the time to mess with these people right back again.
15:12 They wouldn't have the benefit of collecting infrastructure information or any of the other sort of intel that that the ScamBuster tool specifically is going to be doing, which I think is fabulous, like it's the next level, right, of messing with the scammers. No. So yeah, I, I say, I say bravo, this is the sounds like a lot of fun. And, I hope that we get, good data out of it in the process, you know, and that, you know, that we do get to take some bad guys out of the system.
15:43 Of course, with all whack-a-mole systems, as soon as you hit one, another one pops up somewhere else. But, take a few. I'll do what I can do. Yeah. And I think that that also gestures towards one of the things that I thought was interesting about that was like, there are a lot of people who do like to try to be a scam buster on their own, right? But most of them aren't Nick.
16:01 They don't have those skills. Right? And so often the advice we give people is don't engage. Don't try to be a scam buster. You don't know what you're doing. I think it's kind of neat that this thing can, can, can do that work and get the benefit and, and maybe skirt some of those potential issues that like a person who's not as skilled as Nick, could get themselves into when they do this.
16:23 But that does also bring me to another question, which is like, you know, we talked last, segment about, you know, how anything we make for the good guys, the bad guys can get their hands on. Part of me does wonder, like, is there, do we need to be worried about, for example, somebody trying to prompt inject your own scam busting LLM. Like, is this something we need to think about as this sort of these tools are built?
16:44 Michelle, any any thoughts on your end there? Well, I'm not sure about that, but I did think about, you know, what if then also the scammers could use an AI agent to, weed out the AI agents that are responding, right. That so they've got their automated operations going. They hit an AI agent that's pretending to be a human, and they're like, no, we know that's not human because our AI agent is filtering those out.
17:14 So I mean, yes, everything is a double-edged sword that we talk about on this podcast. So, I wouldn't, I would fully expect that to happen. It does bring up the interesting idea of like, you know, a sort of endless conversation between an AI trying to scam an AI who's trying to scam back the AI, and then you've just got just a loop bloop bloop bloop bloop forever.
17:36 Which at least it's tying up like, resources. You know what I mean? Is a benefit. They already created that. They called it MoltBook. I do recall that it turned out some of those things weren't actually AI. But no, you're right. It requires some humans to get things going. You need a little prompt injection from the human. It's true, it's true. But no, I, I I'm wondering, you know, in that vein of, like, possible ways that this thing could be circumvented or misused or whatever.
18:06 Are there any thoughts on our end in terms of, like, what we'd like to see to make a tool like this work? Like, what are you hoping it can do? Nick any thoughts there on you? Like a wishlist, basically? What are you hoping something like this could do for you? Well, at the end, the goal overall is to be able to lower the amount of successful scammers out there, right?
18:25 If anything, at least just make it harder for them because, as I was reading through the article, I noticed some of the things that was, you know, attempting to do is very similar to what we do in threat intelligence, right? Build a bad actor group profile, everything you can learn about them to help track them down. What are their TTPs? I know it's not exactly applicable 1 to 1, right?
18:47 But what are, what are some IOCs that you can determine are related to the same group? Right. Because there could be multiple you know, different scam campaigns being run by the same group. Right? This one's trying to scam people through this method. This group is trying to scam people through that method. And so if we can do something to mitigate that, that would be great.
19:08 And I did take a second to look it up and make sure I was right, which I wasn't. It's episode it was episode 40, and the name of the episode is 'Would you kindly stop trying to scam me?' All right. I mean, that's that title should have told us all that that's what it was. But. Yeah, check out episode 40. But, Nick, I like that you point out this correlation kind of thing, the ability to kind of see connect, maybe some of the dots because, you know, it makes me think about these massive campaigns we've seen in the past,
19:36 you know, Scattered Lapsus Hunters, they were all the rage last summer, you know, and then they're doing all kinds of things all over the place, and and maybe something like this can help us see, oh, that attack over there and that attack over there that we thought were, you know, disconnected, they're actually connected as part of the same thing. So I like that.
19:51 Kimmie, any thoughts on your end in terms of like what you'd like to see from a tool like this, what you hope it could do? I would like to see a lowering of the volume of of scams in general. Yes. I'd like to see a few people go to jail. That'd be fantastic. But I, I, I'd really like, you know, I really like the idea of the intel collection and, and, you know, scamming the scammers in the background because they don't know that you're collecting their data, you know, like, kind of thing.
20:19 Yeah, absolutely. I just, I like I like the fact that somebody created this tool. This is great. I think all of us kind of see the the strong potential for something like this. And it's really neat. And so, you know, when it does actually arrive and it's going to be open source so people can use it, like, I think it's cool, and I hope people experiment with it, and maybe we'll revisit it on the show when, when people get their hands on it and talk about how it's working in practice.
20:39 But I got to move us along here, folks, to our final story for this week. This is a growing gap between skills and abilities in cybersecurity. This is based on a short essay for The Guardian by Bruce Schneier, in which he muses on the ways that AI has decoupled skills from abilities in cybersecurity. You know, in effect, you don't need to know all that much about computers to launch a devastating hack.
21:06 AI can do it for you. This isn't a new idea by any stretch of the imagination. We have talked about it before on this show, but the main reason I wanted to bring it up is I like this particular point that Schneier puts on it, and one of the kind of downsides of the, the deskilling of cybersecurity, if you will. This is a quote. It's a little bit long, but I think it's necessary to read.
21:26 "The thing about people with ability but no skill is that they are often outsiders, not part of any professional community, and not bound by any rules or norms. This phenomenon is much more general than in cybersecurity. Any doctor can tell you how to untraceably poison someone. Many virus researchers know how to create a bioweapon. Any bridge engineer can tell you how to place explosives to blow up a bridge.
21:49 The reason that murderous doctors and terrorist engineers are so rare is that the lengthy process of acquiring those skills also instills a moral and ethical code. If every random person has access to good poisoning advice, that puts us all in danger." I hadn't seen this take before, basically, that like, we're not just losing skills, we're we're losing a kind of moral code that you gain when you learn some of those skills even as like, a script kiddie who's messing around and that sort of thing.
22:14 I'm wondering, Nick, I'll ask you first, do you think, Schneier is on to something there that that that it's not just a loss of skill, but a loss of a kind of broader cybersecurity code of ethics almost? What's your take? I agree completely. Nothing given is respected. Right. And so they didn't have to go through what it took to earn those skills. And as he said, like in the in the process of earning those skills is where that moral compass or at least respect for the group that you work with comes into play.
22:45 But if you can just buy a, you know, ready-to-hack kit and go, you don't owe anybody. You don't owe anybody anything, nor do you care. And the point there, though, was I think it goes both ways. Because we're talking about on our front, we're talking about cybersecurity experts that can lose skill versus ability. Right. But this goes both ways, because you're also going to have bad actors that only know how to use what they bought.
23:12 They aren't going to know how to do anything else outside of that. They only have ability. They have no skill. I that's an interesting spin on on that. And it's almost like, follow up question for you there because I like this. Do you think that that makes them more dangerous or less dangerous, you know, to have kind of ability without skill? Or maybe it's the same with just a different style of attack.
23:31 Any, any takes there? I actually think it makes them less dangerous because they don't know what they're doing, and so they're going to probably get themselves caught a lot easier. I'm more I'm more than open to an argument to that thought line of thinking, but because I can make it, I can make an argument for both. But I really think it makes them less dangerous.
23:53 I would go the other way. I would say that it would make them more dangerous personally, because they don't know what they're doing. And so there's a high probability that they're going to kick something off that causes chaos that they don't know they're going to cause. Now, if you're a bad guy and your goal is to cause chaos, then no problem. But again, you are more dangerous than you were before.
24:13 But going into the argument of, built-in moral code because you went through the certifications of learning a thing. I would I would argue that those two things are not necessarily married, that humans come with moral code and the concept of ethics. AIs do not. We have to build that into them. Right. Schneier says that we gain the moral code and the ethics while we go through the certification process.
24:43 I say we come with them. Some people throw them out the window already. Some people have no moral code and ethics, and they will use the tools in a bad way. Right. So, but but does that but is that, an argument for skill and ability? I mean, I don't know, I just, I think that I think that he has, made, made an argument that isn't necessarily true. I see both of those takes, like, I, I'm not sure where I land any more on it because you both brought up some very good points, Michelle, though, I want to bring you in here.
25:16 People aren't tuning in to hear me. They're tuning in to hear you folks. What are your thoughts here on on the discussion so far? Schneier's takes, Kimmie and Nick, what are your thoughts? Yeah, I think clearly there can be, like multiple branches that stem, from this piece and a lots of different thoughts. And I agree with Kimmie with regards to like, I think, you know, you start out with a certain, code of values, morals, and that sort of, you know, dictates like what you do.
25:47 And so if you're in cybersecurity or if you're not or if you're, you know, contemplating leveraging something to do something bad, I think that would have an influence whether or not you do that. But I think where maybe there's like a, a little bit of a gray line is, you know, oftentimes you have individuals that, are inherently good, but maybe they do something that's not quite good.
26:14 And so I can see where, like, someone that's, maybe down on their luck, and they're struggling and they see this as possibly a means to a way out. And so they just dabble in a phishing scam, right? They wouldn't have normally had the ability to do so. But now with AI, they might try it. And not that they would make a lifelong cybercriminal career out of it, but it's something that they might do and where they otherwise maybe wouldn't have had the opportunity, or maybe I shouldn't use the word opportunity.
26:49 But you know what I mean. Ability versus skill again. Right. You know, the skill comes with the AI. The AI says, I can do this for you. The ability was I didn't actually know what I was doing when I started. I wouldn't have come up with this idea on my own. But I got an opportunity, so to speak. Now, you know? So I'm taking it. I think the the differences, the different opinions that we've put out here all have value.
27:17 But I think the one thing that is the same across the board is the the chasm between skill and ability still continues to widen, regardless of what our opinion is. And it's going to affect us on the cybersecurity, you know, good guy side same as it is going to affect them on the bad guy side, because they're also going to lose skill while, AI is giving them abilities they wouldn't have had, they didn't have to learn because it's going to just do it for them.
27:49 Same on our side. I can red team a little bit here. I can blue team a little bit here, and I didn't have the skill, but I got the ability because the AI can do it for me. And what happens when I've got to do something the AI can't do? Okay, now I'm lost. Same for them. What happens when what they're trying to do doesn't work and the AI doesn't accomplish it for them.
28:07 They don't have the skill required to fill the gap and fix it. So the conundrum is going to affect us across the board. I like that you you frame it on that. Right. Nick, that was a really good way to put it of like, hey, look, we can have all the opinions we want, but like the gap does exist and it's going to keep growing. Right. And so to kind of round out the show, then my question to you folks becomes like, so what?
28:27 What is the so what for us? This gap is growing. You know, it is. We are going to have to deal with it on both sides. Like Nick said, attackers and defenders. What does it mean for us, if anything? Kimmie, I'll start with you. You know, what's the what's the so what here? What's the takeaway? The so what is we got to continue to keep up our personal skills, as much as we.
28:48 Okay. Yes. We have AI, and AI can do things beyond what we originally could do. If you don't keep up with it, if you don't know what it's doing for you, you're just going to be dangerous. That's all there is to it. So I personally, I gotta skill up. I gotta like, I, you know, I have AI doing things for me and I'm like, is that right? I don't know. Oh, shoot.
29:10 There was like a basic rule of thumb that, that Ian Molloy kind of posed on the last episode we did where he was like, would you still be able to do your job if someone suddenly took away your AI? Right. Like, you should still have the skills necessary, so that even if the AI makes you better at your work, and you use it for that, and you should, you should know enough about it.
29:28 Like if the AI suddenly disappeared, you could still do your job. And I kind of like that is like a rule of thumb. And I think that aligns a lot with what you're saying there, Kimmie. Michelle, how about you? Any kind of, you know, what's the takeaway? What's the so what here for the rest of us? I just immediately thought, would I know if that's grammatically correct?
29:43 The answer the answer is definitively sometimes. Maybe. Did I use the Oxford comma in the right way? Thank goodness for AI for that. So, yeah, I mean, I think I believe all of us on this show, have been in this industry, in our careers, long enough where this doesn't impact us as much as it does the newer entry-level individuals coming to the career right now.
30:17 And so, you know, this is something I think obviously we should think about it as well. But I think it's really something for them to, you know, sort of contemplate and ask themselves, do I have the foundation? And if, if so, you know, then I can kind of move to that next level. And if you don't, really, network and talk to people in your organization and your industry to make sure that you can fill those gaps, with or without AI.
30:46 I love that. I love that. Nick, close out the show for us. What are your final thoughts here? What's the takeaway for everyone? Don't let AI make you lazy. Use AI for what its intent. What it was intended. And that's to be a force multiplier, not a replacement. I love it, folks. That does it for this episode. Thank you to our panelists, Nick and Kimmie and Michelle.
31:05 Thank you to the viewers and listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found, stay safe out there. And remember, at the top of the show we asked, is it time to hand things over to the bots? I think the resounding answer here is no. No.
Yes, AI red teams can substantially reduce prompt injection success, but they cannot stop prompt injections completely and require specialized, controlled use.
A model that does less is naturally harder to attack, but that is not useful robustness.
Don't let AI make you lazy.
Software engineer planning to unveil ScamBuster at the Black Hat Conference in August.
11:04Author of a Guardian essay about AI decoupling cybersecurity skills from abilities.
21:56Referenced as the source of a rule of thumb about retaining the ability to work without AI.
29:12