When Safety Locks Leave Your Defences Without Their Best Weapon
You run a tight ship. Your business has firewalls, antivirus, maybe even an IT consultant on retainer. You feel safe from the cyber threats you hear about on the news. But what if the most powerful weapon your defenders have has been taken out of their hands?
That is the startling reality highlighted by a deep dive from TechCrunch. It reveals a growing tension: the AI models designed to help humanity are being locked down so tightly to stop “bad guys” that they are also crippling the “good guys” whose job is to protect you.
For a Malaysian SME owner, this isn’t just tech gossip. It is a fundamental shift in the balance of power between attackers and defenders. And right now, the defenders—specifically the ones who would protect a business your size—are losing the tools they need most.
TL;DR: AI companies like OpenAI and Anthropic have tightened safety restrictions (“guardrails”) on their top models to prevent malicious use. These restrictions are backfiring by stopping legitimate cybersecurity researchers from confirming vulnerabilities. This forces your local defenders to work with crippled tools, and worse, pushes them toward unregulated AI systems where your business data could be at risk.
What This Actually Means for Your Business
Imagine hiring the best security guard in the world, but you tell him he is not allowed to touch a weapon, use his radio to call for backup, or run after a thief. That is the situation offensive cybersecurity researchers find themselves in today.
These researchers proactively hunt for vulnerabilities in software before criminals do. Their job involves testing systems to their breaking point. When they ask an advanced AI for help, the AI often simply refuses.
“It’s like a hammer,” said Chris Anley, chief scientist at NCC Group, as reported by TechCrunch. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”
The same tool that can build an exploit can also find the fix. By locking the hammer away, the AI companies have made the house of global cybersecurity much harder to build.
How This Lockdown Hits Malaysian SMEs The Hardest
1. Your Local Defender Is Handicapped
The cybersecurity firms that serve Malaysian SMEs are rarely the ones with VIP access to programs like OpenAI’s Trusted Access for Cyber or Anthropic’s Cyber Verification Program. These vetted programs offer fewer guardrails. Your 5-person IT support company in Selangor is using the standard, heavily restricted model. The TechCrunch article quotes one researcher whose employer wasn’t in the vetted program, saying of the AI: “If it catches wind we’re doing anything security related, it just stops and isn’t usable.” Your defender is working with a broken tool.
2. The Invisible Patching Delay
When a security researcher finds a bug, they must confirm it is exploitable to prove its severity. Chris Anley noted in the article that asking an AI to “try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing.” If the AI refuses to play along, the confirmation takes longer, or doesn’t happen at all. The bug stays in your system. For a small business on a tight IT budget, you rely on this ecosystem to find and patch flaws in your accounting software, your payment gateway, or your e-commerce platform. If the ecosystem is choked, you stay exposed longer.
3. The Drift Towards Unregulated Tools
Because US frontier models are becoming too restrictive, researchers are voting with their feet. Chris Thompson, CEO of RemoteThreat, warned that researchers are getting “pushed toward Chinese open-source models like GLM” which have no guardrails at all. “You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said.
What does this mean for you? The tools being used to protect your data might be analyzing it without any ethical boundaries or safety standards. Your sensitive business data, customer lists, or financial reports could be processed by an AI system that isn’t bound by the same rules as a commercial provider. This creates a significant liability risk for you.
4. The False Comfort of “AI-Powered Security”
It is a flashy marketing phrase. But the AI powering your security might be a chained-down version. Paolo Stagno of CrowdFense told TechCrunch that AI companies “essentially treat customers like children who need babysitting.” Your security provider is trying to be a professional, but the AI treats them like a potential criminal. Instead of finding threats, they are negotiating with the model. Chris Thompson noted that instead of “analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” Your money isn’t being well spent.
Here is a clear picture of the gap forming in the market right now:
| Capability | Global Enterprise (Vetted Access) | Standard SME Defender |
|---|---|---|
| AI-Driven Exploit Analysis | Potentially Allowed | Strictly Blocked |
| Reverse Engineering Speed | Highly Boosted | Hindered by Refusals |
| Vulnerability Confirmation | Seamless | Manual or Blocked |
| Model Access Variety | Broad (incl. uncensored) | Narrow (public consumer) |
| Time Spent on “Negotiating” | Minimal | High / Mostly Wasted |
Practical Takeaways for Malaysian Business Owners
- Ask the hard question. When you next talk to your IT security provider, ask them: “What AI models do you use for vulnerability research? Do the guardrails on those models limit your effectiveness?”
- Don’t assume “AI” is superior. The hype around AI in cybersecurity is huge. Ask for specifics. How are they training their models? Are they hitting guardrails on prompt requests that stop their work?
- Demand transparency on data handling. If your provider uses open-source models locally, ask how they secure the data. If they use cloud models, ask if the data is used for future training.
- Invest in the basics. The current AI drama highlights a core truth. Multi-factor authentication, regular patching, and employee training are your bedrock. AI is a help, not a saviour. A guardrail-locked AI won’t stop a clever phishing call to your admin.
- Watch for the “Two-Tier” divide. Bigger companies will solve their AI access problems with money and contracts. You cannot assume the same level of AI firepower is defending your shop.
The Bigger Picture: A Storm Is Brewing
Chris Thompson captured the sentiment perfectly in the TechCrunch interview: “There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before.” The storm is AI-powered cyberattacks. The lightning rods are supposed to be AI-powered defenses. But if the best defense is locked in a gilded cage run by a handful of billion-dollar companies, the SMEs are just sitting in the open field.
This isn’t just a technical problem. It is a policy problem for everyone. The AI industry’s current model of “safety through restriction” is creating a two-tier security world. The rich and connected get the best AI defense. The rest of us—the entrepreneurs, the shopkeepers, the logistics operators—get a watered-down version that can barely help its users.
For now, the best protection is awareness. Know that your security tools might be artificially hamstrung. Hold your vendors accountable. And never underestimate your own human defenses. In a world where the AI robot gods are arguing over the rules, the sharp mind of a business owner who asks the right questions is still the strongest tool in the shop.
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
