The black box in AI just got bigger.
Not in the way most people think. A thread on why the iceberg metaphor for AI risk is wrong, and what the right frame changes for security and technology leaders. 🧵
The shift this forces for security and technology leaders:
The question is no longer just what is the model hiding.
It is whether there is anything real below the waterline at all.
For two decades, defenders operated with an invisible subsidy.
Serious vulnerability discovery was rare, expensive, and slow. Exploits were even slower.
That scarcity did a lot of quiet work. 🧵
I wrote up what that work actually looks like on The Critical Stack. Operating model changes, threat modeling changes, where defense in depth just got more valuable, and the KPI that now matters most.
If you run a security program, it is worth fifteen minutes.