Fighting AI Speed is Like Trying to Outswim Loch Ness Monster

Marcus Hutchins published a highly credentialed anti-hype AI risk piece. His conclusions read right to me. Credential Guard, LAPS, segmentation, automatic quarantine, credential rotation are the basics. The basics hold. None of it needs a model. All of it predates the marketing.

That being said I have to protest how he gets there. He argues against “machine speed” using the same mistake that the claim is built on.

Look at how he accepts CrowdStrike’s 29-minute average and 27-second fastest breakout as “solid numbers” and then rejects the 89% AI-enabled figure beside them. Well, that is the same Falcon telemetry, same press release, same selection bias, same, same. He takes what helps him, and leaves the rest, which is what every vendor does with that report. The end he arrives at seems ok, but his means are not.

His core claim, that attackers are not adopting generative AI, is a good example. It all rests on this:

It’s a rare vantage point, but having spent over a decade as a threat intelligence analyst, I’ve gotten to analyze the inner workings of plenty of threat actors’ infrastructure.

Probably true. And also completely unverifiable, which is his complaint about others. The prohibitionist drinks beer? A CISO cannot weigh Hutchins’ visibility against CrowdStrike’s because neither of them is open to inspection. That is how we lose science and end up in mythology, marketing fills the void. It has to be plausible, like a narwhal tooth invents the unicorn. The rebuttal however has to be provable with instruments that may be hard or impossible to get.

Then he prices the AISI Mythos evaluation at $8,000 to $42,000 per successful compromise and says a crew could hire humans for less. Mythos Preview is gated to roughly forty approved organisations, but it seems no crew can buy it at any price.

The actual available commodity baseline is what matters, which is why I have been publishing it since April. AISLE reproduced the showcase Mythos finding on eight of eight open-weight models, one at eleven cents per million tokens. I built Lyrik on Wirken and matched two flagship bugs from the Mythos system card for seventy five cents. Hutchins prices a model no attacker can buy, and then skips past the numbers that would answer his own question.

He says AI attacks are “extremely rare” and every one “makes headlines,” as if that could be proven, then names only PromptLock, a university project. That’s it?

I can think of two other cases. Anthropic’s GTG-1002 report of November 2025 claimed a Chinese state actor ran Claude Code against roughly thirty targets at 80 to 90 percent autonomy. Anthropic detected it, attributed it, wrote it up, and nobody corroborated. That is self-citation, should be panned as such, which Hutchins skips.

The second case has no lab in the loop. OALABS published full session logs in June of an amateur in Addis Ababa who used Opus 4.5 and Codex to breach at least fourteen companies by typing “recon this” and framing every prompt as an authorized red team. Three generations behind the frontier, a consumer subscription, a novice, fourteen networks. That is the machine-speed case as it actually exists, and it fits neither the vendor story nor the “attackers aren’t adopting” story. Hutchins leaves it out, and it would change his whole story.

His pre-AI window is a year too long too. He dates attacker access to generative AI at ChatGPT, 30 November 2022, and shows breakout times falling before it. GitHub Copilot went to public preview 29 June 2021. The GPT-3 API dropped its waitlist 18 November 2021. The trend is observable, and the date he gave it isn’t right.

I guess I remember it because it was late to me, given that in 2012 I gave a BSidesLV talk titled Big Data’s Fourth V: Or Why We’ll Never Find the Loch Ness Monster. Back then all the emerging intelligence technology was seeing only three Vs (volume, variety and velocity). The fourth, I started arguing, was vulnerability, the data itself as the attack vector. I called it Loch Ness to make a warning. An industry that cannot verify inputs will manufacture FUD, like a monster it can never confirm and never dismiss, sustained by the people who sell trinkets aroud the myth. That means when someone talks about machine speed, ask yourself if they are describing the current Nessie swim speed sighting.

Hutchins says the monster is a log, nothing to worry about. He uses the same photograph as the people who say it is a monster to make his point. I say neither can produce the data lake that would settle the question. The ranges, the telemetry, the model access belong to parties whose revenue depends on the sighting staying unresolved. The basics work because they presuppose the risks and do not depend on the answers.

The reason we keep having this argument is that everyone who could end it earns more by leaving it open.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.