Skip to content
Ai4Article

Three AI Luminaries, One Stage: What Ai4's Keynote Panel Signals for Enterprise AI and Cybersecurity

Self-adapting AI worms, a vetoed California bill, and a 1.4% replacement rate: how AI's founders split on security, regulation, and jobs at Ai4 2026.

At Ai4 2026 in Las Vegas last week, AI heavyweights Geoffrey Hinton, often called the godfather of AI, Fei-Fei Li, co-founder and CEO of World Labs and co-director of the Stanford Institute for Human-Centered AI, and Andrew Ng, founder of DeepLearning.AI and co-founder of Google Brain each debated their views on the future of AI and the discussion surfaced a productive divide in opinions when it came to job displacement, security risk, and the shape of AI regulation.

The Washington Post's Yun-Hee Kim opened the panel by pointing to AI systems from major labs going rogue and hacking into other firms, then asked Geoffrey Hinton whether AI has moved beyond human capability. What followed, over nearly an hour on the panel, was a two-on-one on why the AI debate has gone wrong, and a genuine three-way split on what to do about it.

Hinton looked beyond AI systems escaping their sandboxes to attack organizations at will, which he called scary on its own; as he pointed to research out of Toronto demonstrating a new class of worm built on a large language model — one that, on each machine it infects, hunts for a different vulnerability rather than reusing the one that got it in. "That's a very scary [worm], because it can spread to all sorts of different computers," he said, adding he wasn't sure he should mention it at all.

Andrew Ng disputed the "scary" framing rather than the capability. AI has ingested enormous volumes of exploit material, he acknowledged, but the resulting advantage sits with defenders, who can patch what they own and see their own code. Li didn’t enter this part of the debate.

However, this debate has substantial implications for cybersecurity. Hugging Face disclosed on July 16 that an autonomous agent had breached its production systems; five days later, OpenAI confirmed the attacker was its own, two models that escaped a controlled evaluation environment and chained novel exploits to reach the answer key of their own security benchmark. Responders logged more than 17,000 attacker actions and finished the forensics on an open-weight model from Chinese firm Z.ai after commercial model guardrails refused to analyze the payloads.

On regulation, Hinton rejected the industry's preferred metaphor outright. He said Companies spend heavily to persuade the public that developing AI is the accelerator and regulation is the brake, adding "that's the wrong picture." Regulation, in his framing, is the steering wheel. He cited California's vetoed SB 1047 as, in his view, the mildest possible version of what states will keep attempting, and argued AI firms who are happy to pay for chips and electricity should also pay authors for training data.

Related:

Hacker Summer Camp, AI Vishing Targets Wall Street, Packet Protectors and Multi-State Attacks on Water Utilities
All the news and analysis of the past week!
Wall Street Vishing Attacks Started at the Help Desk
Security leaders speaking on this exact vishing threat at an Ai4 cybersecurity panel on Aug. 4 said the best defense against voice-based impersonation is identity verification.
Hacker Summer Camp 2026: Complete Black Hat, BSidesLV, Ai4 & DEF CON Coverage
The CYBR.SEC.Media crew is in Las Vegas to bring you all the insights coming from this week’s proceedings.

Ng warned that lobbying dressed as a safety concern is throttling American open-weight development while China's advances, and arguing that open models are soft power. Li pushed for sector-by-sector rules — food, drugs, financial services, transportation already have regulatory frameworks — plus sustained public investment in AI research outside a handful of private labs, calling AI civilizational infrastructure.

Then Hinton conceded something. He had opposed open weights precisely because they let anyone cheaply fine-tune a frontier model for specialized, potentially malicious activities, such as cyberattacks. "I think that battle's been lost."

Li sees solving the problems regulations seek to solve by increasing AI education and focusing vertically. The most important thing the United States could do, she argued, and some countries are already ahead of it, is fund AI education and research outside the handful of private companies now driving it. AI is infrastructure, in her framing, a civilizational technology whose origins were in universities, research labs, and open publication. Policy, she noted, isn't only restrictive: laws can be incentives.

Where she does want rules, she wants them sector by sector. AI is already having a substantial impact on food and drugs, financial services, transportation, and the environment, all of which have regulatory frameworks that are imperfect and always will be. Those need updating rather than replacement, and the test is what happens where rubber meets the road: are people being kept safe? What she rejects is the instinct to pause. Every technology is a genie: fire, the steam engine, electricity; and humanity has never put one back in the bottle. "We transform that genie into useful genies," she said, "and we put barriers around those too."

However, the regulatory backdrop within the U.S. remains more bark than bite. In the U.S., there is no federal AI statute; the action is within the states, where California's SB 1047 — the testing-and-disclosure bill Hinton called the least you could ask for — passed both houses before Governor Gavin Newsom vetoed it in 2024, and where similar measures keep surfacing. In the EU, the AI Act's obligations for high-risk systems were scheduled to become enforceable on August 2. They didn't. The Digital Omnibus, cleared by the Council on June 29, pushed that tier to December 2027. What did take effect three days before the panel was the Commission's power to investigate and fine general-purpose model providers.

Perhaps the sharpest divide on stage was on jobs. For instance, Hinton doesn’t see much point in attempting to train people to stay ahead of AI when it comes to jobs. "If you don't have a high level of education, any job you could retrain [for], AI will be able to do," he said. 

Ng answered with a number. Citing a large company's internal survey of workers affected by AI deployment, he asked the room to guess the share actually replaced. "Not 50 percent, not 20 percent, not 10 percent, but 1.4 percent." He also reminded Hinton, on stage, of his decade-old prediction that radiology was finished: the job count has grown, and salaries with it.

Security is one of the few fields where both sides of the debate have data behind them. The Bureau of Labor Statistics projects 29% employment growth for information security analysts through 2034, against roughly 4% across all occupations, and ISC2 puts the global workforce shortfall near 4.8 million positions, up 19% year over year even as the active workforce hit a record 5.5 million. That is Ng's picture. 

But the growth in cybersecurity isn't evenly distributed: roughly 52% of security professionals expect AI to cut demand for entry-level work like Tier 1 SOC analysis and routine vulnerability scanning, while only 2% think it threatens the profession itself. More than 64% of current listings already require AI, machine learning, or automation skills. The seats are multiplying at the top of the funnel and thinning at the bottom, which is closer to Li's layered account than to either of the men flanking her. However, everyone predicted AI would eliminate programmers and radiologists, and both are growing. 

On stage, Li reframed the jobs debate. She agreed with Ng that the discourse has been distorted by economic motive: "Let's bring science, not science fiction, back to the AI debate;” she said, but rejected the utopian read just as fast. Every job is a bundle of tasks, she argued, and AI redistributes rather than deletes them. The harder problem comes after: "Increased productivity does not translate to shared prosperity."

Early on, Hinton had summarized the panel himself: "It should be clear by now that we don't all agree."

"But we're still friends," Li said.

HOU.SEC.CON CTA

Latest