Skip to content

Who has the right to have an AI without guardrails?

Google is handing its most powerful model, without safeguards, to "trusted" defenders. The same tool protects and attacks. So who decides who gets it?

Advertisement

A locksmith can open any door. That's why you call one when you've lost your keys. It's also exactly what a burglar would dream of being able to do.

You don't hand a master key to just anyone. But you don't ban it either: without locksmiths, we'd all be locked out.

This week, Google faced the same dilemma, on a completely different scale. Its most powerful model, Gemini 4 Argon, is being handed over without cybersecurity safeguards to defenders deemed "trusted": governments, hospitals, telecommunications operators. One question demands an answer: who decides on that trust?

A tool that protects and attacks

The problem stems from a particularity of these tools. The same capability works in both directions. Finding a flaw in software lets you fix it, or exploit it. Understanding how an attack works lets you block it, or launch it.

It's an old dilemma. The chemistry that heals can poison. Knowledge of viruses that makes it possible to build a vaccine can also be used to cause harm. You can't build a good shield without understanding the sword.

Who decides, today?

Today, it's the company itself. Google chooses who enters its programme, according to criteria it does not detail. That raises three problems.

Power. A private company decides which governments, which hospitals, which operators deserve the most powerful tool of the moment. That is considerable power, exercised without anyone else being able to control it.

People. Trust is granted to institutions, but the tool is used by individuals. A disgruntled employee, a stolen account, and the trust placed in the organisation no longer protects anything. Microsoft's report reminded us of this again this week: stolen legitimate accounts are one of the main entry points for attackers.

Numbers. The longer the list of "trusted people" grows, the greater the risk that a copy slips out. A secret shared by a thousand people is no longer quite a secret.

When cryptography was a weapon of war 🔐
In France, until the late 1990s, the most powerful encryption tools were classified as war materiel. Their use was strictly controlled by the state, reserved for those it deemed worthy of trust. Then the rule was dropped, for a simple reason: with the internet, everyone needed to protect themselves, from banks to ordinary individuals. Encryption that was reserved for a few has become what now protects each of your online payments. The history of defence tools is often like that: reserved at first, shared afterwards.

Doing nothing is also a choice

It would be easy to conclude that everything should be blocked. That would be a mistake.

Attackers, for their part, wait for no one's authorisation. They are already using AI to move faster, and denying defenders the tools to respond would amount to leaving the door open. Keeping the tool under lock and key also has victims: hospitals whose flaw will not be fixed in time.

The real question is therefore not "should the tool be given out?", but "under what conditions?".

What would make that trust legitimate

A few simple principles would make a big difference. Public criteria, to know who can get in and why. Outside oversight, which does not depend on the company alone. A record of every use, so the thread can be traced back if something goes wrong. And the ability to revoke access, quickly, when something goes badly.

None of this is impossible. It is what is already expected of those who handle other dangerous tools, from powerful medicines to site explosives.

What we take away

A master key is neither good nor bad. Everything depends on the hand holding it, and on the way that hand was chosen.

It is not trust that makes a tool safe. It is the means of verifying that we were right to grant it.

Advertisement