Security experts have a message for companies panicking about AI: calm down and go fix your basic infrastructure first.
At the HumanX AI conference, AI security researchers pushed back on the industry's fixation with existential AI risk. Their argument: the branding around AI threats generates more social media buzz than actual danger. The real exposure sits in known, unpatched problems that predate any chatbot - the stuff teams have been meaning to get to for years. Speakers framed this as a distraction problem, not a technology problem.
This matters because security budgets are finite, and attention is a budget too. Every hour spent war-gaming a hypothetical AI takeover is an hour not spent patching the vulnerability that's actually sitting open on a production server. The AI threat narrative is seductive precisely because it sounds futuristic and sells conference tickets - unpatched software does neither.
It's the same pattern security has seen with every hyped technology: the new thing gets the keynote slot, the old unglamorous debt gets ignored until it's the thing that actually gets exploited.