
Austin Slesinger (HackerOne) presents survey data showing the "AI security gap"—the spread between AI expansion and formal security testing—costs organizations ~$730,000/year, and outlines a five-layer framework to close it 2:23-3:02.
Key Takeaways:
• Of 303 security leaders, 94% expanded AI footprint in the past year but only 66% formally tested over 60% of AI systems—nearly a third left 40%+ untested 2:23-2:43.
• Those in the gap saw an 89% attack rate and $1.78M annual impact vs. $1.05M for those who closed it—a $730K/year savings 2:51-3:32.
• Each AI integration multiplies exposure: going from 2 to 8–10 systems correlates with 82% more attack touch and 2.4x financial impact 3:43-4:13.
• Testing is misaligned with threats: app/agent-layer risks are most attacked (51%) yet only 39% test them continuously 5:54-6:27.
• Mature programs layer five methods in parallel—production monitoring, automated adversarial testing, red teaming, OWASP-based pen testing, and crowdsourced testing; 67% of well-resourced teams use all five 6:37-7:39.
• Anthropic's example: pre-launch red teaming of Claude's classifiers (339 researchers, $55K bounties) plus public and private bug bounties 9:41-11:21.
A closing self-assessment checklist—visibility (only 55% track shadow AI), coverage breadth, and continuous cadence—helps organizations baseline their program 12:24-14:22.
Sources:
Thank you, CJ and Quentin. And the core principle he put forward that AI security is application security implemented outside the model is one of those things that sounds simple and is actually quite hard to operationalize, which is the gap we're going to dig into next. Because there's a meaningful difference between knowing AI security matters and actually knowing where your program stands. And that gap between awareness and validated confidence has a real dollar figure attached to it. Our next presenter is a solutions engineer at HackerOne, and he's going to walk through what closing that gap actually looks like in practice, including some data that might prompt a few of you to quietly update your testing strategy. Please welcome Austin Slesinger. >> Hey everyone. Thank you for being her…
Generate a professional CPE document from this video's transcript.