The Hidden Battle Behind AI: Who Gets to Search, and Who Gets to Attack
Hatched by Ante Gojsalić
Aug 02, 2026
10 min read
1 views
86%
The uncomfortable truth about AI is not that it is getting smarter
The bigger question is: who gets to use that intelligence faster, cheaper, and at scale? That is where the real power lies. We tend to imagine AI as a single technological leap, a kind of universal upgrade that makes everyone better at everything. But in practice, AI arrives as an uneven weapon, a patch of infrastructure, and a cost multiplier, all at once.
That is why two seemingly different developments belong in the same conversation. On one side, semantic embedding APIs are changing how search systems retrieve information, promising better relevance, multilingual reach, and cheaper performance when used carefully. On the other side, generative AI is lowering the cost of deception, automating phishing, accelerating malware variation, and widening the attacker advantage. Both are really about access to cognitive leverage.
The deepest tension is not “AI good or AI bad.” It is this: when intelligence becomes a service, the first-order question is no longer what it can do, but what incentives it amplifies. Search can become more precise. Fraud can become more scalable. The same tooling that helps a user find the right document can also help an attacker find the right lie.
AI is not one technology. It is a layer that magnifies intent
A useful way to think about modern AI is as a force multiplier for human intent. It does not merely replace labor. It compresses the gap between intention and execution. If you want to retrieve meaning from a corpus of documents, AI can help you map language into vectors and search semantically rather than literally. If you want to trick someone into clicking a link, AI can help you write a convincing message in the right tone, in the right language, with fewer errors and at larger scale.
This matters because systems of power are often won not by the most advanced tools, but by the side that can deploy them repeatedly at the lowest cost. In search, that means ranking quality, multilingual robustness, and budget. In security, that means phishing volume, code generation, polymorphism, and the ability to overwhelm defenses. The same underlying trend appears in both domains: automation reduces the cost of judgment, then increases the scale of action.
Think of the difference between a telescope and a counterfeit press. A telescope extends vision. A counterfeit press extends deception. AI can act like either, depending on the hands that hold it. The question is not whether the tool is neutral, because no operational tool is neutral once it becomes cheap enough to repeat. The real issue is which capabilities get commoditized first.
When intelligence is abundant, the scarce resource becomes trust.
That insight connects search and security more tightly than it first appears. Search is a trust problem disguised as an information problem. Security is a trust problem disguised as a technical problem. Both depend on distinguishing signal from noise. Both are vulnerable when synthetic output becomes cheap and convincing.
Why retrieval and deception are secretly the same arms race
At first glance, improving search retrieval and improving phishing attacks seem unrelated. One is about helping people find relevant information. The other is about helping criminals impersonate relevance. But under the hood, both are optimization problems over human attention.
A good search system tries to answer: what is the user likely meaning, even if their words are imperfect? A good phishing attack asks: what message will this target interpret as legitimate, even if it is false? In both cases, the winning strategy is not literal match, but semantic alignment. The difference is ethical, not mechanical.
This is why semantic embeddings are so consequential. They do not simply match keywords. They represent meaning in a way that can surface relevant documents across wording differences, domains, and languages. That is an extraordinary capability for retrieval, especially when combined with a cheap first pass like BM25 and a re-ranker that refines the results. But that same semantic sophistication can also make synthetic content more adaptive. The better systems become at understanding context, the better malicious systems become at mimicking it.
Consider a concrete analogy. Imagine a librarian who can instantly understand the intent behind a vague request like “that paper about fraud in banking from last year.” In the hands of a researcher, that is magic. In the hands of an impersonator, the same capability helps craft an email that sounds exactly like the bank, the regulator, or the colleague the victim expects to hear from.
This is where the attacker-defender asymmetry becomes stark. Defenders must get many things right simultaneously: filtering, triage, education, anomaly detection, incident response, and systems hardening. Attackers need only one convincing path through the gate. AI helps attackers generate many paths cheaply, which means the probability of one succeeding rises sharply. The industrialization of language is therefore also the industrialization of persuasion.
The hidden lesson of embeddings: precision is valuable, but only inside a strategy
One of the most practical lessons from retrieval systems is that the best tool is not always the most powerful one, but the most appropriately placed one. A semantically rich embedding model is not automatically the best first-stage retriever. In some settings, a simpler lexical filter like BM25 does a better and cheaper job of narrowing candidates, after which the embedding API can act as a re-ranker.
This is a deeper design principle than it first sounds. It suggests that intelligence systems should be built as chains of responsibility, not monoliths of intelligence. A cheap filter does broad, rough work. A semantic model does narrow, expensive work. The architecture is effective because it reserves high-cost cognition for the cases where it matters most.
That same principle should reshape security. Too many defensive strategies behave as though every threat must be met with maximal sophistication everywhere. But resilience often comes from layered triage: coarse filters, contextual verification, human escalation, and targeted high-attention analysis. The metaphor is not a single genius guard at the door. It is a security funnel, where cheap screening blocks the obvious, and expensive scrutiny handles the subtle.
This is also why multilingual retrieval and multilingual fraud are two sides of the same coin. A semantic model that performs well across languages can help a global organization retrieve documents for a Spanish-speaking employee in Mexico or a French-speaking analyst in Montreal. The very same cross-linguistic fluency also lowers the barrier for attackers to scale convincing social engineering across borders. When language barriers fall, both access and abuse expand.
The practical implication is sobering: you do not get the benefits of universal semantic intelligence without also getting universal semantic misuse. The answer is not to reject the technology. The answer is to design for the full cost of deployment, not just the upside.
The strategic problem is asymmetry, not capability
The most dangerous misconception about AI security is that the future will be determined by who has the most advanced model. In reality, the more important question is who can integrate moderate intelligence into repeatable workflows faster.
Attackers excel when three conditions converge:
- Low marginal cost per attempt.
- High plausibility of output.
- Large-scale variation across targets.
Generative AI is tailor-made for this combination. It can produce endless versions of a phishing message, test tone and vocabulary, adapt to language and region, and generate malicious code variants that evade brittle signature-based defenses. No single attack needs to be perfect if a million attempts can be launched cheaply.
Defenders face a different geometry. They must maintain broad coverage, avoid false positives, preserve user experience, and keep systems affordable. That is why the most effective defensive posture is not to mirror attacker complexity everywhere. It is to reduce the surface area of trust. If a system requires less blind trust from users, then the attacker has fewer seams to exploit.
For example, an employee who is trained to verify payment changes through a second channel is not relying on language fluency to detect deception. A retrieval system that re-ranks search results rather than trusting semantic similarity alone is not relying on a single representation of meaning. In both cases, the defense works by making a cheap imitation insufficient.
The best defense is often not better detection. It is fewer opportunities for a convincing lie to matter.
That framing changes how we should build AI systems inside organizations. The goal is not just to improve accuracy. The goal is to decide where semantic intelligence is permitted to act autonomously, where it must be confirmed, and where it should remain advisory only.
A better mental model: AI should be treated like electricity with circuit breakers
Electricity is useful because it is everywhere, but we do not wire every appliance directly to the source without protection. We use circuits, breakers, insulation, and fuses. We assume overloads will happen. We design for failures.
AI deserves the same mindset.
Semantic retrieval should not be treated as an oracle that gets dropped into every search pipeline and trusted blindly. It should be placed inside a system that understands cost, domain, language, and error tolerance. Likewise, generative AI should not be treated as a harmless productivity layer just because it is easy to use. It should be assumed that hostile actors will use the same primitives to generate scale, camouflage, and variation.
This suggests a three-layer governance model for AI deployment:
- Access control: Who can use the model, and under what conditions?
- Decision control: What actions can the model trigger without human confirmation?
- Exposure control: How much trust does the system place in outputs from model-generated content?
Search and security both need all three. In search, access control determines who can query what. Decision control determines whether a retrieval result can auto-populate, auto-summarize, or auto-answer. Exposure control determines how much confidence the system assigns to semantically similar but potentially misleading content.
In security, access control limits who can send high-risk requests or receive privileged responses. Decision control determines whether a suspicious action is blocked, flagged, or allowed. Exposure control determines how much trust a human should place in an email, voice call, code snippet, or document that merely sounds right.
The point is not to eliminate automation. It is to localize it. The more powerful the model, the more important it becomes to define where it may speak, where it may suggest, and where it may act.
Key Takeaways
-
Treat AI as a force multiplier, not a standalone miracle. Ask what it lowers the cost of: finding information, generating content, impersonating trust, or detecting threats.
-
Use layered systems, not single-model trust. In search, simple filters plus semantic re-ranking often outperform a single expensive retrieval step. In security, layered verification outperforms a single point of detection.
-
Assume attacker adoption will outpace defender adaptation. Build systems that degrade gracefully when synthetic text, voice, or code becomes abundant.
-
Reduce the surface area of trust. Require verification for money movement, identity changes, and high-impact actions. Do not let persuasive output become automatic authority.
-
Optimize for cost of misuse, not just quality of use. A system is safer when it is expensive to abuse, not merely when it is accurate in benign conditions.
The real race is not between humans and machines. It is between trust and imitation
The most revealing connection between semantic search and AI-driven security threats is that both expose the same fragility: modern systems increasingly depend on making fast judgments about meaning. That is efficient, but it is also exploitable. Once machines can model meaning well enough to retrieve, summarize, persuade, and imitate, the boundary between helpful intelligence and harmful intelligence becomes a matter of deployment rather than capability.
So the question is not whether we should slow down AI. The question is whether we can build institutions, interfaces, and verification layers that make synthetic intelligence hard to abuse at scale while still letting it help us find what matters. That is the real design challenge of this era.
In the end, the future will not belong to the most intelligent models. It will belong to the systems that know where intelligence should not be trusted too quickly.
Sources
Hatch New Ideas with Glasp AI 🐣
Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)
Start Hatching 🐣