The Same Machine That Answers Questions Can Teach Attackers How to Ask Better Ones
Hatched by Ante Gojsalić
Jun 12, 2026
9 min read
3 views
73%
The Real Battle Is Not AI Versus Humans
What if the most important security problem in the age of AI is not that machines are getting smarter, but that they are getting better at reducing uncertainty? That sounds abstract until you notice the same capability sits at the center of two opposite uses of AI: retrieving the right information at the right moment, and exploiting the right weakness at the right moment.
That is the deeper tension. Question answering systems are built to turn messy knowledge into precise answers. Attack systems are built to turn messy human environments into precise opportunities. In both cases, the winning move is the same: find the smallest amount of relevant context and use it faster than anyone else.
This is why the rise of retrieval enhanced AI and the rise of AI powered attacks are not separate stories. They are mirror images. One is a knowledge amplifier. The other is an exploitation amplifier. And both are powered by the same core idea: better retrieval means better action.
Retrieval Is Not Just a Feature. It Is a Force Multiplier.
For a long time, people thought of AI as something like a clever parrot, a model that produced language without grounding. Retrieval changes that. When a system can look up a policy manual, a product database, a legal memo, or a support archive before answering, it stops hallucinating in the dark and starts operating with context.
That sounds like a narrow technical improvement, but it is actually a strategic shift. Retrieval gives a model three things that matter in any high stakes environment: precision, timeliness, and relevance. A raw model may know many things, but a retrieval augmented system knows what matters now, for this question, in this setting.
Think of the difference between a general physician and an emergency room doctor with instant access to your chart, lab history, medication list, and imaging. Both may be intelligent. Only one has the context needed to act safely. The same principle applies to AI systems in enterprises, customer support, and search.
Here is the key insight: retrieval is not merely about answering questions more accurately. It is about compressing the distance between a question and a decision. That compression is valuable to defenders. It is also valuable to attackers.
The Same Advantage That Helps Defenders Helps Attackers First
Security has always been asymmetric, but AI sharpens the asymmetry in a new way. Attackers do not need perfect models. They need enough capability to automate reconnaissance, impersonation, and adaptation at scale. Defenders, by contrast, must cover every channel, every employee, every policy, every endpoint, every exception.
That is why synthetic text, voice, and images matter so much. A phishing email used to require time, language skill, and a degree of psychological intuition. Now it can be generated in seconds, tailored to a job role, a company style, and a current event. A voice clone does not have to fool everyone. It only has to work on the one person who has authority to move money or reset access.
The danger is not just realism. It is throughput. AI lowers the cost of trying. If one attempt costs almost nothing, then attackers can test thousands of variations until one lands. That is the same dynamic that makes retrieval powerful in legitimate systems. Search enough, rank enough, and you find the answer that matters. Search enough human weaknesses, and you find the one that opens the door.
The unsettling truth is that AI does not simply make attacks better. It makes experimentation cheap.
That changes the economics of crime. Human fraudsters had to choose their targets carefully. AI enabled fraudsters can now industrialize curiosity. They can generate malware variants that slip past signature based systems, draft convincing lures for different demographics, and personalize deception at machine speed. The defender is still forced to be right every time. The attacker only has to be right once.
A Better Mental Model: AI as Context Compression
To understand why these two trends are so tightly linked, it helps to use a single mental model: AI is a context compression engine.
In a good retrieval system, the model compresses a large knowledge space into a tiny response that is relevant enough to be useful. In a malicious system, the model compresses a large target space into a tiny intervention that is relevant enough to work. The same mechanism operates in both cases. The difference lies in intent.
This model clarifies something important about defense. Many people imagine cybersecurity as a game of building walls. But in an AI mediated world, the battle is increasingly about who can contextualize faster. If an attacker can infer your organizational structure, social norms, vendors, terminology, and approval processes faster than you can verify identity and intent, they have already reduced your advantage.
That is why old security assumptions begin to fail. Traditional filters are built for static patterns. AI generated threats are dynamic. Traditional awareness training assumes a finite set of phishing styles. AI generated persuasion can adapt to tone, status, timing, and urgency. Traditional code scanning assumes that known bad code resembles known bad code. AI generated malware can produce infinite slightly different versions, each one nudging itself around the edges of detection.
The deeper issue is not that AI is making everything novel. It is that AI makes targeted variation cheap. And targeted variation is the secret of both effective search and effective attack.
The Real Vulnerability Is Not Technology, It Is Trust Infrastructure
If we focus only on models, we miss the broader point. AI attacks succeed because they exploit the infrastructure of trust that organizations already depend on. That includes human habits, approval workflows, shared language, urgency, hierarchy, and assumptions about who sounds legitimate.
Consider a familiar scenario. A finance manager receives a message from what appears to be the CEO, asking for an urgent wire transfer before a deal collapses. In the past, the scam depended on luck and imitation. Now it can be enriched with public data, recent company announcements, voice synthesis, and role specific language. The message is no longer generic. It is situated.
This is where retrieval and security intersect most sharply. Retrieval systems thrive when they can attach the right facts to the right prompt. Attackers thrive when they can attach the right facts to the right lie. In both cases, context is power.
The uncomfortable implication is that security can no longer be treated as a perimeter problem. The perimeter has become conversational. If a model can answer questions using internal documents, then it can also reveal internal logic if prompted improperly. If a company trains people to trust messages that sound familiar, then it has built a human retrieval system that attackers can query.
In the AI era, trust is no longer a feeling. It is an attack surface.
The New Security Principle: Verify Context, Not Just Content
Most security advice teaches us to inspect content. Does the email have suspicious grammar? Does the attachment look dangerous? Does the link point somewhere strange? Those checks still matter, but they are no longer enough. AI can make content look right.
A stronger principle is to verify context. Ask not only whether the message says the right thing, but whether it arrives through the right channel, at the right time, from the right authority, with the right process behind it. This is the same idea that makes retrieval systems trustworthy: an answer is only as good as the evidence attached to it.
Here is a practical analogy. Imagine a museum display label that looks authentic. If you only inspect the typography, you might be fooled. But if you verify the provenance, acquisition record, curatorial chain, and storage history, the deception becomes much harder. Security in an AI world should work the same way.
That means organizations need to move from content based trust to process based trust. Example: instead of believing an urgent payment request because it sounds like the CFO, require a second authenticated channel. Instead of trusting a support email because it includes accurate account details, verify through a known portal. Instead of allowing code changes because the request seems plausible, tie approvals to system enforced identity and provenance checks.
The goal is not to eliminate human judgment. It is to stop overloading judgment with tasks that can be fooled by synthetic realism.
How Defenders Should Think Differently
If attackers are using AI to search the space of weaknesses, defenders need to use AI to search the space of exposures. That means security teams should adopt a retrieval mindset of their own. They need systems that can surface the right policy, the right anomaly, the right dependency, and the right escalation path quickly enough to matter.
But there is a trap. Simply adding more AI to security does not solve the asymmetry. If the defender uses AI as a cosmetic layer while leaving workflows brittle, they have merely accelerated their own confusion. The better approach is to use AI to improve three specific capacities:
- Detection at scale: Spot unusual patterns across communications, code, access requests, and endpoints faster than humans can manually review.
- Verification by provenance: Attach identity, source, and change history to every sensitive action.
- Response compression: Turn a noisy incident into a small number of clear, executable steps.
This is the defensive mirror of retrieval augmented answering. A good question answering system does not drown the model in raw data. It retrieves the most relevant evidence. A good security system should not drown analysts in alerts. It should retrieve the most relevant signals.
That shift has organizational consequences. It rewards companies that know their own processes, document them clearly, and make exceptions rare. It punishes companies whose critical workflows depend on informal trust and ad hoc approvals. In other words, AI does not create security discipline, but it exposes whether it already exists.
Key Takeaways
- Treat context as the new perimeter. The real defense is not just filtering bad content. It is verifying provenance, channel, timing, and authority.
- Assume attackers will use AI for cheap experimentation. They do not need one perfect scam. They can run thousands of tailored ones.
- Shift from static trust to process based trust. Use out of band verification, signed requests, and enforced approval workflows for sensitive actions.
- Apply retrieval thinking to security operations. Surface the most relevant evidence, not more noise.
- Design for synthetic realism. If a fake email, voice, or document can look convincing, identity must be validated through systems, not intuition.
The Future Belongs to Systems That Can Prove, Not Just Claim
The tempting conclusion is that AI makes the world less trustworthy. The more useful conclusion is sharper: AI makes unverified trust untenable.
That is why retrieval augmented systems and AI driven threats belong in the same conversation. Both reveal that the decisive resource is not raw information, but the ability to bind information to context quickly and convincingly. In one case, that helps a system answer better. In the other, it helps an attacker deceive better.
The deepest shift is this: we are moving from a world where being convincing was enough to a world where being convincing must be accompanied by being provable. The organizations that thrive will not be the ones that merely sound intelligent. They will be the ones that can show their work.
So the next time you hear about a new AI feature that retrieves knowledge more effectively, ask a harder question. If a machine can find the right context to help you, who else can use the same power to find the right context to hurt you? The answer is not to slow innovation. It is to build systems, workflows, and habits that make context verifiable before it becomes actionable.
Sources
Hatch New Ideas with Glasp AI 🐣
Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)
Start Hatching 🐣