Leadership Perspectives

The Cyber Defense Window Must Include Consumers

Why consumer Cyber Safety must be a central part of the collective defense against AI-powered attacks

Howie Xu's photo

Chief AI & Innovation Officer

Published

Read time

6 Minutes

The Cyber Defense Window Must Include Consumers

Written by

Chief AI & Innovation Officer

Published

Read time

6 Minutes

The Cyber Defense Window Must Include Consumers

    Related article

    Financial Safety 101 for Gen Z: Build It Before You Need It

    Share this article

    Last week, Gen joined more than 100 technology, cybersecurity and infrastructure companies, including Google, Microsoft, OpenAI and Anthropic, in calling for stronger collective cyber defenses before AI-powered attacks become dramatically more widespread and sophisticated.
    Gen is proud to be part of that effort; we also bring a distinct perspective to it.

    As a global leader in consumer Cyber Safety, Gen protects nearly 500 million people around the world through brands including Norton, Avast, LifeLock, and MoneyLion. We see what cyber risk looks like not only inside enterprises, but in the everyday digital lives of individuals and families. That matters because the AI cyber challenge will not stop at the enterprise boundary.

    The same forces highlighted in last week’s open letter will increasingly reach consumers, and consumers have far fewer resources to defend themselves.

    The letter makes three important calls to action: the security status quo will not be enough, defenders need access to powerful AI, and cyber defense has to become a collective effort.
    We strongly agree. And we believe consumer Cyber Safety needs to be a central part of that collective defense.

     

    The status quo will not be enough for consumers either

    Historically, sophisticated cyberattacks required expertise, time and money. That naturally concentrated attackers on higher-value targets.

    AI changes the economics. Attackers can increasingly automate research, personalize phishing, generate convincing text and images, clone voices, translate scams across languages and adapt attacks to individual victims at very low marginal cost.

    Sophistication is also becoming commoditized. That means attacks that once made economic sense primarily against enterprises or high-value individuals can increasingly be aimed at anyone. At Gen, we already see attackers moving closer to the systems and relationships consumers trust. Our latest threat research shows attacks increasingly hiding inside booking platforms, messaging conversations, legitimate accounts, software workflows and AI agents operating with permissions users themselves granted.

    For consumers, cybersecurity therefore has to evolve. Stopping malware remains essential. But Cyber Safety increasingly has to help answer much more fundamental questions: Is this person real? Is this message authentic? Can I trust this website? Should this AI agent have access to this information? Should this action be allowed to happen?

    Trust itself is becoming part of the security perimeter.

     

    Powerful defensive AI has to reach the consumer too

    The open letter calls for cyber-capable AI to be placed in the hands of defenders, and we strongly support that goal, but we should define “defender” broadly.

    A defender can be a security professional protecting a hospital, government agency or data center. It can also be technology protecting a parent from an AI-generated impersonation scam, stopping malicious code before an AI agent executes it, or preventing an autonomous agent from sending credentials somewhere it should not.

    Consumers cannot suddenly become cybersecurity experts simply because AI makes attacks more sophisticated. The technology has to do more of the defending for them.

    That is precisely why Gen began rolling out the Agent Trust Hub (ATH) earlier this year. ATH is designed as an independent security and trust layer around increasingly autonomous AI. It can evaluate agent capabilities before they run, observe agent behavior during execution and help stop dangerous actions in real time.

    We have since expanded that architecture through technologies including Sage, Agent Detection and Response, VPN for Agents, Norton AI Agent Protection and AARTS, our open standard for AI agent runtime safety.

    The goal is straightforward: protect consumers at the points where AI risk actually emerges, from the tools an agent uses to the commands it executes, the data it accesses and the networks it connects to. AI increasingly has to help defend us from AI.

     

    We need to prepare before emerging capabilities become common threats

    The urgency in the letter is important because AI capabilities are advancing extraordinarily quickly.

    Recently, OpenAI released detailed findings from a security incident involving OpenAI and Hugging Face infrastructure. During cybersecurity evaluations, highly capable experimental agents circumvented sandbox controls, found ways to reach the internet, exploited vulnerabilities and established unauthorized ways to communicate. OpenAI described the incident as a “warning shot.” These behaviors remain unusual today, and we should not exaggerate the current threat, but that is precisely why the industry has a window to act.

    We can now see capabilities emerging that could become much more consequential as AI systems become more autonomous, persistent and interconnected. The question is not whether every consumer faces this threat today, the question is whether we can build the defenses before they do.

     

    Collective defense must connect frontier AI to the consumer edge

    This is where Gen’s role in the coalition becomes especially important. Frontier AI companies see emerging model capabilities first, cloud and infrastructure companies understand the systems those models run on, and cybersecurity companies understand attackers, vulnerabilities and defensive controls.

    Meanwhile, governments can coordinate standards, intelligence and policy. What’s lacking across these is the consumer Cyber Safety perspective at global scale.
    We see what happens when new technology reaches hundreds of millions of people who do not have a CISO, a SOC or a security engineering team protecting them. All of these perspectives need to connect.

    That means sharing threat intelligence, defensive technologies and best practices. It means creating open standards rather than isolated security systems around individual AI platforms. And it means ensuring that breakthroughs in frontier cyber defense ultimately become protections that ordinary people can benefit from automatically.

    That is why Gen has been working across the AI ecosystem while also developing open approaches such as AARTS, designed to create a common way for security systems to understand what an AI agent is doing and intervene when necessary.

    Collective defense cannot stop at enterprise networks and critical infrastructure, it has to reach the consumer edge.

     

    The defenders’ window is open now

    Gen joined the call because we believe the central premise is right: AI will strengthen attackers, and AI can strengthen defenders even more. But that will happen only if the industry moves early, works together and ensures that the benefits of advanced cyber defense reach everyone.

    For Gen, protecting consumers is a critical part of that mission. Nearly 500 million people already trust Gen brands to help keep their digital lives safer. As AI becomes more autonomous and more deeply integrated into everyday life, that responsibility expands.

    We will need stronger AI for defenders, we will need independent trust layers around autonomous systems, and we will need shared intelligence and open standards.

    We also will need to treat consumer Cyber Safety as an essential part of the same collective defense mission protecting enterprises, governments and critical infrastructure.
    Gen is proud to stand with the more than 100 companies making that call. Now we need to make sure collective cyber defense protects everyone.
     

    More on this topic

    Chief AI & Innovation Officer

    Follow us for more