The Quiet Reason AI Might Make You Less Safe, Not More, and the $60M Bet to Reverse It
Image Credit: Corma
A cybersecurity startup called Corma launched this week with $60 million from Sequoia Capital and a single, unsettling claim: the same AI making your company faster is arming your attackers faster than it’s arming your defenders. They call the widening space between the two the “Defensive Gap,” and closing it may be one of the defining security problems of the decade.
Here is a pattern we’ve watched build across nearly every cybersecurity company we’ve covered this year.
Across launch after launch, the same quiet admission keeps surfacing: the old way of doing security, bolting protections onto finished systems, catching threats after they appear, cannot keep up anymore. Dawnguard framed it as security that has to be designed in from the first line of code. Glow framed it as the impossibility of protecting an organization you can’t even fully see, now that employees install AI tools faster than anyone can review them. StirlingX framed it as sovereignty, the need to control your own data in contested environments.
Corma, which launched on August 10, 2026, has framed it in the most fundamental way yet. And once you see their framing, the others start to look like symptoms of the same underlying disease.
The story in one uncomfortable sentence
Offense is compounding. Defense is not.
That’s the whole thing. Everything else is detail.
To understand why it should worry you, sit with what AI has actually gotten good at over the past two years. Modern models are exceptional at reading code, reasoning through complex software, and chaining tools across multi-step tasks. If you’re a software team, that’s a productivity story. If you’re an attacker, it’s the same story, because finding and exploiting a vulnerability is, at its core, a code-reasoning problem run against a bounded target. Every capability that helps your engineers ship faster helps an adversary break in faster. And it compounds with every model release.
Now look at what defending an organization actually requires: continuously reading enormous volumes of logs, events, and network flows; connecting faint, scattered signals across many systems over months; and making thousands of consistent, correct decisions a day as conditions shift underneath you. Those are not code-reasoning problems. They’re a different, harder shape of intelligence, and general AI models have not improved at them nearly as fast.
So the two curves diverge. Offensive capability climbs steeply with each model generation. Defensive capability crawls. The space between them, the Defensive Gap, is exactly where breaches will live.
And here’s the part that should end any comfortable “we’ll just hire more security people” response: you can’t hire your way across it. No human team, at any size, defends at the speed and scale of an AI-driven attacker. Corma’s founders are blunt about this, and on the logic, they’re hard to argue with.
The moment the gap stopped being theoretical
For a while, this was a concern you could file under “eventually.” Then the evidence started arriving.
Corma points directly to Anthropic’s Mythos disclosure, in which an AI system was shown capable of running end-to-end attack chains, not just assisting a human attacker, but executing the full sequence.
That is the line between an interesting theory and a funded, generational mission. Once machines can attack autonomously, “defense will catch up on its own” stops being a plan.
What Corma is actually building, and what to believe
Most companies would take a powerful general model and fine-tune it for security. Corma is doing something harder and more interesting: training defense-specific foundation models from first principles, built to read the raw material of defense, logs, events, network flows, as fluently as a general model reads English or Python. They describe deploying it as a “superintelligent security workforce” that runs alongside human teams rather than replacing them.
The company says this model already outperforms every general frontier model on defensive tasks, and is already protecting Fortune 100 companies across healthcare, finance, critical infrastructure, and retail.
Here’s where we apply the skepticism any serious reader should. Those results are self-reported. Independent, standardized benchmarks for defensive cybersecurity intelligence barely exist yet, which is part of what makes the problem so hard, and the hardest technical claims sit ahead of Corma, not behind it. A first-principles foundation model for defense is an enormous undertaking with real odds of falling short. The idea is sharp. The proof is early. Both things are true.
Why this matters even if you never buy Corma
Zoom out, and Corma is less important as a product than as a lens.
The Defensive Gap reframes the entire AI-risk conversation for anyone running a company. The dominant worry has been what AI might do wrong on its own. The nearer, sharper risk is competitive and asymmetric: the exact same models making your business more capable are making your adversaries more capable, and right now the adversary’s side of that trade is compounding faster.
That reframes the executive question from “how do we adopt AI” to something stickier: “can our defense keep pace with everyone else’s offense.” It’s the kind of question that doesn’t have a product-purchase answer so much as a strategic one, and it’s why a defensive-AI arms race, largely invisible to the public, is quietly becoming one of the most important contests in technology.
The bottom line
Corma has given the industry a genuinely useful frame and $60 million to chase it. Whether this specific team closes the Defensive Gap is unproven, and the reasons it might not are real. But the gap itself is not in doubt. Offense is compounding. Defense is lagging. And the distance between those two curves is where the next decade of security will be won or lost.
The race between AI attackers and AI defenders has only just started. The whole game now comes down to a single question: who compounds faster.