Ivan Tsarynny, the CEO of Feroot, said AI regulation should empower defenders rather than limit their ability to defend systems [1].
This perspective highlights a growing tension between the need for strict AI safety guardrails and the practical requirements of cybersecurity professionals. If regulations are too restrictive, defenders may find themselves unable to use the same tools as attackers to identify vulnerabilities.
Tsarynny said these concerns during an appearance on The Exchange, a CNBC Television program [1]. He said that the current approach to AI model testing and safety needs to evolve to ensure that those protecting the infrastructure have the necessary tools [1].
According to Tsarynny, the goal of regulation should be to support the people tasked with defending against AI-driven threats [1]. He said the importance of safer AI model testing to prevent systemic failures while maintaining the agility of security teams [1].
The conversation focused on the balance between preventing the misuse of AI and ensuring that security researchers can simulate attacks to build better defenses [1]. Tsarynny said that limiting the capabilities of defenders effectively grants an advantage to malicious actors who operate outside the law [1].
By advocating for a framework that prioritizes empowerment, Tsarynny said that regulators should focus on the intent and role of the user rather than implementing blanket restrictions on AI capabilities [1].
“AI regulation should empower defenders rather than limit their ability to defend”
The debate over AI regulation is shifting from general safety concerns to the specific operational needs of the cybersecurity industry. If policymakers implement restrictive 'black box' regulations that prevent security professionals from testing models or simulating adversarial attacks, they may inadvertently create a security gap where attackers possess superior tools than the defenders tasked with stopping them.



