- Published on
The Asymmetry Advantage: Why Fighting AI With AI Cannot Mean Mirroring It
Wildland firefighters really do fight fire with fire. The backburn is a genuine tactic, not a figure of speech. What makes it work, though, is not that the defensive fire is bigger or hotter than the one coming at it. It works because of where it is lit, when, and along which ridge. A crew that responded to an advancing fire by simply lighting a larger one would not be practicing the tactic. They would be losing faster.
"We need AI to fight AI" has become the security industry's version of that mistake. The premise is correct and increasingly urgent. The conclusion usually drawn from it — that defenders need a mirror-image arsenal, a detector for every generator — is the expensive wrong turn. The defensive case for AI does not rest on symmetry. It rests on the specific, structural ways the attacker's use of AI differs from what defense actually needs it for.
- The Rate Limit That Used to Do Our Work for Us
- Symmetry Is the Trap
- What Cheap Leaves Behind
- Defend Where Autonomy Breaks
- The Constraint Nobody Can Design Away
- What This Means for Practice
- Closing
The Rate Limit That Used to Do Our Work for Us
For as long as there has been organized fraud, criminal operations have been bounded by human labor. A romance scammer could sustain a handful of convincing relationships, not five hundred. A document forger produced one passable passport at a time. A social engineer had to learn a target, hold a persona, and speak the language. Effort was the natural governor on volume, and quality and quantity traded against each other in a way defenders could rely on.
Almost every defensive process in use today was calibrated against that governor, mostly without anyone deciding to calibrate it. Alert thresholds assume a certain base rate of attempts. Triage queues assume an analyst can work through a day's worth of cases in a day. Know-your-customer checks assume that fabricating a coherent identity — the document, the face, the address history, the voice on the verification call — is costly enough that most attackers will not bother. Manual review exists as a backstop precisely because the volume reaching it was supposed to be small.
AI did not defeat those controls by outsmarting them. It removed the constraint they were built on. Effort stopped being scarce on the attack side while remaining entirely scarce on the defensive side. TRM Labs' 2026 AI-in-Crime Adoption Index, which scores criminal AI maturity across crime types, captures the uneven shape of this: adoption is deepest in scams and fraud, where the bottleneck was always conversational labor, and shallowest in narcotics trafficking, where the bottleneck is physical and AI has little to offer. That pattern is the tell. Criminal AI adoption tracks almost exactly where human effort used to be the limiting factor.
So the honest formulation of the problem is not that criminals have a powerful new weapon. It is that defense has been running on an implicit subsidy — the attacker's labor costs — and the subsidy has been withdrawn. The question is what replaces it.
Symmetry Is the Trap
The instinctive answer is to match the attacker capability for capability. They generate synthetic faces, so we buy synthetic-face detection. They write phishing with a language model, so we buy AI-written-text classification. Each purchase is defensible on its own. Together they constitute a strategy of pure symmetry, and symmetry is the worst ground a defender can choose.
Three reasons, and they compound.
The first is that symmetric detection puts you in a race whose tempo the attacker sets. Every detector that works becomes a training signal for the next generation of generator. You are not building a wall; you are contributing to your opponent's evaluation suite. This dynamic is well understood in the deepfake context — I have argued elsewhere that single-artifact detection is the wrong battle — but it generalizes well beyond synthetic media.
The second is that the economics are inverted. Generation is cheap, gets cheaper, and fails gracefully: an attacker running ten thousand approaches does not care that nine thousand are ignored. Detection is expensive, degrades under distribution shift, and fails expensively, because a defender operating at scale pays for every false positive in analyst hours and customer friction. Matching an adversary whose cost curve runs the opposite direction from yours is not a strategy.
The third is the subtlest. Symmetry copies the attacker's objective function, and that objective is the wrong one for us. The attacker is optimizing for plausibility at volume. Defense is not trying to produce anything plausible. It is trying to establish what actually happened, to a standard that survives an adversarial process. Borrowing the attacker's tooling philosophy imports a goal that was never ours.
What Cheap Leaves Behind
Here is the asymmetry that actually favors the defender, and it comes directly from the thing that makes AI attacks work.
Volume is not free of consequences. It is free of labor costs, which is not the same thing. Ten thousand synthetic personas generated in an afternoon share something that ten thousand personas built by hand over ten years would not: they were produced by the same process, under the same constraints, drawing on the same infrastructure, within the same window of time. They register accounts through overlapping providers. They cluster in phrasing distributions and response latencies. Their funds move along paths that converge. The very economics that make the attack scalable also make it structured, and structure is the thing analytical systems are genuinely good at finding.
This reframes what defensive AI is for. Not adjudicating artifacts one at a time, which is the losing battle, but correlating across them — pulling together signals from independent sources that an attacker would have to compromise separately and consistently to defeat. A fabricated identity can be made to survive any single check. Making it survive the joint distribution of a document check, a liveness check, a device history, a funding path, and a behavioral profile, while a thousand of its siblings are doing the same thing, is a qualitatively harder problem. It stays hard even with good models, because the difficulty scales with the number of independent sources rather than with the quality of any one forgery.
That is the backburn. Not a bigger fire. A different position on the ridge.

It is also why the architecture matters more than the model. Correlation at this scale is not one classifier; it is a set of specialized capabilities working over shared context — entity resolution, temporal reasoning, network analysis, anomaly surfacing — which is the practical case for the kind of multi-agent investigative architecture that is emerging across serious platforms. The capability that matters is not detection. It is compression: turning a volume of weak, scattered signals into a small number of things a human should look at.
Defend Where Autonomy Breaks
There is a second asymmetry, and it is more perishable, so it is worth exploiting now.
Criminal AI is uneven across the lifecycle. It has moved furthest into the stages that are pure information work — target selection, initial contact, persona maintenance, sustained deception — and least far into the stages that touch the physical and financial world. Autonomous attack tooling documented so far has been able to run a full technical intrusion and then stall at monetization, because converting access into money still requires negotiation, human-controlled accounts, and cash-out infrastructure that does not automate cleanly.
This has a direct operational consequence: defensive effort concentrated at the points where automation is weakest buys more than the same effort spread evenly. The generation stages are where the attacker's advantage is largest and the defender's leverage is smallest. The monetization, laundering, and cash-out stages are where attacker automation thins out, where the same human operators and the same infrastructure recur across many campaigns, and where correlation across cases pays off most. Following the money remains the hardest part of the work — but it is hard in a way that AI-assisted crime has not yet made harder, and that is a rare thing to be able to say in 2026.
The window will narrow. It is open now.
The Constraint Nobody Can Design Away
One more asymmetry, and this one runs against us. It deserves stating plainly because strategies that ignore it do not survive contact with reality.
The attacker has no compliance obligation, no audit trail, no false-positive cost, no explainability requirement, and no duty to anyone affected by a mistake. The defender has all five. A model that flags the wrong person imposes a real cost on a real person, and eventually on the institution. A system that cannot show its reasoning cannot support a charging decision or survive cross-examination. These constraints are not bureaucratic drag to be engineered around. They are the reason the defensive side is worth defending.
The practical implication is that defensive AI has a requirement attacker AI does not: it has to be legible. Every inference has to be traceable to the evidence that produced it. This rules out a class of otherwise attractive architectures, and it is the strongest argument for keeping the machine on discovery and the human on decision. Machines are now better than we are at finding the thread in a haystack of weak signals. They are not better at deciding what a thread means for a person's liberty, and the gap between those two things is not primarily a technical gap.
What This Means for Practice
Three directional shifts, not a checklist.
Buy correlation, not detection. When evaluating a capability, ask whether it adjudicates artifacts in isolation or reasons across independent sources. The first is a subscription to an arms race. The second compounds: it gets stronger as more data types come under one roof, and it forces the attacker to solve a harder problem than the one they have been solving.
Measure tempo, not accuracy. The relevant question is no longer how accurate a model is on a benchmark. It is how long it takes to get from first weak signal to a decision a human can defend, and whether that interval is shrinking faster than the attacker's cycle time. An accurate system that takes three weeks to produce a reviewable case is losing to an inaccurate one that takes three hours.
Instrument the human layer deliberately. If the machine is doing discovery and the person is doing judgment, then the handoff between them is the actual product. Analysts need to see why something surfaced, what it is built on, and what would change the conclusion. Tooling that hides its reasoning shifts the accountability onto a person who has been given no basis to exercise it.
Closing
We do need AI to fight AI. Not because the other side has it — that is the slogan version of the argument, and it leads to buying mirrors. We need it because the labor cost that used to rate-limit crime is gone, and nothing else will fill the gap at the volumes now in play.
But the tactic is the backburn, not the bigger fire. The attacker uses AI to make things cheap, plausible, and numerous. Defenders should use it to do the thing cheap, plausible and numerous things are bad at surviving: being placed next to each other and compared. Volume creates pattern, pattern is tractable, and the machine that finds the pattern should hand it to a person who decides what it means.
The fire is bigger than it was. The ridge is still ours to choose.