The Real "We" in AI Security Today: A Taxonomy of Actors Operating at the Substrate Where AI Risk Is Created, Measured, and Controlled

When AI security practitioners invoke ‘we’ in the context of defending against AI-enabled threats, they typically mean the traditional cybersecurity community: defenders, SOC analysts, incident responders, and the certification and training organizations that serve them. This paper argues that ‘we’ is the wrong referent. The actors who operate at the substrate where AI risk is actually produced—model weights, training data, agentic behavior, eval pipelines, and substrate governance—constitute a fundamentally different coalition than the traditional cybersecurity community. This paper maps that coalition across six groups: frontier labs, AI-native security research organizations, government AI safety institutes, open-source AI security communities, enterprise AI governance teams, and independent governance practitioners. It then characterizes the structural reasons why legacy security institutions are downstream of this coalition and cannot address substrate-layer AI risk regardless of curriculum updates, and argues that closing the gap requires not better training but genuine upstream engagement with the substrate where AI risk originates.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-05-30
DOI
https://doi.org/10.5281/zenodo.20460975
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

The Real "We" in AI Security Today: A Taxonomy of Actors Operating at the Substrate Where AI Risk Is Created, Measured, and Controlled

Narnaiezzsshaa Truong
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
article

The Real "We" in AI Security Today: A Taxonomy of Actors Operating at the Substrate Where AI Risk Is Created, Measured, and Controlled

Narnaiezzsshaa Truong
article en

Abstract

When AI security practitioners invoke ‘we’ in the context of defending against AI-enabled threats, they typically mean the traditional cybersecurity community: defenders, SOC analysts, incident responders, and the certification and training organizations that serve them. This paper argues that ‘we’ is the wrong referent. The actors who operate at the substrate where AI risk is actually produced—model weights, training data, agentic behavior, eval pipelines, and substrate governance—constitute a fundamentally different coalition than the traditional cybersecurity community. This paper maps that coalition across six groups: frontier labs, AI-native security research organizations, government AI safety institutes, open-source AI security communities, enterprise AI governance teams, and independent governance practitioners. It then characterizes the structural reasons why legacy security institutions are downstream of this coalition and cannot address substrate-layer AI risk regardless of curriculum updates, and argues that closing the gap requires not better training but genuine upstream engagement with the substrate where AI risk originates.

Zenodo (CERN European Organization for Nuclear Research)
American Rock Mechanics Association (US)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.