All thoughts

The Velocity Gap: When Bad Intent Moves Faster Than Good

Nov 26, 2025 · 12 min · AI Security Now

There's a race happening in AI development between "normal" and bad intentioned usage of LLMs. While enterprise security teams are still writing procurement justifications for defensive AI tools, attackers are downloading fully functional malicious LLMs in under five minutes. While compliance committees debate the controls of AI deployment, cybercriminals are running Telegram channels with 500+ active subscribers sharing ransomware generation tips.

And the side of good is losing.

Not because our AI is weaker. Not because we lack resources. We're losing because the very things that make us "good" are what slow us down.

The Numbers

WormGPT 4 charges $220 for lifetime access to an AI that generates functional ransomware, convincing phishing emails, and lateral movement scripts. Setup time? Minutes. Compliance review? Zero. Ethics approval? Not applicable.

KawaiiGPT is completely free, lives on GitHub, and can be running on your Linux box in under five minutes. It greets you with "Owo! okay! here you go... 😀" before generating data exfiltration code that bypasses most DLP systems.

Meanwhile, your organization's defensive AI initiative is still in month three of a six-month pilot rollout program.

Do you see the problem?

The Asymmetry We Built

Here's what we did: We spent signifigant time democratizing AI. We built intuitive interfaces. We created free trials. We wrote prompt engineering tutorials. We built communities on Discord and Telegram to share techniques. We celebrated when AI became accessible to everyone.

The criminals didn't invent a new playbook. They used the sameplaybook we created. The same UX principles that make ChatGPT delightful make WormGPT effective. The same community-building strategies that helped legitimate AI adoption are now helping cybercriminals share ransomware templates.

We optimized for accessibility and we got it. All of it. The good and the bad.

The Velocity Paradox

Here's the cruel irony: Every safeguard we put on beneficial AI is time attackers don't have to wait for.

Building defensive AI requires:

  • Ethics review boards
  • Security assessments
  • Compliance validation
  • Integration testing
  • User training programs
  • Procurement approvals

Building offensive AI requires:

  • None of the above

Every committee meeting, every approval cycle, every responsible deployment checkpoint is friction. Necessary friction, important friction, ethical friction. But friction nonetheless.

And while we're being responsible, the attackers are being fast.

The Unit 42 research shows this explicitly: attacks that previously required "days or hours of manual effort" now take "mere minutes of prompting." But our defensive deployment timelines didn't compress. They got longer. More complex. More governed.

We added process while they removed friction.

The Innovation Asymmetry

There's another gap that nobody talks about: the success rate differential.

Defensive AI needs to work 100% of the time. Or close to it. You can't deploy a security tool that's right 80% of the time. You need accuracy, explainability, auditability, reliability. You need to justify every decision to compliance, every alert to analysts, every action to auditors.

Offensive AI just needs to work once.

One convincing phishing email in a thousand. One undetected malware variant in a hundred. One successful lateral movement in ten attempts.

This is the fundamental unfairness of the attacker-defender dynamic, now running at AI speed.

Defenders need 100% success, attackers need 1%. Defenders need months of testing, attackers need minutes of iteration. Defenders need buy-in from stakeholders, attackers need only themselves.

The playing field was never level. AI just made it steeper.

The Historical Pattern (That We Keep Ignoring)

This isn't new. Technology has always been dual-use.

When locks got better, lockpicks got better. We didn't ban lockpicking tools; we made stronger locks and accepted that some people would use the same metallurgy for crime.

When encryption got stronger, it protected both privacy and crime. We had the Crypto Wars, we debated clipper chips, and ultimately we accepted that you can't have strong privacy without enabling some criminal use.

When the internet connected the world, it connected criminals too. We didn't shut down TCP/IP; we built firewalls and accepted that the same protocols enabling collaboration enabled fraud.

The pattern is clear: Technology advances. Criminals adopt it. Defenders adapt. The cycle continues.

Except AI is different in one critical way: the cycle time is compressing.

It used to take years for defensive technology to catch up. Then months. Now? We might be looking at weeks. Or days. The lag between "new offensive capability" and "defensive countermeasure" is shrinking, but it's not shrinking fast enough.

The Question Nobody Wants to Answer

Are we watching criminal use outpace legitimate use?

Look at the evidence:

Offensive Advantages:

  • Deployment time: <5 minutes (KawaiiGPT)
  • Cost barrier: $0 to $220 lifetime
  • Skill requirement: "basic understanding of prompting"
  • Compliance overhead: zero
  • Community support: active Telegram channels, GitHub repos
  • Iteration speed: instant

Defensive Realities:

  • Deployment time: months (procurement, integration, training)
  • Cost barrier: enterprise contracts, professional services
  • Skill requirement: specialized security teams
  • Compliance overhead: substantial
  • Community support: vendor-gated, expensive consulting
  • Iteration speed: quarterly updates if you're lucky

The adoption curve for offense might already be steeper than defense.

WormGPT 4 has 500+ Telegram subscribers. KawaiiGPT has hundreds of weekly active users. These are small numbers in absolute terms, but think about velocity: How many enterprise security teams have successfully deployed defensive AI in the same timeframe?

The criminals aren't winning because they're better at AI. They're winning because they don't have our constraints.

The Intent Problem (That Has No Technical Solution)

Here's the uncomfortable truth: We built AI to amplify human capability, and it's working exactly as designed.

We just conveniently forgot that "human capability" includes human malice.

Every paper about making AI more helpful makes it better at helping both the security analyst and the attacker. Every improvement in natural language understanding helps the defender interpret logs and helps the attacker craft phishing emails. Every advance in code generation accelerates both security tool development and malware creation.

The same model that designs the lock can pick it.

This is the dual-use dilemma at its purest: The better AI gets at doing what we ask, the better it gets at doing what anyone asks. And we can't technically distinguish "good ask" from "bad ask" without understanding intent.

But intent isn't in the data. Intent is in the human. And humans lie.

The Speed vs. Safety Trade-off We Can't Escape

So what do we do?

Option A: Remove safeguards, move faster, compete with attackers on velocity. Result: We become less ethical to stay competitive. We sacrifice safety for speed.

Option B: Maintain safeguards, stay responsible, accept that we'll be slower. Result: We fall further behind. The gap between offensive and defensive capability widens.

There's no Option C where we're both perfectly safe and perfectly fast. The trade-off is real, and it's brutal.

Every day, security leaders are making this calculation: Do we deploy this defensive AI tool even though it's not perfect? Do we accept some false positives to get detection deployed faster? Do we compromise on explainability to match the speed of threats?

These aren't hypothetical questions. They're daily decisions. And every decision is a trade-off between speed and safety.

The attackers don't have this problem. They just ship.

Where We Actually Have Advantages (And Why They Might Not Matter)

Let's be clear: Defenders aren't powerless.

We have resources attackers don't:

  • Funding (billions in security budgets)
  • Talent (the best researchers, highest salaries)
  • Compute (enterprise-scale infrastructure)
  • Legitimacy (can operate openly, recruit publicly)
  • Scale (every major enterprise is a potential customer)

These are real advantages. Structural advantages. Sustainable advantages.

But notice what they're not: speed advantages.

Money doesn't eliminate procurement cycles. Talent doesn't bypass compliance reviews. Compute doesn't accelerate ethical approval. Legitimacy doesn't reduce integration complexity.

Our advantages are in capability and resources. Their advantages are in velocity and friction-removal.

And in an arms race where the attack surface is expanding daily, where new vulnerabilities emerge hourly, where threats evolve in real-time... does capability matter if you can't deploy it fast enough?

The Critical Metric (That We're Not Measuring)

Here's what actually matters: Not who has the better AI. Not who has more resources. Not even who has the most sophisticated capabilities.

What matters is: Rate of improvement.

If defensive AI improves at 50% year-over-year, but offensive AI improves at 75% year-over-year, we're falling behind even as we get better.

If it takes us six months to deploy a new defensive capability, but attackers can deploy a new offensive capability in six days, the gap widens every cycle.

If our iteration time is quarterly, and their iteration time is daily, they're running 90 experiments for every one of ours.

Absolute capability doesn't matter. Velocity does.

And right now, I'm not sure we're winning the velocity race.

The Uncomfortable Conclusion

We can't un-invent malicious LLMs. WormGPT is out there. KawaiiGPT is on GitHub. The knowledge is distributed, the tools are accessible, the communities are established.

We can't regulate it away. The cat's out of the bag. You can't put open-source back in the bottle. You can't ban ideas that are already published.

We can't make AI "safe" without making it less useful. The capabilities that make AI dangerous are the same capabilities that make it valuable. Remove one, you remove both.

So what can we do?

We can try to stay ahead.

That's it. That's the strategy. Not "stop the bad guys." Not "make AI perfectly safe." Just: try to stay ahead in the velocity race.

And staying ahead means making hard choices every single day about speed versus safety, about deployment versus perfection, about accessible versus controlled.

The Question We Should Be Asking

The question isn't "How do we stop malicious AI?"

The question is: "How do we ensure beneficial AI adoption outpaces malicious AI adoption?"

And maybe more importantly: "What are we willing to sacrifice to maintain that lead?"

Because the answer can't be "nothing." You can't have zero trade-offs. You can't be perfectly safe and perfectly fast. You can't maintain every safeguard and match their velocity.

Something has to give.

The attackers already know what they're willing to sacrifice: ethics, safety, responsibility, trust.

What are we willing to sacrifice to stay ahead of them?

Not what we should sacrifice. Not what sounds good in a board presentation. What are we actually willing to trade for speed?

Because they're already moving. They've been moving. And every day we debate, they deploy.

The Race We're Actually In

This isn't a race between good AI and bad AI. Both sides have access to the same models, the same papers, the same techniques.

This is a race between good intent and bad intent, both using AI at full throttle.

Same tools. Same acceleration. Different constraints.

We have ethics, compliance, responsibility, accountability. These are good things. Necessary things. Things that make us the good guys.

But they slow us down.

And in a velocity race, being slow might mean being late.

The question is: How much can we streamline without becoming what we're fighting against?

That's the balance we need to find. Not perfectly safe. Not maximally fast. Just: fast enough to stay ahead without sacrificing what makes the defense legitimate.

Because if the criminals outpace us in adoption, in iteration, in deployment speed... it doesn't matter how good our AI is.

It only matters if we can deploy it before they deploy theirs.

And right now, that's not a guarantee.

It's a race.

And we'd better start running faster.


References & Further Reading

This article draws on research and observations from the broader AI security community. For additional technical details on malicious LLMs and the commercialization of offensive AI capabilities, see:

The Dual-Use Dilemma of AI: Malicious LLMs - Unit 42, Palo Alto Networks (November 25, 2025)

Unit 42's comprehensive analysis of WormGPT 4 and KawaiiGPT provides concrete evidence of the velocity gap discussed in this article, including specific details on deployment timelines, pricing models, and the democratization of cybercrime capabilities.