The numbers come first. An AI agent can execute thousands of autonomous actions in the time it takes a security team to notice something is wrong. That is the core finding Shlomo Kramer, co-founder and CEO of Cato Networks, laid out in a Fortune commentary published August 7, 2026 — and it is the kind of figure that should concentrate the mind of every enterprise risk officer in America.
Kramer, widely regarded as a godfather of Israeli cybersecurity, used the Hugging Face incident as a case study in what he calls a different category of risk. A human insider threat unfolds over days or weeks and leaves detectable patterns. An AI agent operating with autonomy leaves no such runway. 'That's not a marginal difference,' Kramer wrote, 'it's a different category of risk, and most organizations are still building their defenses for the old category.'
The wrong debate is winning
What concerns Kramer as much as the breach itself is the industry's response to it. Rather than focusing on the mechanics of what occurred and a clear path forward, he argues, the conversation has drifted toward open-source versus closed-source comparisons and national-origin debates — Chinese models against American models, Beijing versus Silicon Valley.
'The attack surface doesn't care about a model's passport,' Kramer wrote. His argument is precise: every hour spent debating where a model was built is an hour not spent building the controls that can stop the next incident, regardless of origin.
Security is a discipline, not a feature
Kramer's central principle is one the free-enterprise technology sector should recognize immediately: the team that builds a product is rarely the team best positioned to secure it, because those are two different disciplines with two different mandates. He applied that logic directly to AI. 'I do not expect model companies, whether frontier models or open-source models, to provide cyber protection for the models they build,' he stated.
That is not a criticism of model builders. It is a structural observation with a 20-year precedent in enterprise software. Cybersecurity has always been a specialized discipline, and the AI era, Kramer argues, will require security architecture built for visibility, governance, and real-time control — not tools adapted from a different problem.
Coalition, not competition
Kramer points to the Open Secure AI Alliance, spearheaded by Nvidia, as a step in the right direction, while noting it is 'just the beginning.' He calls for global collaboration among model companies, security experts, governments, and enterprises — each of which, he argues, holds a piece of the AI safety puzzle the others lack.
The CEO Times read
Kramer's argument is a clean vindication of the free-market principle that specialization produces better outcomes than consolidation. Asking model builders to double as security architects is the same category of error as asking a software vendor to regulate itself — it sounds efficient until the breach happens.
The deeper point for American enterprise is competitive urgency. Every company operating AI agents with any degree of autonomy is already inside this risk perimeter. The question Kramer leaves on the table is the right one: whether anyone is watching closely enough to catch what these agents are primed to do next. Capital rewards clear rules, and right now the rules are still being written.



