Tech
How AI guardrails are impeding the work of offensive cybersecurity researchers
For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers.
In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.
Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)
That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program.
These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.
During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”
Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.
Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails.
Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.
“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”
It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”
When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.
Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails.
Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model.
Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities.
“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”
One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.
“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said.
Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs.
“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.”
Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.
“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”
Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.
“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Monday.com is the latest tech company to blame AI for layoffs — here are 20 others
Monday.com, the Tel Aviv-based work management software company known for its colorful, customizable project-tracking boards, this week became the latest tech company to cite AI as a factor in job cuts. On Wednesday, the company said in an SEC filing that it will lay off about 20% of its workforce, or just over 600 employees, as part of a “restructuring plan” tied to its “ongoing transformation of its product, marketing, and go-to-market strategy” in support of “a leaner, more focused operating model” as it continues investing in its “AI-driven growth strategy.”
Co-founder Eran Zinman told employees in a LinkedIn memo that the move “was not made to reduce costs or replace people with AI,” positioning it instead as adapting the organization to a new AI-first vision the company laid out roughly a year ago when it rebranded around a platform-wide AI push. Monday.com, which has two offices in the U.S., expects $45 million to $55 million in net restructuring charges but still projects up to 20% year-over-year revenue growth for 2026.
So far, according to new Financial Times analysis, U.S. tech companies have slashed nearly 140,000 jobs since the start of this year, with Amazon, Oracle, Meta, and Microsoft alone accounting for almost 50,000 of those cuts as they funnel hundreds of billions of dollars into AI data center buildouts. Interestingly, the FT also found that companies citing AI as a factor in job cuts have underperformed the Nasdaq by almost 10% in the 30 trading days following their announcements, suggesting the market doesn’t entirely buy the stories that the companies are telling.
Still, the picture isn’t uniformly bleak. The FT notes that AI-focused companies like Anthropic and OpenAI are hiring rapidly, absorbing some of the talent shed elsewhere in the industry. And within some of the very companies making cuts, headcount is shifting rather than disappearing entirely. Meta, for instance, earlier this year moved roughly 7,000 employees into new AI-focused roles even as it laid off 8,000 others, and IBM says it’s tripling entry-level hiring for AI and hybrid-cloud roles alongside recent cuts.
Below is a running look — in reverse chronological order — at the bigger tech companies that have announced significant layoffs this year with AI as a stated factor.
Microsoft — July 9, 2026. Microsoft cut about 4,800 roles, or 2.1% of its global workforce, most of them in its Xbox gaming unit, resetting the business only three years after acquiring Activision Blizzard for $75 billion, per the FT. Separately, it offered buyouts structured as voluntary separations, without disclosing how many employees these would impact. The company said the role eliminations were “not being replaced by AI” but acknowledged “AI is changing how work gets done.” CFO Amy Hood said total headcount declined year-over-year in fiscal Q3, and was expected to keep declining as the company focuses on “building high-performing teams that operate with pace and agility” amid rising AI investment.
Oracle — June 22, 2026. Oracle disclosed in late June that it had reduced its workforce by 21,000 employees over the past 12 months, a decline of 13%, which means more cuts than was previously known, including because of AI. “The adoption and deployment of AI technologies across our operations have resulted, and may continue to result, in reductions to our workforce,” the company said in an annual financial regulatory filing.
GitLab — June 3, 2026. GitLab laid off roughly 350 workers, about 14% of its staff, to fund AI infrastructure investment and handle surging traffic from AI workflows. CEO Bill Staples said agentic workloads are “pushing competitors to the brink” and that the company had begun a “generational rebuild” of its core infrastructure to support what he called 100x growth requirements. GitLab is exiting 22 countries, flattening management layers, and partnering with an unspecified AI lab to rebuild its platform for agent-scale workloads. The company reported first-quarter revenue of $264 million, up 23% year-over-year, and expects to incur $30 to $35 million in restructuring costs.
Google — ongoing through May. Alphabet’s Google has quietly cut employees across its Cloud division, including its Threat Intelligence Group and Mandiant-linked cybersecurity staff, even as Cloud revenue grew 63% to exceed $20 billion for the first time and its backlog nearly doubled to over $460 billion. Over the past year, Google has cut more than a third of the managers overseeing small teams — 35% fewer managers with fewer direct reports. Unlike most companies on this list, Google has never announced a single overall number — the cuts have come through a rolling performance review process, a voluntary buyout program, and structural reorganizations, with outside estimates putting the 2026 total at between 1,500 and 3,000+ engineers.
Intuit — May 20, 2026. Intuit announced plans to eliminate roughly 3,000 jobs — about 17% of its total workforce — in a restructuring centered on reducing complexity and reallocating resources toward AI. CEO Sasan Goodarzi reportedly told staff the company is reducing complexity and simplifying the structure so it can deliver better products.
Meta — May 20-21, 2026. Meta laid off about 8,000 employees, roughly 10% of its workforce, while moving about 7,000 employees into new AI-focused roles (that they reportedly hate). CEO Mark Zuckerberg told staff the cuts were necessary because “success isn’t a given” in AI.
Cisco — May 14, 2026. Cisco announced it’s cutting nearly 4,000 jobs, about 5% of its workforce, despite reporting better-than-expected profit and revenue. CFO Mark Patterson said: “This was really not a savings-driven restructure… this is more [about] realigning … resources around silicon, optics, security and AI.”
Cloudflare — May 7-8, 2026. Cloudflare cut about 20% of its workforce (1,100 people), reporting quarterly revenue of $639.8 million, up 34% year-over-year and the highest single quarter in company history. CEO Matthew Prince wrote that “the vast majority of those we laid off last week were measurers” — middle management, finance, legal, internal auditing, and revenue recognition.
General Motors — May 12, 2026. GM eliminated 500 to 600 jobs, largely in IT roles in Austin, Texas, and Warren, Michigan, saying it was reevaluating its workforce needs amid uncertain market conditions. A person familiar with the cuts told CNBC that AI played a role in the decision but that it wasn’t the only reason. GM’s statement said it was “transforming its Information Technology organization to better position the company for the future.” Despite the cuts, the company still had roughly 80 open IT positions, including roles in AI, motorsports, and autonomous vehicles.
Coinbase — May 5, 2026. The crypto exchange said it was cutting about 700 employees, or 14% of its staff, as part of a restructuring aimed at addressing market volatility and increasing AI efficiency. The company flattened its organizational structure to five layers below the CEO and COO, and said it would experiment with “one-person teams” combining engineering, design, and product roles. CEO Brian Armstrong wrote that AI had changed the pace of work dramatically — “engineers use AI to ship in days what used to take a team weeks” — and that the company needed to “leverage AI across every facet of our jobs.”
PayPal — May 5, 2026. PayPal announced plans to cut around 20% of its workforce over the next two to three years — north of 4,500 jobs — as part of a turnaround strategy centered on AI adoption and organizational simplification. CEO Enrique Lores told investors the company would “aggressively adopt AI” in its development processes and formed a new “AI transformation and simplification” team reporting directly to him, tasked with redesigning the company’s processes “function by function.” Lores framed the cuts as removing organizational layers, and said AI would extend well beyond coding into customer service, support operations, and risk management.
Microsoft — April-May 2026. Microsoft offered buyouts structured as voluntary separations, without disclosing how many employees these would impact. CFO Amy Hood said total headcount declined year-over-year in fiscal Q3, and is expected to keep declining as the company focuses on “building high-performing teams that operate with pace and agility” amid rising AI investment.
Snap — April 16, 2026. Snap cut roughly 16% of its global workforce — about 1,000 full-time employees — and closed more than 300 open roles, with CEO Evan Spiegel citing AI advancements as a key driver. “Rapid advancements in artificial intelligence enable our teams to reduce repetitive work, increase velocity, and better support our community, partners, and advertisers,” Spiegel wrote in a memo filed with the SEC. The company said it had already seen small squads using AI tools to drive progress across Snapchat+, ad platform performance, and infrastructure efficiency.
IBM — rolling through 2026. Between Q4 2025 cuts and April 2026 Red Hat engineering reductions, estimates range from 3,000 to 9,000 U.S. positions eliminated, bringing IBM’s cumulative total since September 2024 above 15,000. Bloomberg reported IBM plans to triple its U.S. entry-level hiring for AI and hybrid-cloud roles, even as roughly 200 HR positions were replaced by AI agents. An IBM spokesperson described the Q4 2025 round as a routine rebalancing affecting “a low single-digit percentage” of its global workforce.
Atlassian — March 11, 2026. Atlassian cut about 1,600 jobs (10% of its workforce) to “rebalance” toward AI and enterprise sales, even as shares rose nearly 2% on the news. CEO Mike Cannon-Brookes said: “Our approach is not ‘AI replaces people.’ But it would be disingenuous to pretend AI doesn’t change the mix of skills we need or the number of roles required in certain areas. It does.”
Dell — January 30 (though disclosed in March 2026). Dell’s total workforce fell about 10% in fiscal 2026 — roughly 11,000 jobs — to about 97,000 employees from 108,000 a year earlier, with $569 million spent on severance. The cuts came as Dell projected its AI-optimized server revenue could double in fiscal 2027.
Oracle — March 5-31, 2026. As noted above, Oracle began telling employees it would be cutting thousands of jobs via terminal emails. The cuts came even as Oracle posted $3.7 billion in quarterly net income, up 27% year-over-year, with remaining performance obligations up 325% to $553 billion — savings redirected toward AI data centers. The cuts that would later total 21,000 over 12 months, as Oracle disclosed in its June 22 annual filing.
Block — February 26-27, 2026. Jack Dorsey’s Block cut 4,000 jobs — nearly half its workforce, down to under 6,000 from over 10,000. Dorsey wrote on X: “We’re already seeing that the intelligence tools we’re creating and using, paired with smaller and flatter teams, are enabling a new way of working which fundamentally changes what it means to build and run a company.” He added: “I think most companies are late. Within the next year, I believe the majority of companies will reach the same conclusion and make similar structural changes.”
Salesforce — February 10, 2026. Salesforce laid off fewer than 1,000 employees across marketing, product management, data analytics, and its Agentforce AI unit. The company told Fortune, “Because of the benefits and efficiencies of Agentforce, we’ve seen the number of support cases we handle decline and we no longer need to actively backfill support engineer roles.” This followed an earlier cut of about 4,000 customer-support roles, shrinking that team from roughly 9,000 to 5,000, with CEO Marc Benioff saying the company needed “less heads” because AI agents handle the work.
Amazon — January 28, 2026. Amazon cut 16,000 corporate jobs, following 14,000 cuts in October 2025 — about 9% of its corporate workforce in three months. The company said it was part of “strengthen[ing] our organization by reducing layers, increasing ownership, and removing bureaucracy.” CEO Andy Jassy had said in June 2025 that, “As we roll out more generative AI and agents, it should change the way our work is done. We will need fewer people doing some of the jobs that are being done today… in the next few years, we expect that this will reduce our total corporate workforce as we get efficiency gains from using AI extensively across the company.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
One fallen power line exposed a growing AI data center problem. Here’s how to fix it.
A power line went down outside of Washington, DC, this week. Normally, the grid would only need a few seconds to recover from such an event. But this one took more than 10 minutes because more than 3 gigawatts of data centers stopped drawing power nearly simultaneously.
The event caused voltage across the PJM grid to spike from Northern Virginia to Chicago, according to data collected by Ting Labs, a startup that runs an IoT sensor network out of people’s electrical sockets.
The event didn’t cause a blackout, but it did cause lights across the region to flicker. The incident demonstrated the effect that data centers can have on the grid — an outcome that experts believe will become more frequent.
Northern Virginia, which is in PJM’s territory, is home to the highest concentration of data centers in the world.
“It’s the canary in the coal mine,” Ricardo de Azevedo, CTO at ON.Energy, told TechCrunch. These sorts of events involving large loads like data centers are “happening more and more,” he added.
The event echoes one that happened two years ago, also on PJM’s grid, and it could foreshadow larger events if data centers aren’t built to more elegantly handle disruptions to power supplies. The PJM Interconnection manages grids from New Jersey to Illinois and serves 67 million customers, making it the largest grid operator in the United States.
When the power line went down this week, it triggered data centers to switch to backup power, and about 3.1 gigawatts of load vanished in about 30 seconds, according to PJM data. The grid appeared to recover somewhat, but a short time later additional loads dropped off. At its peak, PJM’s grid had an extra 3.49 gigawatts of electricity on it. It took another 11 minutes before it stabilized. The disconnected data centers represented around 3% of total demand on PJM at the time, according to Reuters.
A few percent may not sound like much, but the electrical grid needs to operate in a state of near-perfect balance, with supply and demand closely matched. If they don’t, voltages can sag or spike. The grid and devices connected to it can tolerate small fluctuations, but if those fluctuations grow too large, they’ll trigger failsafes within the grid or within individual facilities, causing them to disconnect.
When data centers in Northern Virginia sensed the fluctuation caused by the failed power line, they switched to backup power, which removed their load from the grid. As more data centers made the switch, they removed greater amounts of load from the grid. What started as a relatively small drop in supply became an even larger drop in demand, sending supply surging and causing light bulbs to flicker.
Most data centers make decisions in a split second, and those that disconnected this week appear to be no different. When the voltage dip reached them, they all decided to disconnect within a few seconds of each other, Ali Zain Banatwala, senior market models specialist at the Independent Electricity System Operator, told TechCrunch.
“We need to figure a way for these loads that are located next to each other to sequentially either disconnect or reconnect,” he said. A more orderly process would allow grid operators to develop more robust procedures in advance.
Alternatively, data centers could be built to absorb disruptions and not turn their backs to them. One startup, ON.Energy, has been working on a product to help data centers — and the grid — ride through events like the one that occurred this week.
The company has developed an uninterruptible power supply for an entire data center campus, covering not just servers but also chillers and other equipment. The company essentially hides the data center behind a bank of batteries connected to sophisticated power conversion equipment. All the grid “sees” is one consistent, well-behaved load rather than the peaks and valleys from each individual part of the data center. ON.Energy’s system allows data centers to ramp computing workloads up and down, including AI training, without bothering the grid.
Perhaps more important, it also means that data centers can absorb power fluctuations from the grid. Rather than disconnecting from the grid, ON.Energy’s system can use any extra power to charge its batteries, and if the flow dips, the system can dispatch power to servers. Plus, it can follow the grid’s lead within milliseconds, preventing sags or surges like the ones that caused this week’s problem for PJM.
ON.Energy is currently installing a total of 3 gigawatts worth of its systems at four different data center campuses, de Azevedo said.
Grid managers have also woken up to the problem.
ERCOT, for example, is going to require large loads like data centers to “ride through” disruptions, de Azevedo said.
The clock is ticking, though. The mass disconnection this week was twice as large as a similar event in 2024, when 60 data centers simultaneously disconnected, pulling 1.5 gigawatts of load from the grid. Back then, data centers accounted for about 6% of PJM’s load, according to Synapse Energy Economics. By 2040, they are expected to make up 24%. If the problem isn’t addressed soon, things could get a lot worse.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Librarians are hosting viral ‘Avoiding AI’ workshops for people who are fed up with Big Tech
“Everybody’s on their phone at my program!” joked Charlie Bailey, a librarian in South Philadelphia. He’s just asked his audience to pull out their phones so that he can walk them through the steps of disabling Apple Intelligence and Gemini.
Bailey stands at the front of a library classroom that’s outfitted for children – the focal point is the vibrant rug he’s standing on, which reminds us that M is for “moon” and Z is for “zebra.” But the 20-odd adults in the room aren’t here to learn about the alphabet. They’re at a workshop called Avoiding AI, which, in this context does not stand for “apple” and “igloo.”
“I was inspired by the feeling of people’s frustration with AI tools being kind of forced onto them, and feeling like AI tools we didn’t ask for are suddenly everywhere in our lives,” Bailey told TechCrunch.
Bailey starts the hour-long workshop with an overview of how AI chatbots and other consumer AI tools work, explaining why people might want to use these products, and why they might opt to abstain. Then, he walks through all of the most popular tech platforms and devices, showing step-by-step instructions on the projector to guide people through turning off specific features.
“As a librarian, I think it’s important to see this as advancing digital literacy and helping people reclaim their autonomy over whether they want to use AI tools,” Bailey said. “It’s important, especially when it can be so difficult not to use them, and when the design seems to force adoption.”

Bailey got the idea for the Avoiding AI workshop from Hannah Cyrus, a librarian in Maine. He was one of dozens of librarians from around the world who contacted Cyrus after she published a journal article about developing her own workshop.
“This has never happened before with anything I’ve worked on,” Cyrus told TechCrunch. “Nobody has ever been emailing me like, ‘Can you give me your Intro to Computers slides?’”
At the Bangor Public Library, patrons turn to Cyrus when they need help with anything involving technology.
“More and more, I was getting questions about, ‘How do I turn this [AI] stuff off? Why is it trying to write my emails for me? Why is it trying to summarize my one-sentence email that I can easily read?’” Cyrus said. “I just decided that with so much media hype out there about AI products, it would be a good opportunity to teach people about the basics of what is happening when you’re using this technology, and then getting into how to turn it off if you don’t want to use it.”
Usually, Cyrus’ classes like Intro to Computers get about a dozen attendees. But so many people expressed interest in her first Avoiding AI workshop that she had to cut off registration at 30 people, open a waitlist, and share the workshop on Zoom. Including the livestream, about 70 people attended each of Cyrus’ first two workshops.
When Bailey followed Cyrus’ lead to host a workshop in Philadelphia, the reception was similarly unprecedented. The library’s Instagram post about the “Avoiding AI” event got over 2,000 likes and 220 shares, whereas most of the library’s posts don’t get more than a few dozen likes. He scheduled a second program because the first got too many registrations.
“As an information professional, it feels good to see people skeptical of AI,” Bailey said. “It felt really good to see how many people share this feeling.”
There’s a sense of camaraderie among the room of strangers during the workshop. When Bailey invites attendees to share their own tips, one person explains that when you append “&udm=14” to a Google Search, it will hide AI results. Bailey writes the string of characters down on a whiteboard next to the log-in credentials for the teen Wi-Fi server.
“You have to go through all the trouble to buy a home in today’s world, and two years from now, there could be a data center next to your house,” one workshop attendee named Johnny says.
“I keep getting AI shoved down my throat at work, and every time I see it, I think about the environment,” another attendee named Gabrielle adds. But she’s also not writing off AI as a technology altogether. “I’m not against AI in terms of medical breakthroughs.”
AI naysayers know that this technology is far broader than just chatbots and deepfake apps. Cyrus mentioned how useful optical character recognition is for scanning old documents at the library. But for her and the people who go to her workshops, the anti-AI movement isn’t about rejecting technology altogether so much as it is about advocating for more control, agency, and freedom in how people use technology.
“I think the forced adoption of AI on people’s devices might be the straw that’s breaking the camel’s back in some ways,” she said. “The awareness has been growing for a long time that these products and these companies that make them have an outsized influence over us, and that we’re not really using these products in the way that we would like to.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
