Andreessen asserts that AI hacking does not create new security vulnerabilities — it only makes it faster and easier to exploit vulnerabilities that already exist.
Snapshot · The a16z Show
Andreessen asserts that AI hacking does not create new security vulnerabilities — it only makes it faster and easier to exploit vulnerabilities that already exist.
Where this was said
At 35:20 · chapter starts 34:20
Pressed to take a position on the export-control trade-off, Andreessen reaches for his deepest conviction: the technological imperative. Once a technology exists, it exists — steel, steam, electricity, the Haber-Bosch process, the computer chip. They happen. They may happen faster or slower, but they happen everywhere. Given that, the question is not whether AI proliferates but whether you are dominant when it does. Andreessen's answer is that the US should aim for maximum proliferation of American AI — working hand-in-hand with companies to ensure American AI at the software level, chip level, and beyond runs the entire world. On the Mythos cybersecurity question specifically, he argues for getting advanced AI defensive tools into every company as fast as possible: AI hacking exploits existing vulnerabilities, not new ones, and banks are already being attacked without AI. The defenses need to be AI-powered and they need to be everywhere [1] — Marc Andreessen "AI hacking doesn't create new vulnerabilities — it just makes it faster to exploit existing ones. Banks are already getting hacked without …" 35:00 . He acknowledges the opposing arguments are in good faith, but notes the winds seem to be going against him on both counts.
AI hacking doesn't create new vulnerabilities — it just makes it faster to exploit existing ones. Banks are already getting hacked without AI. The answer is not to restrict advanced AI models but to get them into every company's hands as fast as possible to build AI-powered defenses. Restricting Mythos-level models means leaving everyone undefended against attacks that are already happening.
When Andreessen launched Netscape in 1994, US law classified it as a munition under ITAR — in the same category as a Tomahawk missile. The 4-line RSA encryption algorithm on a t-shirt was technically illegal to wear on an international flight. It took years of government negotiation before US tech could go global. The AI export control debate is this story repeating.
Ad-based monetization works well for game apps where users spend extended time in-session, as seen with Grid and Wordle.
Tool-focused apps like PuffCount are poor candidates for ad monetization because users don't stay in-session long enough.
A hard paywall is a screen that blocks all app features unless the user pays or starts a free trial — it cannot be dismissed.
Mobile apps are primarily monetized through either ads (best for games) or in-app purchases/subscriptions (best for tools).
According to the episode, YouTube outperforms every other social platform for building trust and driving SaaS conversions.
Vasco stated that the majority of his app's user base came directly from his YouTube channel.
SEO Bot features a 'Boost My Domain Rating' button that routes users directly to Listing Bot, an example of in-product cross-selling.
The founder's entire product portfolio is AI-related, making it easier to package products attractively for directories.
The founder attached their SaaS demo to the trending debate about whether AI coding is actually good enough to build a full SaaS product.
We use essential and analytics cookies to run Vuci. To understand how the site is used: Privacy Policy.
Install Vuci on your phone
Add it to your home screen for a faster, app-like experience.
Install Vuci on your phone
Tap the Share button, then “Add to Home Screen”.
A new version is available
Reload to get the latest Vuci.