This panel discussion, recorded at Nullcon Goa 2026 (Day Zero track), examines the market and industry reaction to Anthropic’s Claude Code Security launch: the promise of autonomous vulnerability discovery, the dip in security stocks, and whether the “Anthropic Shock” represents real disruption or sentiment-driven panic. Anant Shrivastava moderates an unmoderated conversation with panelists from security consulting, military, and design engineering backgrounds.
Summary
The panel opens with the observation that markets run on speculation, not ground reality: the stock dip after Anthropic’s announcement was sentiment, and the same logic applies to the AI hype cycle, where FOMO is the best marketing tool and every CISO fears management asking why they did not adopt. From there the discussion moves to what is actually changing: organizations have unified platforms and typically use only 25-50% of purchased functionality; the single feature they actually needed can now be built in-house with AI assistance. The traditional vendor moat (maintaining edge cases, maintainability) is eroding, and “if you are not doing it, your vendor is doing it.” The argument he develops in Vendors Sell Suites, Teams Need Slices: AI Made It Cheap runs through this segment: vendors sell 200-feature suites when teams need one slice, and AI has made building that slice in-house affordable.
The panel then grounds the debate: today’s models are compressed human knowledge, trained on a fraction of available expertise. The differentiator is speed, and adversaries get the same speed. A geopolitical concern is raised alongside Anthropic publicly rejecting US government pressure to remove guardrails: there is no way to verify that the models defending your enterprise are not influenced by nation-states, and the black-box problem means that uncertainty never resolves. In a country like India, cutting the human out of the loop is not realistic.
On liability, the panel is blunt: AI vendors offering “unlimited indemnification” behave like insurance companies, and insurance companies specialize in rejecting claims. The moment indemnification enters, limitation-of-liability follows, and lawyers, not CSOs, will decide where liability lands. CSOs are also warned that sharing a risk profile with insurers exposes them. Even organizations that skip AI get dragged in: Gemini is baked into Google Workspace licenses, and a fresh example shows Maps API keys granting access to Gemini environments when enabled at org level. The dependence on free open source labor that vendors and enterprises take for granted, and the unpaid expectations placed on maintainers, came up here as well (see Open Source: Unpaid Expectations).
Anthropic’s own guidance is cited: treat AI output as draft one, never an oracle. The panel worries about complacency (skipped code reviews, business pressure) and closes with three threads: a military veteran comparing AI hype to past “Revolution in Military Affairs” and “network-centric warfare” waves that oversold reality; a design engineer describing his struggle to keep his team writing fresh code; and a closing argument that beyond attack-surface discovery, organizations should actively reduce attack surface, watch policy decisions (“keep an eye on Delhi”), and mount reasoned, well-studied pushback against the FOMO tsunami.
Key Topics Discussed
Market Reaction and Hype:
- Markets run on speculation; the Anthropic-driven dip was sentiment, not fundamentals
- FOMO as the primary marketing lever aimed at CISOs
- Hype arrives in waves (RMA, network-centric warfare, AI); conference narratives consistently oversell
What AI Actually Changes:
- Models are compressed human knowledge; the edge is speed, and adversaries have the same speed
- Building is now cheap; usability, sellability, and value remain separate questions
- The vendor moat erodes when the one feature you need can be built and maintained in-house
Liability, Insurance, and Vendors:
- “Unlimited indemnification” claims will be fought by lawyers through limitation-of-liability clauses
- Insurance carriers specialize in rejecting claims; sharing your risk profile creates exposure
- AI arrives through vendor bundling even when you opt out (Gemini in Workspace, Maps API key access story)
- Vendors are invested in their revenue, not in your security
Discipline and Human-in-the-Loop:
- Anthropic’s own advice: treat output as draft one, not an oracle
- Complacency risk: skipped code reviews silently expand attack surface
- Human-in-the-loop cannot be removed in the Indian context
Practical Guidance:
- When hype peaks, do not buy; examine the code and processes first
- Reduce attack surface instead of accumulating 200 systems for one task
- CISO decisions require lawyers and business teams in the room
- Watch policy and regulatory decisions and push back with studied reasoning
Notable Quotes
- “Market does not work on ground realities. Market works on speculations.”
- “If you are not doing it, your vendor is doing it.”
- “When there is a hype, don’t buy. Wait for things to settle down.”
- “Vendors are not invested in your security. They’re invested in their product and their revenues.”
- “Don’t just worry about what is the attack surface, also start actively working towards reducing it.”