Salvo: Interview With CEO Jacob Arbeid About AI Cybersecurity And Agentic Adversary Simulation

By Amit Chowdhry ● Today at 9:10 PM

Salvo is a nonprofit focused on understanding and reducing security risks created by increasingly capable AI systems. Its work includes agentic adversary simulation, where human-supervised AI agents test real business networks for vulnerabilities, along with research and data collection around AI-assisted hacking incidents. The organization is particularly focused on critical infrastructure, governments, and smaller organizations that may lack the resources of large enterprises. Pulse 2.0 interviewed Salvo CEO Jacob Arbeid to learn more about his background in AI security, the origins of Salvo, and why he believes autonomous AI could fundamentally change the scale of cyberattacks.

Jacob Arbeid’s Background

Jacob Arbeid

When asked about his background, Arbeid shared:

I’m not originally a technical guy. I studied History and Modern Languages at the University of Cambridge.

I loved the thrill of successfully speaking to someone in their native language, and the degree felt like the best combination to satisfy a deep curiosity about human affairs and cultures and the systems our species builds in the world.

My plan afterward was to become a diplomat.

I was living in Geneva working on U.S.-China diplomacy for AI and biotech in 2023, when I heard that the UK government was building the AI Security Institute and hosting a big summit on AI safety and security issues.

I quit my job and joined immediately because I saw the potential for AI to reshape geopolitics and the economy, and thought we needed people working with governments and national security.

While waiting for my security clearance to come through, I visited some family in Israel.

On a Friday, my clearance came through and I was told to come back immediately to contribute to the Bletchley Park AI Safety Summit three weeks later.

The Saturday was October 7th, and I found myself stuck in the country.

I was eventually able to get on several roundabout flights to London, almost getting stuck in Turkey along the way. It felt like every day counted for something this important.

The Summit took place in November 2023. Kamala Harris, Gina Raimondo, Elon Musk, Dario Amodei and the Chinese Vice-Premier were in attendance.

My team was in charge of a starting plenary, demonstrating to the Summit audience how we were already able to see AI agents going rogue.

After the Summit, I helped build the Security Institute into a team of 250 people, poaching staff from OpenAI, DeepMind, Anthropic, Palantir, etc.

I built the world’s largest AI security evaluation program with 200+ researchers and worked with OpenAI and Anthropic to run the world’s first government tests of a model’s autonomous capabilities.

I saw the intelligence community in the UK and allied nations take a growing interest in AI risks.

How Salvo Started

When asked how the idea for Salvo came together, Arbeid explained:

At AISI, I worked to test models and saw their hacking capabilities rapidly improve.

When we started out in 2024 they were about as good at hacking as an enthusiastic but not particularly gifted middle schooler.

But the trend back then was already clear.

I remember running a threat scenario workshop with GCHQ and having a lightbulb moment when I realized just how much of our complex, democratic societies are dependent on poorly secured digital infrastructure.

Our finances, social lives, taxes, supply chains and even some defense systems are all run through the web, and that makes them vulnerable.

But because of how much skilled effort it takes to hack into something, we have so far got away with not investing much in their security.

Arbeid said the emergence of increasingly capable AI agents could change that balance:

I was worried that AI would change the game because you can in theory just keep spinning up more agents.

There are probably only a few tens of thousands of people in the world with the ability to hack into critical infrastructure.

They can’t hack everything at once, and lots of them are moral enough to work for the good guys.

But once the AIs get to a level where they are capable of autonomous hacking, you can just keep scaling your attacks by running more AI agents.

Where previously a Russian hacker group would take weeks or months to crack into a critical system, we now have reports that a Russian group instructed the Chinese DeepSeek model to autonomously hack nearly 400 targets including schools and businesses.

In a few years I think we’ll see incidents where entire regional power grids or local government systems are brought down with the help of AIs.

That concern ultimately led to Salvo’s approach:

So I started thinking, we need to be prepared for the moment when AIs can carry out mass hacking operations, because the scale at which they can do things combines with the fact that a lot of infrastructure is poorly defended, and it just gives you this immense capacity to cause damage.

One part of preparing is doing what we call “agentic adversary simulation.”

It’s a lot like penetration testing, except we have humans supervise agents to map your business’s vulnerabilities and help you improve.

Another part is doing research on AI hacking incidents that are already happening out in the world and analyzing that data for key players, governments, industry, etc.

But also the general public, because we think that AI-assisted hacking is going to increasingly affect Main Street and the public have to know how to secure their personal systems and their businesses.

Favorite Memory

When asked about his favorite memory working for Salvo so far, Arbeid said:

I was talking with a VC about Salvo’s work, not a pitch per se.

I asked if we could try to hack their firm.

He said, “yes, my partners are onboard to have you try to rekt us.”

This is a fairly large fund, $200 million AUM, and he was willing to give access to his network to a guy he’d just met.

I loved the speed and it felt like a strong validation that yes, this was a big deal and we needed to prepare businesses.

I think VC firms are particularly vulnerable to AI-assisted attacks.

It requires a lot of phishing, often including voice phishing, to get access to their funds, and AIs are now good enough to impersonate members of their teams.

They also often have weaker security than other financial firms.

Core Products And Features

When asked about Salvo’s core products and features, Arbeid explained:

Our core work is testing whether AI systems are capable of compromising networks, and advising on risk reduction based on what we find.

We run AI agents based on OpenAI, Claude, and open-weight models like DeepSeek against real critical business networks to help them and help governments understand the economic exposure to AI-assisted hacking.

We are also building a product which aggregates public and private data on AI-assisted hacking incidents like the recent OpenAI incidents.

We want it to eventually provide an early warning signal for incidents that can help defenders.

But in the meantime, it’s a good source of data to help governments and industries with broad exposure understand where the risk is concentrated.

Safely Testing AI Against Real Networks

When asked about challenges in the sector and how Salvo has addressed them, Arbeid said:

When running AI adversary simulation, the problem isn’t so much whether an AI can hack a real company.

The problem is if we can get it to hack the company without causing collateral damage.

Agents are incredibly powerful but they are not yet fully reliable.

We’ve had to invest in guardrails and safety layers and we also ensure a human monitors the agent the whole time.

Arbeid also highlighted the challenge of communicating AI cyber risk:

We’ve also faced challenges in communicating the challenge of mass AI-assisted hacking.

It’s easy for people to bind that up with concerns about superintelligence and misalignment.

It’s not that these things are necessarily bad to work on, but mass cyberattacks are something that are happening now and are increasingly visible.

I think over the last few weeks, with the most recent round of hacking incidents, people are starting to understand that these models are just incredibly powerful tools and they can cause significant damage if we don’t secure them properly.

How Salvo’s Technology Has Evolved

When asked how Salvo’s technology has evolved since launching, Arbeid explained:

We are quite new, only three months old, but that is already a long time in AI.

As models have gotten more capable, we’ve been able to use them to do more of our monitoring work, our drafting, project management and the like.

While we’ve built safety layers for our pentest work, we make sure to always have a human in the loop given the stakes are high.

Key Company Milestones

When asked about Salvo’s most significant milestones, Arbeid said:

We received $200,000 as pre-seed funding, non-dilutive, from a foundation.

A month later after we had more traction, we got another $1.5 million in donations, and we’ve subsequently got another $1.5 million, totaling $3.2 million.

We are about to finish and publish the results from the hacking exercise on the VC firm.

We have also noticed increasing interest from governments and intelligence agencies and have made a lot of inroads as the issue has grown in salience, but it’s not possible to give details.

Total Addressable Market

When asked about Salvo’s market opportunity, Arbeid explained:

Salvo is currently run as a nonprofit, because the flood of capital into AI security work gives us the resources we need while being able to focus on public service.

But we think that AI security and assurance will be huge.

If AI will be the largest global industry some day, AI security, making sure our economy is secure with AI, will be the second-biggest industry.

The AI Assurance Tech Report estimated a $276 billion TAM by 2030.

Given the report was published in 2024, I think this is conservative.

Competitive Differentiation

When asked what differentiates Salvo from other organizations in AI cybersecurity, Arbeid explained:

We are a nonprofit acting in the public interest.

Most companies doing AI cybersecurity are focused on finding bugs in codebases, application security.

Salvo is focused on the entire attack surface, not just bugs, but also companies’ vulnerabilities to phishing attacks, reuse of standard passwords, etc.

Most companies suffer a cybersecurity breach because of these more mundane factors, rather than a novel vulnerability being found.

We also choose to work with smaller and medium organizations, the logistics firms, water plants, local governments, etc. that are the backbone of our civilization but which don’t have the budget to secure themselves.

Future Goals

When asked about Salvo’s future goals, Arbeid said:

We want to help businesses, especially in critical domains like finance and health and logistics, see the importance of investing in their security given how the low cost of AI hacking is making “security through obscurity” irrelevant.

We also want to help Western governments have the best possible understanding of how AI is changing the security landscape, including tracking threats to critical infrastructure from adversary states.

We’re also building Salvo’s reputation so we can attract top research talent.

Understanding The Emerging AI Cybersecurity Landscape

When invited to discuss other areas of interest, Arbeid highlighted several topics:

I’m happy to speak to what pre-release testing of models actually looks like. I ran some of the earliest tests in the world while at AISI.

I can speak to what the general public most misunderstands about AI cyber risk.

I can also speak to a new phenomenon we’re seeing, where adversary states like Russia, China and Iran are using AI to industrialize cyberattacks, and how the press around OpenAI hacking incidents is missing this other key component of the landscape that could be just as destructive.

Exit mobile version