AI Has Turned Vulnerability Disclosure Into an Hours-Long Cyber Threat
Databricks chief executive Ali Ghodsi says the chance of AI causing human extinction is “close to zero,” arguing that the more immediate threat is AI-assisted cyberattack. He says the time for attackers to turn disclosed software vulnerabilities into working exploits has shrunk from roughly two years to hours, requiring heavier investment in adversarial testing and AI-based defenses. Ghodsi also cites the pace of AI change as a reason Databricks should remain private for now.

The immediate AI risk, in Ghodsi’s view, is cyberattack—not takeover
Ali Ghodsi puts the existential risk from AI to humanity at “close to zero.” But he argues that AI has made a nearer-term security problem markedly more urgent: the time between a vulnerability becoming known and an attacker using it to break into a system has, by his estimate, fallen from roughly two years to hours.
That assessment contrasts with an OpenAI statement displayed during the interview. In a September 16 blog post, OpenAI wrote that the industry had not solved alignment and monitoring sufficiently to continue scaling “at maximum speed for much longer.” Ghodsi, meanwhile, argues that leaders should not frighten people with AI-takeover scenarios. He says such fears can leave people in a bad state and have consequences for mental health.
The existential, like, you know, hey, you know, humanity is, you know, AI takes over, that's, that probability is close to zero. Where there is risk is in cyber, because AI is just very good at breaking into things.
His analogy is the early internet. Once the world became connected, he says, an attacker could target systems anywhere; worms and viruses spread in an environment that had not yet been adequately secured. AI changes that environment again, in his view, because models are effective at breaking into things and now have many targets to work through.
The resulting damage and cost could be real, Ghodsi says; his point is that it belongs in a different category from human extinction. The practical response, he argues, is major investment in protecting software systems. Databricks participates in that work through Lakehouse, he says, a product that uses agents and AI for cyber work.
The distinction matters because Ghodsi sees AI as both a security accelerant and a source of useful applications. Treating cyber risk and takeover scenarios as the same problem, he argues, can make people broadly fearful of a technology whose benefits are already visible in customer deployments.
A disclosure now creates an hours-long defense problem
Ali Ghodsi describes Databricks’ security posture as an extension of his longstanding preference for “sky is falling” exercises. The company has worked on AI since 2013, he says, and conducts annual worst-case planning. Cybersecurity has become a central part of those exercises because Databricks holds highly sensitive data.
The company lets outside attackers attempt to penetrate its systems and reach what Ghodsi calls its most “sacred secrets,” then hardens defenses based on what those efforts expose. Databricks has increased that work over the past four years, he says.
In 2018 and 2019, Ghodsi says, an attacker might take two years to weaponize a disclosed vulnerability—to turn it into a way of breaking into a site. Now, he says, an organization can be attacked within hours of disclosure.
For Ghodsi, that compression is the concrete security problem demanding attention. It helps explain why Databricks has ramped up adversarial testing and why he places AI-enabled cyber defense ahead of an existential-risk framing. AI may create risks, he says, but the risk he regards as real is attackers gaining faster access to systems.
Agents are increasing data consumption across the business
Ali Ghodsi says Databricks is seeing acceleration “across the board,” rather than in a single narrow product line. His explanation is that agents are beginning to do more work inside companies—“almost as if every company on the planet doubled their employee count.”
Those agents do more with company data and draw more insights from it, he says. That raises consumption of Databricks’ platform; because its pricing model is consumption-based, increased usage translates into revenue growth and, in Ghodsi’s account, accelerating revenue.
He points to several uses of that demand. Zipline, which he identifies as a major Databricks customer, uses AI to automate medicine-delivery drones. Crisis Text Line uses large language models to detect self-harm among young people and help prevent it, he says. Cyber work is another application area: the technology that can help attackers break into systems can also be used to protect them.
Ghodsi singles out Genie, a Databricks product he describes as an analyst that can answer business questions such as how a product is performing, who is churning, or where a sales pipeline stands. He says Genie has significantly accelerated revenue growth.
Rapid change is Ghodsi’s case for staying private
Ed Ludlow asked whether the current AI-safety debate affected Databricks’ thinking about an IPO. Ghodsi says the company will go public eventually, but that preparing for an IPO would be a poor use of management time while demand for its software is high and the technology is changing rapidly.
A public company, he argues, would have to spend time reacting to each new crisis, assessing whether investors think “the world is going under,” and dealing with stock-price consequences. He would rather direct the company’s attention to the business: serving demand for AI and data work, including the cyber-defense uses he considers urgent.
In these big times of transition, you know, it's better to do those transitions in private.
Ghodsi notes that some public companies have gone private to manage transitions and later returned to public markets. Databricks, he says, will become public; he simply does not think the timing is right now.



