It was the night of November 30, 2022. ChatGPT had gone live a few hours earlier, and somewhere, someone typed an odd request: a rap about Kevin Mitnick, social engineering and magic. It named the company he worked for. The machine answered on the spot, in verse, as if it had known the man personally.
Who was on the other end of that keyboard? Hold that question. The answer is in the talk.
What matters right now is what that request gave away without meaning to. For the first time, anyone with a browser window had access to an intelligence that could write, research, explain and, as we'd soon find out, plan. It didn't ask for credentials. It didn't bill by the hour. It didn't sleep.
Someone who doesn't sleep on the other side
Almost twenty years earlier, I had learned the hard way what it means to have someone on the other side who doesn't sleep. I was the company's sysadmin, and a few days before, my boss had asked me the question every boss asks: are we secure? Confident, I said yes.
Then my phone rang. It was him. And he read my password out loud. Not something close to it. Mine. On his desk was a report from a consultant he'd hired without telling me. The consultant had broken into the company and taken over everything, starting from a single .doc file sent to HR. I hadn't seen a thing.
That room taught me more than any certification. It taught me that trust isn't a feeling: it's evidence. It taught me that the way in is almost never sophisticated: it's an attachment, a click, the daily routine of someone who was just doing their job. And it taught me that a competent attacker doesn't make noise.
That's how I left infrastructure and went into security: not out of calling, but out of wounded pride. With a decision made in that room that I still carry today: I never wanted to get owned again. Six months later, I was the one on the other side, running pentests and reading other people's passwords.
Why IA × IA
This project exists because that consultant, today, would be a machine. It maps your attack surface in minutes, finds the forgotten credential in the repo, writes the exploit, tests it, adjusts, and runs it. It does this against thousands of targets at once. And it will do it for you, too, if you know how to put it on your side of the board.
That's what IA × IA is about: the same AI producing two opposite outcomes, and what separates one from the other. In the attacker's hands, it finds the flaw and exploits it on the spot. No queue, no prioritization, no committee. In your hands, the same AI finds the same flaw and hands you a report. And then begins everything the attacker doesn't have: the prioritization, the bureaucracy, the sign-off, the sprint that's already full.
The difference isn't the model, which is the same. It's who turns the flaw that was found into a fix. The attacker is already winning because they detect and attack in the same motion. The race isn't about detection; it's about remediation. Machine-speed attacks call for machine-speed defense.
That demands something that makes a lot of security people freeze: the AI has to be free to act. Within limits, and limits are what this entire guide is about. But an AI that waits for a human to approve every IP block, every takedown of a fake site, every first-level containment isn't on your side of the board. It's standing in line with you. Detect. Decide. Act. Within limits, but act.
From talk to guide
IA × IA started as a talk. It became a public guide because the talk proved it worked: someone watched a version of it, walked out, took the idea and built Cyberbot, which reads the traffic that got past the WAF, analyzes the context, and blocks the attacker at the edge. From log to block in under a minute, in production. That's the result this site exists to repeat.
And it exists for the people on the outside. The most capable security models are restricted to a short list of large organizations. Meanwhile, a regional hospital, a credit union, a city government or a nonprofit becomes the target of a single person with an agent. That's why the guide is free, vendor-neutral, and built to be taken to your AI: the success stories show what already runs, the defense playbooks show what you can build, and Build your playbook helps you design your own, with the authority the agent can hold and the controls that need to exist.
Security can't become the Sales Prevention Department, the team that blocks AI in the business because it doesn't know how to govern it. AI is a business enabler. Security's job is to make it run safely, and to use that same AI to get safer. AI in favor of AI.