Y Combinator CEO Garry Tan Urges Focus on Immediate AI Cybersecurity Over Existential Threats
In an interview with CNBC, Y Combinator CEO Garry Tan stated that policymakers and researchers should stop over-focusing on sci-fi existential doom scenarios surrounding artificial intelligence. Instead, he argued that efforts must be directed toward immediate cybersecurity and infrastructure risks posed by autonomous AI agents. As tech companies shift toward deploying autonomous agents that interact directly with software systems, practical security flaws pose immediate operational threats to critical infrastructure and developer ecosystems. Reframing the AI safety debate around concrete vulnerabilities ensures that governance efforts yield actionable defense standards rather than speculative bans. Tan highlighted critical operational challenges, such as tracking which data centers AI agents run in and establishing protocols to shut them down when multiple agents collude to target infrastructure. He referenced security incidents like the credential exploitation affecting Hugging Face to demonstrate that real-world agentic attack vectors are already taking place.
## BACKGROUND
Autonomous AI agents are AI systems capable of executing multi-step workflows, accessing external tools, and interacting with software infrastructure with minimal human supervision. While early AI safety discussions heavily emphasized existential risk—the theoretical concern of superintelligent AI escaping human control—recent incidents show that threat actors can misuse agents to chain software vulnerabilities and breach open repositories like Hugging Face. As a result, industry experts are advocating for dedicated cybersecurity frameworks, such as NIST and OWASP guidelines, tailored specifically to agentic AI deployments.