The question I get most often — at conferences, at readings, from journalists — is some version of: "How has AI changed the threat landscape?" It's a reasonable question. The answer I usually give is compressed because there's only so much you can say in a panel segment or an interview, and I want to try to say it properly here.

What AI Does Well

The first change is real and significant: AI has made certain kinds of threat detection much better. Pattern recognition at scale, anomaly detection in network traffic, behavioral analysis of large datasets. This isn't marketing. It has saved money, caught things that would have been missed, and increased the baseline competence of defensive operations at organizations that can afford to deploy it well.

This improvement is genuine and worth acknowledging before I describe the other change, which cuts the other way.

The Distinction That Gets Missed

Detection and assessment are different cognitive tasks. Detection is recognition: is this thing on the list of things I've been trained to flag? Assessment is interpretation: what does this mean, in this context, given what I don't know?

Detection can be delegated to a well-trained system. Assessment — real assessment, the kind that produces actionable understanding of a novel threat — cannot. Not yet. Possibly not ever, in the same way. The confusion of detection for assessment is, in my view, the most consequential misunderstanding currently operating in the threat intelligence space.

The most dangerous threat actors are those who don't look like prior threat actors. They've read the same papers on AI-based detection that the defenders have, and adjusted accordingly.

There's a further problem, which is the one that preoccupies me more: a monoculture of detection creates a monoculture of expectation. When everyone uses the same AI-based detection systems, trained on the same datasets, everyone's blind spots converge. The unseen becomes uniformly unseen. This is a gift to anyone operating in that shared blind spot.

What This Means for Fiction

Knox operates in that space — the gap between what systems are trained to flag and what is actually happening. I've been writing him there for seven books. What changes in Kill Latency is that his adversary operates there too, not because she found the gap by accident, but because she understood from the beginning that the gap was the only viable operating environment. She is, among other things, a student of the same detection literature the defenders use.

Fiction is useful here because it can hold the ambiguity that the security literature tends to resolve prematurely. A detection system confident it has covered the threat surface is, in a certain light, more dangerous than one that admits uncertainty — because the confidence shapes what operators choose to look at. Knox operates in the space that confidence leaves unexamined. So do his adversaries.

The question I keep returning to, across all eight books, is what happens when the adversary has read the same literature the defenders have. When the detection logic is known. When the pattern of the search becomes the map for avoiding it. The answer, in the Knox series, is that the contest moves somewhere else — somewhere the frameworks haven't caught up to yet.