This is the kind of AI move I actually like on principle—and still don’t trust in practice.
An “open-weight” cybersecurity model that local businesses can run without sending their sensitive code to some outside provider sounds like the adult version of AI. Less blind faith. Less “just upload your crown jewels and hope the vendor behaves.” More control. More privacy. More sanity.
But it also opens a door that’s hard to close: if the model is good at finding security holes, it’s not just good for defenders. It’s good for attackers too. And the people who move fastest in cybersecurity are rarely the ones filling out compliance forms.
Based on what’s been shared publicly, a Belgian cybersecurity company called Aikido just launched an open-weight AI model meant to help with cybersecurity for local businesses. The pitch is pretty clear: there’s rising demand for defensive AI tools, and companies want to use AI without sending sensitive code to an external provider. This comes at a time when there’s growing fear that criminals are using AI to exploit software vulnerabilities, and Europe is leaning harder into region-specific security solutions.
That’s the surface story. The deeper story is about trust and control—who gets to inspect your software, where your code goes, and who benefits when powerful security tools become easier to run.
If you’ve ever worked in a company that takes security seriously, you know the moment that makes everyone tense: “Can we share this code with the vendor?” Legal says one thing. Security says another. Engineering says, “We just need the tool to work.” And leadership says, “What’s the risk if we don’t do it?”
A model you can run locally changes that conversation. Imagine a mid-sized business with a small dev team. They want AI help scanning their code for mistakes, but they can’t stomach uploading proprietary code or client details to a third party. An open-weight model, run in-house, gives them a way to get the upside without making a huge trust leap. That’s real value. That’s not hype.
It also pushes back on a pattern I’m tired of: security becoming subscription-shaped. You don’t just buy tools anymore; you rent access to them, usually in a way that pulls data out of your environment. Even when the vendor is honest, it creates a dependency: your safety is tied to someone else’s uptime, policies, pricing, and priorities. Local tools reduce that dependency. That’s a win for businesses that don’t want to be trapped.
Here’s where I get uncomfortable: making defensive capability more accessible often makes offensive capability more accessible too. If criminals are already using AI to find and exploit vulnerabilities, then releasing a model that helps spot vulnerabilities becomes a double-edged move. People will argue, “Attackers already have better tools.” Maybe. But “already” is doing a lot of work there. Lowering the cost and effort of finding flaws changes the math for low-skill attackers. It turns “hard but possible” into “easy and scalable.”
Say you’re running a small online store. You have one developer. You don’t patch fast because you’re busy shipping features that keep you alive. A criminal doesn’t need to be a genius anymore; they need a workflow. AI can give them that. If a defensive model leaks into the wrong hands—or if similar capabilities are easy to copy—the number of people capable of causing harm can jump. Security isn’t just about how strong the locks are. It’s also about how many people are trying the doors.
Still, I don’t think the right response is “keep security AI locked up forever.” That tends to concentrate power in a few big companies, and it quietly tells everyone else, “You can’t be trusted with your own defense.” That’s a bleak future: a world where small firms and public institutions can’t secure themselves without paying rent to a handful of providers, while attackers find ways around it anyway.
What I do want is honesty about what this is: a shift in who holds capability. Aikido is betting that local demand is real—and I believe it is. Europe’s interest in region-specific solutions makes sense too. Data rules are tighter, trust boundaries are different, and the tolerance for “just send it to an external provider” is lower.
But “local” doesn’t automatically mean “safe.” A local model can be misused internally. It can be run carelessly. It can be pointed at codebases by people who don’t understand what they’re looking at. And it can create a false sense of security: “We ran the AI scan, so we’re fine.” That’s how companies get hurt—by thinking a tool replaced responsibility.
The best-case scenario is that tools like this help raise the security baseline for the boring middle of the market: the companies that aren’t huge, aren’t tiny, and are usually under-defended. The worst-case scenario is that it accelerates the vulnerability arms race, where the defenders get slightly better but the attackers get faster, cheaper, and more numerous.
I’m left with one question that actually matters more than the launch itself: if we make powerful security AI easier to run locally, what level of openness is worth the risk of also making powerful attack workflows easier to build?