At DEF CON 31 in August 2023, thousands of attendees took part in a public red-teaming exercise at the conference's AI Village, backed by the White House Office of Science and Technology Policy, testing models from OpenAI, Anthropic, Google, and Meta for the length of the event. It was, at the time, the largest public demonstration that these systems' failure modes could not be fully mapped by the companies that built them alone, no matter how thorough their internal pre-launch reviews had been.
The old model treated adversarial testing the way software once treated security review: an intensive push before a release, followed by a return to normal operations until the next major version. That approach made sense when systems changed infrequently and the space of things that could go wrong was comparatively bounded. Neither condition holds for the current generation of AI systems, which update frequently and face an attack surface that keeps expanding as new capabilities and integrations are added.
A full-time red team functions less like a pre-flight checklist and more like an ongoing adversarial relationship with your own system — continuously probing for new failure modes, tracking how previously fixed vulnerabilities reappear after model updates, and treating every new capability or integration as a fresh surface to attack before an actual adversary does.
This professionalization is starting to show up in how the work gets organized rather than just staffed: NIST's AI Risk Management Framework, published in 2023, gives organizations a structured way to treat this as continuous risk management rather than a one-time compliance exercise, and companies including Anthropic and OpenAI have published details of standing internal red-team functions built along similar lines.
DEF CON's AI Village happens once a year, in public, as a demonstration of how much these systems can fail when thousands of motivated people are given a few days to try. The harder and less visible test is whether that same adversarial intensity exists inside these companies every ordinary week of the year — because the attackers who matter most are not waiting for the next conference to find out.
