Skip to main content
Live
Main content

GC Cybersecurity's Tarique Mustafa: AI security can't be bolted on

At MIT Technology Review's EmTech AI, the GC Cybersecurity cofounder argues legacy defenses are buckling as AI expands the attack surface.

Jaeden Schafer
Editor in Chief · · 4 min read
GC Cybersecurity's Tarique Mustafa: AI security can't be bolted on

GC Cybersecurity cofounder Tarique Mustafa used the EmTech AI stage on May 1, 2026 to deliver a blunt message: enterprise security has to be rebuilt with AI at the core, not patched on after the fact. Speaking in a session titled 'Cyber-Insecurity in the AI Era' at MIT Technology Review's conference, Mustafa argued that defenses already strained before generative AI are now visibly cracking under it. The session was presented by GC Cybersecurity, where Mustafa serves as CEO and CTO.

His framing was direct. 'Cybersecurity was already under strain before AI entered the stack,' Mustafa said. 'Now, as AI expands the attack surface and adds new complexity, the limits of legacy approaches are becoming harder to ignore.' His prescription, in his own words: 'security must be rethought with AI at its core, not layered on after the fact.'

The credibility behind the argument is the resume. Mustafa has 20+ years of technical leadership in the security industry, including senior roles at Symantec, DHL Airways IT, MCI WorldCom, EDS, Andes Networks, and Nevis Networks, where he served as Principal Architect on next-generation monitoring, event correlation, IDS/IPS, and SSL/IPSec systems. He was the founding CEO and CTO of NexTier Networks, a Silicon Valley data leak prevention vendor, before launching GC Cybersecurity and its compliance spinout Chorology, Inc.

Key facts

  • 01Tarique Mustafa, cofounder and CEO/CTO of GC Cybersecurity, presented 'Cyber-Insecurity in the AI Era' at EmTech AI on May 1, 2026.
  • 02Mustafa architected the AI algorithms powering GC Cybersecurity's 4th and 5th generation autonomous data leak protection platform.
  • 03He brings 20+ years of technical leadership, with prior senior roles at Symantec, MCI WorldCom, EDS, and Nevis Networks.
  • 04Mustafa also founded data compliance spinout Chorology, Inc. and previously served as founding CEO/CTO of NexTier Networks.
  • 05He holds multiple USPTO patents and earned a Rotary International Scholarship for doctoral studies at USC.

At GC Cybersecurity, Mustafa architected the core AI algorithms behind the company's 4th and 5th generation fully autonomous data leak protection and exfiltration platform. The pitch is that classification, DLP, and data security posture management — three categories long handled by separate point products — collapse into a single autonomous system once AI does the heavy lifting. That is a different posture than most incumbent vendors, who have spent the last two years adding AI assistants to existing consoles.

Mustafa architected the core algorithms behind GC Cybersecurity's 4th and 5th generation autonomous data leak protection platform, drawing on 20+ years of security leadership.
Jaeden Schafer

The backdrop matters. Generative AI has handed attackers cheap phishing at scale, deepfaked voice and video, and rapid vulnerability discovery, while defenders are still wiring large language models into SOC workflows. Mustafa's argument is that retrofitting will not close the gap because the underlying assumptions — perimeter, signature, rule — were built for a slower threat model.

Mustafa's technical pedigree spans knowledge representation, inference calculus, and AI planning, and he holds multiple approved and pending USPTO patents. He earned a Rotary International Scholarship for doctoral studies in computer science at USC, where he also holds master's degrees in engineering and computer science, plus a bachelor's in mechanical engineering from NED University of Engineering & Technology in Pakistan.

GC Cybersecurity's spinout, Chorology, focuses on the compliance side of the same problem: knowing what sensitive data exists, where it lives, and whether its handling violates regulation. That is the unglamorous half of the AI security story, and the half regulators have been most aggressive on, particularly around training data provenance and personal information leakage from model outputs.

The skeptic's case is straightforward. 'AI-native' has become a marketing label as much as an architecture, and every legacy DLP and EDR vendor now claims it. Buyers cannot easily tell whether a platform was genuinely designed around autonomous agents and machine reasoning or whether an LLM was wired onto a 2018 rules engine. Mustafa did not, in the EmTech session, publish benchmark numbers that would settle the question.

Related · from this week
GC Cybersecurity's Tarique Mustafa: rebuild security with AI at the core, not bolted on
Jaeden Schafer · 4 min read →

GC Cybersecurity's bet is that the security stack consolidates the way the observability stack did a decade ago, with the AI-native entrants taking share from the suite vendors. That thesis has been tested before — by every startup that pitched against Symantec, where Mustafa himself once worked. The difference this cycle is that the threat actors are also AI-native, and that asymmetry is what makes the bolted-on approach look increasingly untenable to anyone running a real security operations center.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

GC Cybersecurity's Tarique Mustafa: rebuild security with AI at the core, not bolted on
Security

GC Cybersecurity's Tarique Mustafa: rebuild security with AI at the core, not bolted on

At MIT Technology Review's EmTech AI, the GC Cybersecurity cofounder argues legacy defenses can't keep up with AI-expanded attack surfaces.

Jaeden Schafer4 min read
HPE and Oak Ridge pitch sovereign AI factories at EmTech AI
Business

HPE and Oak Ridge pitch sovereign AI factories at EmTech AI

Chris Davidson of HPE and Arjun Shankar of Oak Ridge argued data control is now a strategic asset for governments running national AI.

Jaeden Schafer4 min read
Anthropic logo
Security

Cybersecurity researchers say Anthropic's Fable blocks even routine code reviews

Fable's keyword-triggered guardrails reject benign security work, falling back to Claude Opus 4.8 whenever 'cybersecurity' surfaces in a prompt.

Jaeden Schafer4 min read