An hour over a Colorado pass, a sentence in a Google ballroom, and the disappearance of the one thing every previous technology revolution quietly handed us: time
Pueblo, Colorado. Hours before sunrise. To the west, the mountains we would have to cross were still dark on dark, more shape than range. A slight breeze worked across the ramp. At altitude, that breeze would magnify tenfold. We had been at the preflight since four in the morning. Weight and balance. Fuel. Oil. Water. The satellite phone. The short list of loved ones who knew our route.
It was still dark over the Sangre de Cristos when I pulled the chocks. The airplane was a Cessna 172 from the early 1980s — boxy, honest, underpowered, the kind of trainer that has carried two generations of student pilots and almost nothing else. The cockpit would climb to ninety degrees once the August sun was up. Bernie — a fellow pilot, a friend — had gotten us out before sunrise on purpose. Two pumps on the primer. A turn of the key. The engine chugged to life.
Wind matters in the mountains. The earlier you go, the lighter it blows out of the west. And a westerly wind hitting a ridgeline does not just slow an aircraft down. It falls. On the lee side of a peak, the air collapses downward in a column that can swallow a small airplane’s entire climb rate. Full power. Best rate of climb. Still descending.
That is what we got.
We had planned for it. We circled twice on the leeward side of Mosca Pass, clawing for altitude in slow, patient turns, and approached the pass at a forty-five-degree angle so that if the downdraft won, we could turn away without committing. The winds at the top were eleven knots — forgiving, by mountain standards. We crossed in a five-hundred-foot-per-minute descent. Falling, but falling on our own terms. On the other side, the world opened into pink sand dunes and flat, hot, red earth running all the way to Utah.
It took an hour of climbing just to be in position to try.
A couple of years later, Kelly and I made the same crossing in a different airplane — turbocharged, air-conditioned, full glass cockpit. That airplane could climb a thousand feet a minute at altitude. The 172 could do, at best, a tenth of that. There was no circling. No forty-five-degree hedge. The pass that had once required an hour of strategy slid beneath us like a footnote.
I had time, on the second flight, to think about the first one. The heat of the ninety-degree cockpit. The slow spiral. The careful arithmetic of altitude and wind. And then I thought further back — a hundred and eighty years ago, people had crossed those same mountains with wagons, horses, and mules.
Three eras of the same crossing. A hundred years from now, I thought, the trip will look nothing like any of them. Inventions we have not thought of yet will be ordinary.
That memory is the load-bearing wall of an argument I have been making, in conference rooms and client meetings, ever since. The argument is not really about airplanes. It is about a sentence I heard in a hotel ballroom and have not been able to put down.
Jon Ramsey, vice president and general manager of Google Cloud security, was opening a moderated session.
“The other day, someone said to me,” Ramsey told the room, “‘Today’s pace of change is faster than it has ever been, and the slowest that it will ever be.'”
I nodded in the moment. Most of the room nodded.
It was the kind of sentence that follows you onto the airplane home.
Ramsey was not offering a slogan. He was offering a derivative — a description of how the rate of change is itself accelerating. Not the speed. The acceleration of the speed.
And the longer I sat with the sentence, the more it did something quiet and unsettling to the way I think about my work.
Every prior technology revolution arrived with a gift nobody bothered to name. Time.
The wagon-to-172 leap took roughly a hundred and eighty years. The 172 to the glass cockpit, about forty. Radio went commercial in the 1920s and got two decades to build the regulatory and editorial scaffolding around itself before the next thing arrived. Aviation went from canvas biplanes to jet airliners in roughly thirty years, and the FAA grew up alongside the airframes — an institution finding its shape inside a moving cloud. Television. The credit card. The mainframe. The personal computer. Each one rearranged the world. Each one handed us a generation, give or take, to redesign jobs and laws and schools and security models around it.
The web is the closest analog to what comes next. Even the web gave us a decade. We argued about cookies and copyright for years before any of it became urgent.
That was the pattern. Disruption was real. But disruption arrived with a buffer. The buffer was what let institutions catch up. The buffer was why most prior technology revolutions were survived rather than endured.
The buffer is gone.
ChatGPT crossed a hundred million users in two months — faster than any consumer technology in recorded history. Foundation models, the same general class of system that powers chatbots, are now writing exploit code on their own. They are chaining attack paths through unfamiliar infrastructure. They are surfacing vulnerabilities that experienced humans had not noticed. This is not a future-state slide in a vendor pitch. It is being demonstrated, today, against production systems.
The years to reorganize, retrain, regulate — compressed into months.
Nick Bostrom saw this coming, sort of, in 2014.
When his book Superintelligence arrived, most of the headlines fixated on its doomsday scenarios, which were lurid and easy to dismiss. The more useful idea in the book has aged better. Bostrom called it the control problem, and the argument, stripped of its science-fiction wrapper, is this: the gap between when a capability emerges and when society can govern that capability matters more than the capability itself. Solve governance and oversight before the capability arrives. Once the capability is loose, the curve outruns your ability to catch up.
Bostrom was writing about superintelligence. The argument generalizes.
Cloud. Mobile. Social. Machine learning. Every meaningful leap of the past decade shipped capability before the institutions around it were ready to govern it. We mostly muddled through, because the leaps still gave us room to muddle.
The leap in front of us will not.
There is a kind of executive every reader of this knows — still asking whether artificial intelligence is more accurate than a human at the basic, expensive stuff. Contract review. Document summarization. Code review.
It is.
My honest counsel for the people still running that comparison is to step out of the doorway. The colleagues already leaning in have done the math. They have accepted that AI makes mistakes. They have decided to use it anyway, because that is the price of admission to whatever comes next. They are not waiting for certainty. They are already three problems ahead.
This is the uncomfortable part. The instinct to wait — to pilot, to study, to socialize, to align — was, for thirty years, the mark of a serious operator. Caution was a virtue because the buffer was generous enough to absorb it. The buffer was the reason caution worked.
The buffer is what changed.
The traditional chief information security officer — the person whose pager goes off when something is on fire — has spent two decades being measured on the implementation of controls. Frameworks. Audits. Maturity scores. Five-year roadmaps presented to boards in handsome decks.
The half-life of a security architecture decision used to be five to seven years. It is measured in quarters now. On some questions, weeks. The roadmap is no longer scripture. A two-year strategic plan that does not get re-examined every quarter is a museum piece by the time it ships.
The work that matters now is not implementing controls. It is compressing decision cycles.
Three things, and most security organizations are doing none of them well.
Shorter horizons. Plan in quarters, not years. Review more often. Be willing to delete your own work, including the part you presented to the board with a clean color-coded chart eight months ago.
Automate the decision, not just the action. Most security automation still keeps a human in the middle, deciding whether to act on what the machine already knows. That human, once the safeguard, is now the bottleneck. Where the consequence is reversible, push the decision to the machine. Reserve the humans for the calls that actually require them.
Rehearse the leap, not the breach. Most tabletop exercises walk through scenarios the team already knows how to handle — a stolen laptop, a phished credential, a misconfigured bucket. Run the one nobody is rehearsing. The scenario where an AI-capable adversary owns the cycle-time advantage. Where the attacker, machine-driven, is iterating faster than your meeting cadence. Where do you lose? What would you have to be doing today to have a chance?
That gap is the real backlog. Everything else is a headwind. Or worse, a downdraft.
There is something you learn in your first weeks of flight training that has nothing to do with airplanes.
The runway behind you is useless.
You cannot taxi back to it. You cannot recover the feet you have already burned. The only runway that matters is the runway in front of you, right now, and what you do with it before it ends.
Every prior generation of technology leaders got to use the buffer. They got the wagon-to-172 century. They got the 172-to-glass-cockpit decades. The years between the cookie and the regulation. Between the credit card and the credit bureau. Between the web and the law.
That is over.
The companies that thrive over the next decade will not be the ones with the best controls. They will be the ones with the shortest decision loops, run by leaders who stopped waiting for the dust to settle.
The dust is not going to settle. It is going to keep moving.
Plan shorter. Decide faster. Swing anyway. You are going to miss. A lot. It is the only way to get better.
The last time I crossed Mosca Pass, I barely noticed it go by. I wasn’t at the controls. I was in the back of a 737. Somewhere underneath us, the ridgeline I had once spent an hour climbing toward in a Cessna 172 slipped away almost unnoticed, and I remember thinking how quickly the difficult had become ordinary.
A hundred years from now, a hundred years feels generous.
Frequently Asked Questions
What does “the vanishing buffer” mean in cybersecurity?
The vanishing buffer refers to the shrinking amount of time organizations have to adapt to major technology changes. In cybersecurity, this means leaders can no longer rely on long planning cycles because AI-driven change is accelerating faster than traditional strategies can keep up.
Why is AI changing cybersecurity decision-making?
AI is speeding up both innovation and risk. Attackers can use AI to find vulnerabilities, automate activity, and move faster through environments, which means security teams need faster decision loops, shorter planning horizons, and more adaptive response models.
Are traditional cybersecurity roadmaps still useful?
Yes, but they need to be reviewed more often. A two- or three-year roadmap that is not revisited quarterly can quickly become outdated as AI, cloud, and threat activity continue to evolve.
How should security leaders respond to the pace of AI change?
Security leaders should plan in shorter cycles, revisit decisions frequently, automate where risk is reversible, and rehearse scenarios involving faster, AI-enabled adversaries rather than only familiar breach scenarios.
