>Because the threat model is one-sided - if an AI attack fails, the controller simply moves to the next target. If an AI defense fails, the victim is fucked.
This was always the case? Security is asymmetric and attacker only needs to succeed once.