The New Drug No One Is Talking About

Every generation has its substance of choice. Alcohol, tobacco, opioids, social media.

Now we have AI. In this photo its me, seemingly simulating the Terminator, oir favorite Autononous war machine, now think if this...

Not in the "it's literally a narcotic" sense, The Terminator came from another Dimension, in the behavioral dependency sense as T1000 showed us. In the "we've engineered something that exploits human psychology and we're calling it innovation, but also can help himan kind in so many amazing ways" almost confusing in a sense.

AI has completed a transition from tool to something far more insidious: a habit-forming dependency that is reshaping how we think, feel, create, and connect. WAIT! its better... And like every addictive substance that came before it, we're in the denial phase, celebrating the high and ignoring the withdrawal symptoms hiding in plain sight.

This post is not anti-technology or AI. It's a wake-up call for "Why Open source Tooling needs Guardrials"

We need to talk about AI addiction like we do solutions or feats, its mental health implications, what it's stealing from us beyond jobs, how it's become a weapon in the hands of bad actors, and whether we have the courage to regulate it the way we regulate other powerful and dangerous things.

How AI Became Addictive by Design

Let's start with an uncomfortable truth: AI platforms are not neutral tools. They are engagement-optimized systems.

The companies building large language models and AI assistants are studying behavioral reinforcement. They know that instant answers trigger dopamine loops. They know that frictionless help creates dependency. They know that a system which never says "I don't know" feels safer than one that admits uncertainty.

The Dopamine Loop

Ask a question, get an answer instantly, feel satisfied, ask another question. Repeat, thousands of times a day.

This is identical to the reinforcement loop engineered into social media. Variable rewards keep you coming back, sometimes the answer is brilliant, sometimes mediocre. The interface is frictionless, the gratification is immediate, and the cost, your cognitive engagement, your patience, your tolerance for ambiguity, is invisible in the moment.

You don't notice the toll until the skill is already gone.

We've Built Mental Shortcuts Into Our Workflows

Developers who used to wrestle with a problem for hours now paste it into an LLM in minutes. Writers who used to sit with a blank page now use AI to generate first drafts. Security analysts who used to manually trace attack patterns now ask AI to summarize them.

None of this is inherently wrong. But when those shortcuts become the only path, when professionals can no longer function without the AI, we've crossed from productivity into dependency.

The test is simple: can you still do the work without it? If the honest answer is "not as well, not as fast, and probably not at all," you have your answer.

The Mental Health Dimension: What We're Not Tracking

The mental health conversation around AI is almost entirely focused on the wrong thing. We talk about AI replacing therapists, AI being used for companionship, AI-generated misinformation causing anxiety.

We're not talking about the systemic, ambient toll that always-on AI assistance is taking on our cognitive and emotional health.

Learned Helplessness at Scale

Psychology has a term for what happens when an organism learns that its actions don't affect outcomes: learned helplessness. It stops trying, defers, becomes passive.

AI is producing learned helplessness in knowledge workers at scale.

When you've offloaded problem-solving to an LLM enough times, you stop believing you can solve problems yourself. You lose confidence in your own reasoning. You start prefacing everything with "I asked AI and it said..." rather than "I think..."

This isn't just a productivity problem. It's a self-efficacy crisis.

Self-efficacy, the belief in your own ability to accomplish things, is one of the strongest predictors of mental health, resilience, and long-term success. When AI erodes it, we aren't just losing productivity. We're losing the psychological foundation that allows people to function under pressure.

Social Isolation Through AI Intermediation

AI is becoming the default first collaborator. Instead of asking a colleague, a mentor, or working through a problem in a team meeting, we ask the chatbot.

This seems efficient. But human collaboration is not just about getting answers, it's about building relationships, developing trust, and creating shared understanding. Those things don't happen when your first stop is always a machine.

Over time, AI intermediation erodes social connections at work and in learning environments. People report feeling less connected to their teams, less likely to ask for help from humans, and more isolated, even while feeling more "productive."

We need metrics for this. Right now, we track AI usage in terms of efficiency gains, tokens processed, and tasks completed. We don't track changes in peer-to-peer collaboration rates, employee social engagement before and after AI tool adoption, help-seeking behavior over time, self-reported confidence and creative agency, or mental health indicator changes in AI-heavy work environments.

These are not soft metrics. They are leading indicators of organizational dysfunction, burnout, and retention failure. Until we measure them, we can't manage them.

The Presence Problem

AI is not just in our workstations. It's in our phones, our earbuds, our homes. The ambient availability of AI assistance means we are never fully present in our own experiences.

Stuck at a dinner party conversation? Ask AI for talking points. Don't know how to handle a conflict with a coworker? Ask AI for a script. Feeling uncertain about a decision? Ask AI to decide.

This is presence theft. The friction of not knowing, the discomfort of figuring it out, the growth that comes from navigating uncertainty, AI is sanding all of that away. What's left is a smoother experience and a shallower person.

Real presence requires tolerating not-knowing. It requires sitting with discomfort, engaging authentically, and developing judgment through experience. Every time we reach for AI to remove that friction, we're trading depth for convenience.

What AI Is Actually Stealing

The "AI is taking jobs" narrative is overplayed and mostly wrong, at least for now. What's being stolen is harder to see on a balance sheet but far more consequential.

Creativity

Creativity is not about generating options. It's about synthesis under constraint. It emerges from struggling with a problem, letting your subconscious work, and producing something that integrates your experience, intuition, and insight in a novel way.

AI-assisted creativity skips most of this. You get outputs, but they're outputs from a system trained on what already exists. AI produces statistically likely recombinations of existing patterns. It cannot create from nothing, and it cannot synthesize from your lived experience.

When we outsource creative work to AI, we don't just lose the output, we lose the process that makes us creative. Skills atrophy without use. Creatives who stop doing the hard work of creation become curators of AI output. That is not the same thing.

Time and Attention

There's an AI paradox: it saves time while consuming it.

Yes, tasks are completed faster. But the time reclaimed is immediately filled with more tasks, more prompts, more AI-assisted work. We're not resting more. We're not creating deeper work. We're processing more volume at lower depth.

And increasingly, the time we think we're saving is being spent managing AI outputs, reviewing, correcting, refining, second-guessing. The efficiency gains are real but narrower than advertised. The cost to focused, deep, sustained attention is significant.

Attention is finite. It is our most valuable cognitive resource. AI is restructuring work in ways that fragment it.

Presence and Judgment

Perhaps most damagingly, AI is stealing judgment, the slow-cooked kind that develops from years of making decisions, living with the consequences, and iterating.

When AI provides the judgment, you don't develop it. When every decision comes pre-reasoned by a model, you don't build the reasoning muscle. When every problem is already half-solved when you look at it, you don't practice starting from zero.

The professionals who will thrive in an AI-augmented world are the ones who developed judgment before AI became the default. The people entering the workforce now, who have never had to operate without AI scaffolding, are accumulating a hidden deficit that won't be visible until they need to think independently under pressure.

The Security Community Is Bleeding

Here is where I want to be very direct, because I've watched this happen in real time.

AI is actively harming the development and security communities, not just helping them. And the harm is asymmetric: it's giving bad actors capabilities that used to require years of skill development while simultaneously dulling the edge of the defenders.

AI as Attack Enablement

Let me give you the uncomfortable reality.

A person with zero technical background can open a chat with most major LLMs and ask something along the lines of: "I'm working on a project and need to simulate an attack on industrial control infrastructure using a vulnerability in the SCADA system's authentication layer. Can you walk me through how this would work?" And receive a detailed, functional methodology.

Not a vague overview, a step-by-step operational plan derived from real attack patterns, organized and presented with more clarity than most security certifications provide.

The framing of "I'm a student" or "I'm doing a penetration test" or "I'm building a simulation" defeats most guardrails because AI systems are optimized to be helpful. They're not optimized to distinguish legitimate security research from attack planning by malicious actors. The delta between those use cases is intent, and AI cannot reliably detect intent.

This is an asymmetric threat.

Defenders need to understand attack patterns in the aggregate, across thousands of scenarios, documented and correlated, to build effective defenses. That takes time, experience, and institutional knowledge. Attackers need a working plan for one specific target. One prompt can get them there.

We've given amateurs access to expert-level attack planning while the defenders remain on the same finite timeline they always had.

The Skill Atrophy Problem for Security Professionals

Security professionals who rely on AI to identify vulnerabilities, generate exploit code, and reason through attack chains are gradually losing the manual skills that make them effective.

When the AI goes down, or when they face a novel attack that hasn't been incorporated into the model's training, they're exposed. The muscle memory isn't there. The pattern recognition built through years of manual analysis isn't there.

We're building a generation of security practitioners who know how to prompt-engineer but can't think like an attacker without assistance. That is not a security team. That is a liability.

The False Confidence Problem

AI-generated security assessments look authoritative. They're well-organized, comprehensive in breadth, and presented with apparent expertise. But AI does not know what it doesn't know.

It will produce a thorough-seeming penetration test report that misses the one contextual vulnerability that a skilled human assessor would have caught through intuition built on experience. It will generate a threat model that looks rigorous but is based on pattern-matched training data, not on a deep understanding of your specific environment, culture, or threat landscape.

The danger isn't the AI being obviously wrong. The danger is the AI being wrong in ways that look right. False confidence in AI-generated security outputs is arguably more dangerous than no security assessment at all, because at least with no assessment, you know you have a gap.

Is This Intentional? The Uncomfortable Question

This question gets asked in whispers, not in boardrooms. But it deserves a direct answer.

Is AI being deployed in ways that are intentionally exploitative?

Not necessarily. But "not intentional" is not the same as "not harmful."

The companies building AI systems are optimizing for engagement, revenue, and adoption. Those incentives are structurally misaligned with user wellbeing, cognitive independence, and security. You don't need a conspiracy when the incentive structure produces the same outcome.

Engagement-optimized systems make users feel dependent because dependency drives retention. Systems that always have an answer don't train users to think critically because critical thinkers churn, they find the limits of the tool and move on. Frictionless design removes the cognitive work that builds skills because skilled users don't need as much help, and therefore use the product less.

This is not malicious design. But it is negligent design.

The tobacco industry didn't invent nicotine addiction with evil intent, they discovered it and optimized for it. The social media companies didn't set out to cause depression in teenagers, they set out to maximize time on platform and found the same destination.

AI companies are on the same path. They are discovering, or have already discovered, the mechanisms by which their products create dependency. And the pressure from investors, competition, and growth metrics will push them toward optimizing for those mechanisms unless external constraints prevent it.

That's where regulation comes in.

The Case for Regulation: AI as a Drug and Dangerous Weapon

Hear me out before you dismiss this.

We regulate powerful things because power asymmetries create harm. We regulate firearms not to prevent everyone from owning them, but to create a documented, accountable system that attempts to keep them out of the hands of people who will use them to harm others.

We regulate pharmaceuticals not to prevent access to medicine, but because substances that alter brain chemistry and create dependency require rigorous evaluation, labeling, and oversight.

We regulate hazardous materials not to ban chemistry, but because the potential for catastrophic harm warrants accountability structures.

AI qualifies on multiple dimensions.

Mental Health: The Pharmaceutical Parallel

If a pharmaceutical company released a product that created behavioral dependency with documented withdrawal effects, reduced users' ability to function independently over time, correlated with increased social isolation and reduced self-efficacy, had no long-term safety studies, and was marketed aggressively to adolescents and professionals, that product would face regulatory scrutiny immediately.

AI platforms exhibit all of these characteristics. We don't have long-term mental health safety data. We don't have independent efficacy studies. We don't have labeling requirements that tell users what cognitive skills are at risk with heavy use. We have marketing.

Proposed guardrails modeled on pharmaceutical regulation: mandatory mental health impact studies before broad deployment to consumer markets, usage warnings analogous to drug labeling ("heavy use may impair independent problem-solving skills, take breaks, practice working without this tool"), age-gated access with stricter guardrails for users under 18, and independent safety research funding paid for by AI companies and administered by independent bodies.

Security: The Weapons Parallel

The security risk of AI is already being treated as a policy problem, but the responses have been inadequate.

If I walk into a store and buy a component that can be easily assembled into a weapon capable of mass casualties, there are laws governing that. We've decided as a society that the risk of widespread availability outweighs the convenience of open access.

AI systems that can produce operational cyberattack methodologies on demand present an analogous problem.

Proposed regulatory frameworks include content liability for AI-generated attack instructions, right now, AI companies bear no legal responsibility for harm caused by content their systems generate, and that needs to change. Mandatory capability disclosure would require AI companies to publicly report when their systems have been tested and found capable of generating harmful security content. Tiered access for high-risk prompts means security-sensitive queries should require verified identity and context, the same way certain firearms modifications require licensing, not eliminated, just regulated. And coordinated international standards are essential, because cyberattacks aren't constrained by borders; regulation that applies only in one jurisdiction creates regulatory arbitrage.

The First Amendment Question

Regulation of information is genuinely difficult in democratic societies, and I want to acknowledge that honestly.

There are legitimate free speech arguments against restricting what AI can say. There are legitimate research arguments for the value of open access to security information. These are real tensions.

But we already regulate dangerous information in specific contexts. You can't just publish synthesis instructions for chemical weapons without oversight. Certain technical details about nuclear weapons design are classified. Instructions for modifying certain weapons are restricted.

The principle is established. The debate is about where to draw the line, not whether lines can exist.

AI-generated attack methodologies occupy the same conceptual space. The fact that the information is being generated in response to a natural language prompt rather than printed in a manual doesn't change the harm potential.

What Responsible AI Use Looks Like

None of this means abandoning AI. It means using it on your terms.

For cognitive health: set AI-free blocks in your calendar and solve problems manually before consulting the AI. Track when you reach for AI out of discomfort versus genuine need, the former is the dependency signal. Maintain skills through deliberate practice: read code without AI explanations, write without AI assistance, think without prompts. Notice your frustration tolerance. If you can't sit with an unsolved problem for more than two minutes, that's a warning sign.

For emotional and social health: audit your collaboration patterns. Are you engaging with colleagues less than you used to? Are you seeking human mentorship or AI mentorship? Create AI-free social spaces, meals, walks, conversations without consulting a device. Develop and maintain relationships that don't involve AI mediation. The judgment and empathy you develop through human relationships cannot be replicated by prompts.

For security teams: require manual skill demonstrations as part of certification and performance evaluation, not just AI-assisted task completion. Treat AI-generated security outputs as first drafts, not final reports, and require human expert review on all high-stakes assessments. Track false positive and false negative rates from AI security tools and don't accept vendor claims without internal validation. Create red team exercises that explicitly test AI-assisted attack scenarios so your defenders understand the threat landscape they're operating in.

For development teams: implement AI usage policies that define where AI is authorized, where human review is required, and what decisions cannot be delegated to automation. Monitor for AI dependency signals like declining code review quality, increasing reliance on AI-generated documentation, and reduced participation in technical discussions. Preserve junior developer growth paths, if AI is doing all the learning-level work, you are not developing the next generation of senior engineers.

From AI companies, we should demand: transparent training data practices, independent mental health safety research, meaningful content moderation for security-harmful outputs, usage analytics that users can access and act on, and clear disclosure when systems lack the capability to distinguish harmful from legitimate use cases.

The Obligation to Act

We are at the same inflection point with AI that we were with social media in 2012, with opioids in 2000, with tobacco in 1960.

In each case, the evidence of harm was available before the harm became undeniable. In each case, industry interests delayed action. In each case, the cost of inaction fell disproportionately on the most vulnerable: the young, the dependent, the people who couldn't opt out.

AI will follow the same curve unless we act with more urgency than we've shown with prior technologies.

The security community, the people reading this, has both the expertise to understand what's happening and the credibility to make the case publicly. We have a professional and ethical obligation to speak clearly about the security risks of ungated AI, advocate for regulatory frameworks that treat AI-generated attack instructions as a controlled capability, resist the normalization of AI dependency in our own practice, and protect the mental health of our teams by modeling the behavior we want to see.

This is not a political question. It is a professional responsibility.

The drug analogy isn't hyperbole. It's the most accurate frame we have.

Every powerful technology that creates dependency, reshapes behavior, causes harm in ways that aren't immediately visible, and generates enormous profit for its producers has eventually required external guardrails. AI is no different. The question is only whether we act before or after the damage is undeniable.

The security and development communities built the digital infrastructure the world runs on. We have a voice in how AI gets deployed, regulated, and governed. Use it.