Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. 'Yellow Teams' Are Defining the Future of AI Security In some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat. A small number of engineering teams are developing the defenses that organizations will need against future advanced AI attacks. They're also building the frameworks attackers will utilize to carry out those attacks. In April, Anthropic invited more than 50 organizations to participate in its Project Glasswing initiative to preview Claude Mythos, which the company claimed at the time was the most advanced cybersecurity AI. OpenAI followed suit shortly after, inviting organizations to play with its own GPT 5.5 under the Daybreak program. Since then, red teams — penetration testers — have been using the AI models to exploit their own companies' systems, and rival blue teams tried to detect and defend against those exploits. In the middle of it all are engineers, building both mitigations against the models' greatest threats and frameworks for mobilizing their greatest powers. In modern cybersecurity parlance, these are "yellow" teams, a term first introduced at Black Hat 2017 to bring developers into the security testing process. They're out defining what cybersecurity will look like for years to come. "Yellow team is a build team," explains Sam Curry, chief information security officer (CISO) at Zscaler, a Glasswing partner. "They'll say: 'Hey, Red, what tools could you use to do better attacks?' As if they were the engineering department behind a major attacker. They'll also turn to Blue and go: 'What would you like on defense that isn't supplied to you by your vendor community?'" Step Into the Room With Yellow Teams Yellow teams don't often build for red teams. Yet that's