Read Time: 15 minutes
TL;DR
In May, Pope Leo XIV published Magnifica Humanitas, his first encyclical, and he devoted it entirely to artificial intelligence. It runs to 245 paragraphs, and most of the commentary so far has come from theologians, ethicists and technology executives. I read it as someone who has spent a career breaking and defending systems, and I found a document that reaches, by a very different road, several of the conclusions my field reaches by experience: concentrated power is a single point of failure, technology is never neutral, a machine cannot carry responsibility, and the most dangerous systems are the ones where a human being has been engineered out of the decision. Its central demand, that AI be “disarmed”, is easy to dismiss as a metaphor. Read from the security chair, it is closer to a requirements list. This is what I think it gets right, where I think it is too optimistic, and what a CISO or an AI builder can take from it on Monday.
A note on what this is. This is not a theological review, and I am not the right person to write one. It is a reading of a public document by a security practitioner, on its merits, the same way I have read threat reports, regulations and resignation letters on this blog. Quotations come from the official English text published by the Vatican, and paragraph numbers are given so you can check them.
Why a security person should read this
The Church has done this before. In 1891, Leo XIII published Rerum Novarum in response to the industrial revolution, and it shaped a century of thinking about labour, property and the state. Two days after his election in May 2025, Leo XIV told the cardinals that he had taken his name partly in honour of Leo XIII, at a time when the Church faces “another industrial revolution”. Magnifica Humanitas, signed on 15 May and presented on 25 May 2026, is that same exercise for the age of AI, and its subtitle says so plainly: “on safeguarding the human person in the time of artificial intelligence”.
You do not need to share its faith to find it useful. What makes it worth a security professional’s time is that it is a serious attempt by a global institution with no product to sell to say, in plain language, what AI must not be allowed to do to people. Most of what we read about AI comes from vendors, investors or regulators drafting under lobbying pressure. This comes from somewhere else, although the industry was not absent: one of the speakers at the presentation in the Synod Hall was Chris Olah, a co-founder of Anthropic. Either way, it lands surprisingly close to home.
It opens with a choice, framed through two biblical images: humanity is “today facing a pivotal choice: either to construct a new Tower of Babel or to build the city in which God and humanity dwell together” (¶1). Strip the imagery and you have an architecture decision: build one tower that concentrates everything, or build something distributed, accountable and shared. Anyone who has designed for resilience knows which one survives contact with an adversary.
“Technology is never neutral”
The sentence I would put on the wall of every AI lab is in paragraph 9: technology “is never neutral”, because it “takes on the characteristics of those who devise, finance, regulate and use it”.
Security people learn this the hard way. Every system encodes a threat model, and the threat model is a list of choices about who matters and who does not. A feature that makes a product easier for its owner to monitor is, from another angle, a surveillance capability. An “assistant” that reads your mail to help you is also a component with access to your mail. The encyclical’s point is moral, but the engineering version is identical: you cannot understand a system without understanding who built it, who pays for it and who controls it.
Concentration is a single point of failure
The thread that runs through the whole document is power. The encyclical observes that the main drivers of development today are “private, often transnational, parties”, and that technological power has taken “an unprecedented, predominantly ‘private’ aspect” (¶5). It counts patents, algorithms, digital platforms, technological infrastructure and data among the goods meant for everyone, and warns that keeping them “concentrated in the hands of a few” creates a new imbalance (¶67). It asks for “transparency, accountability and meaningful forms of participation”, including “independent checks, transparency regarding algorithms, equitable access to data and avenues for recourse” (¶71).
Its sharpest lines on this are in paragraph 107. Unless the ethical frameworks built into AI are open to public debate, it warns, “those who control AI will impose their own moral vision, which will become the invisible infrastructure of these systems.” And then: “A more moral AI is not enough if that morality is determined by a few.”
The Church frames this as justice. I read it as systemic risk, and my field made that case more than twenty years ago. In September 2003, seven security researchers (Dan Geer, Rebecca Bace, Peter Gutmann, Perry Metzger, Charles Pfleeger, John Quarterman and Bruce Schneier) published CyberInsecurity: The Cost of Monopoly through the Computer & Communications Industry Association. Their target was Microsoft’s dominance of the desktop, and their thesis fits in one line from the report: “monocultures create aggregated risk like nothing else.” When nearly every machine runs the same code, one flaw reaches all of them and failures cascade. The paper cost Geer his job as CTO of @stake within days of its release. Time has proved it right.
In July 2024, a single faulty update from one security vendor took down some 8.5 million Windows machines worldwide, by Microsoft’s own count, and within hours grounded flights and disrupted hospitals and banks. Nobody attacked anything; the monoculture did the damage on its own. Now picture the same concentration applied not to endpoint agents but to the models that write our code, triage our alerts, answer our customers and, increasingly, act on our behalf. A handful of providers, a handful of model families, a handful of cloud regions. Swap “operating system” for “foundation model” and the 2003 report reads as if it were written this year. Ethics aside, it is the largest single point of failure we have ever built, and a target every capable state will study.
I made a related argument in Pace the Frontier, Defend the Valley: whoever controls the summit does not control what is already loose in the valley. The encyclical adds the mirror image. Whoever controls the summit also becomes the summit, and everything below inherits its failures and its values.
What “disarm AI” means from the security chair
The phrase that went around the world was the Pope’s call for AI to be “disarmed”. The encyclical argues that “merely regulating it is insufficient; it must be disarmed, welcoming and accessible”, and then sharpens the idea into something every security architect will recognise: “To disarm means discrediting the assumption that technical power automatically confers the right to govern” (¶110).
That sentence is the principle of least privilege, written by someone who has never read a hardening guide. Capability is not authority. The fact that a system can do something does not mean it should be allowed to, and the fact that a company can build something does not give it the right to decide how everyone else lives with it.
In practice, “disarming” an AI system looks a lot like the controls we already know and rarely apply to AI:
- Scope what it can reach. An agent with shell access, git credentials and a deadline is armed. My last article was about exactly that: a coding agent that published personal data and live tokens because nothing stood between its permissions and the outcome.
- Keep a human on irreversible actions. Payments, deletions, publication, anything that touches a person’s rights.
- Make it traceable. If you cannot reconstruct what the system did and why, you cannot hold anyone accountable for it.
- Do not let the builder be the only judge. Independent testing, independent audit, independent red teams.
We have known all of this for years. The new part is a moral authority with more than a billion followers saying it out loud.
“No algorithm can make war morally acceptable”
The most direct passage for anyone in security or defence is on war, and it is categorical: “it is not permissible to entrust lethal or otherwise irreversible decisions to artificial systems. No algorithm can make war morally acceptable” (¶198). AI, it adds, can only make conflict faster and “more impersonal, lowering the threshold for resorting to violence”.
Unusually for a document of this kind, it names my field directly. Paragraph 183 lists “cyberattacks, information manipulation, campaigns of influence and the automation of strategic decisions” among the new forms of conflict, and notes that because many technologies are “intrinsically ambivalent”, “what is created for defense can be rapidly repurposed for offense, and the fine line between protection and aggression becomes blurred.” Anyone who has done vulnerability research knows that sentence by heart. The same model that finds a flaw for a defender finds it for an attacker. Last month I wrote about an AI-safety researcher who resigned warning of “systems that can hack anything”, and then about a threat report showing that the distinguishing feature between attackers is now intent, not sophistication. An encyclical cannot stop a state from automating offensive operations. What it can do is name the line clearly: the decision to cause irreversible harm to a human being must stay with a human being who can be held to account for it. That is a line worth defending in every procurement and every rules-of-engagement document, cyber included.
Surveillance is a new form of power
The encyclical describes the mechanism precisely. When every action, from movements to purchases to relationships, leaves a trace, “a new form of power emerges, namely the power to profile, predict and influence behavior, often without individuals being fully aware of it” (¶171).
This is the part I would hand to anyone who still says “I have nothing to hide”. Reading your messages is the least of it. A system that knows enough about you can predict you, and a system that can predict you can steer you. I have written about how states use spyware to coerce other states; the same capability, aimed at citizens and powered by AI, scales from targeting a minister to profiling a population. And the personal AI assistants now arriving, which hold our memory, our mail and our calendar in one place, are the richest profile ever assembled about a human being. Data minimisation, local processing and strict separation of who can see what sound like compliance chores. In practice, they are what keeps a tool from becoming a leash.
Truth is a security property
The encyclical treats truth as “a common good and not the property of those with power or influence”, and calls for “an ecology of communication”, with rules that make content selection more transparent and protect personal data (¶137). It is blunt about the threat: “Disinformation did not begin with AI, yet today it finds a powerful amplifier in AI” (¶132).
From the security side, I would go further: the integrity of what we see and hear is now an attack surface. Voice cloning has turned the old “CEO fraud” call into something that sounds exactly like the CEO. Synthetic video makes evidence negotiable. Disinformation is no longer a craft; it is a pipeline. Media literacy helps, but it is not enough. You need provenance for content, verification procedures that do not rely on recognising a voice or a face, and organisations that train people to verify through a second channel before they act. Authentication used to be about machines proving who they are to each other. It now has to cover reality itself.
Work, and the workers no one sees
On work, the encyclical quotes the Vatican’s 2025 note on AI, Antiqua et Nova: while AI “promises to boost productivity by taking over mundane tasks, it frequently forces workers to adapt to the speed and demands of machines”, and can “subject them to automated surveillance” (¶150). I explored the economics of that in The Death of the Job. The security angle is narrower but real: workplace AI is usually also workplace monitoring, and the telemetry that measures productivity is the same telemetry an attacker would love to steal. And behind every model is a supply chain of people whose working conditions are invisible to the companies that rely on them. The encyclical names them: millions doing “data labeling, model training and content moderation”, many of them “young people, predominantly women, working under demanding conditions for minimal wages” (¶173). We audit our software suppliers. Very few of us audit the human supply chain behind the AI we buy.
A machine cannot carry responsibility
The encyclical is plain about what these systems are not. So-called artificial intelligences “do not undergo experiences, do not possess a body, do not feel joy or pain”, and they do not “bear responsibility for consequences” (¶99). It then turns directly to the people building them: “Developers, therefore, bear a particular ethical and spiritual responsibility, for every design choice reflects a vision of humanity” (¶111). And its conclusion opens with a line from Saint Paul that could hang over every engineering team: “Let each builder choose with care how to build” (¶229).
This is the most useful idea in the whole document, because it points exactly to where AI deployments fail day to day. “The model decided” is not an answer an auditor, a regulator or a court will accept, and it should not be one we accept internally. Every automated decision needs an owner with a name. Every agent needs a human who is accountable for what it is allowed to do. If you cannot name that person, the system is not ready.
Where I would push back
Read from the security chair, the document also has gaps worth naming.
“Disarm” is easier to say than to engineer. The capabilities that worry the encyclical are dual-use by nature. The same model that writes a phishing campaign writes the training to detect it. You cannot disarm a capability that is general-purpose; you can only control who uses it, for what and with what oversight. The encyclical’s principles point in the right direction, but it leaves the hard engineering to the rest of us. That is probably the right division of labour, but it should be said.
Accessibility and diffusion pull in opposite directions. The document wants technology freed “from monopolistic control” and opened “to discussion and debate” (¶110), and its critique of concentration is one I share. But from a security standpoint, wider access also means wider access to offensive capability, as the threat reports this year have shown. Decentralising power and containing misuse are both right, and they are in tension. I would rather say that out loud than pretend the tension away.
Regulation has its own risks. Not everyone who read the encyclical welcomed it. Some technology investors argued that the rules it calls for could themselves become tools of state surveillance, and some commentators found it too measured to change anything. Those are fair challenges. Any regulatory regime strong enough to constrain a powerful AI company is strong enough to be abused by a powerful government, and security people should be the first to say so.
So what
Strip away the theology and the scripture, and Magnifica Humanitas asks the people who build and secure AI for five things I would sign as a security architect:
- Avoid the single tower. Diversify providers and models for critical functions, and treat AI concentration as the systemic risk it is.
- Separate capability from authority. Least privilege for every agent; a human on every irreversible action.
- Make it traceable. Logs, provenance and audit trails good enough to reconstruct what happened and who decided.
- Minimise the profile. Collect less, keep it closer, and assume anything you centralise will one day be stolen or misused.
- Name the owner. No automated decision without a human who answers for it.
None of these require faith. They require the discipline our field already preaches and rarely applies to AI. It is not every day that a papal encyclical reads like a security requirements document. It even sums up the task in a line that would not look out of place in an architecture review: we should be “builders of communion, rather than architects of Babel” (¶16).
Stay paranoid. Keep a human in the loop. And never confuse what a system can do with what it should be allowed to do.
- X (Twitter): @SimonRoses
Further Reading:
- Encyclical Letter Magnifica Humanitas (official text, vatican.va)
- Presentation of the encyclical by Pope Leo XIV (25 May 2026)
- CyberInsecurity: The Cost of Monopoly (Geer, Bace, Gutmann, Metzger, Pfleeger, Quarterman, Schneier; CCIA, September 2003)
- Vatican News: AI must serve humanity, not concentrate power
- Dicastery for Promoting Integral Human Development: Magnifica Humanitas resources
- When Your Coding Agent Publishes Your Secrets: An AI Forensics, Containment and Audit Playbook
- Intent, Not Sophistication: The AI Attacker Is on the Record
- Pace the Frontier, Defend the Valley: A Security Reply to Dario Amodei
- Systems That Can Hack Anything: An AI-Safety Resignation, Read From the Security Chair
- The Death of the Job: How AI and Robots Will Rewrite Work in the Next 10 Years
Questions or feedback? Reach out via:
- Website: vulnex.com
- AI Security Strategy: vulnex.ai
- Twitter/X: @SimonRoses
- LinkedIn: linkedin.com/in/simonroses
- GitHub: github.com/vulnex
Contact: info@vulnex.com


