When AI safety constrains defenders more than attackers