The Board Room
Two data points from this week sit awkwardly together.
Anthropic's Mythos cleared both UK AISI end-to-end cyber attack simulations, and TrustedSec showed AI compressing commercial EDR reverse engineering from weeks to days across all five products tested. The defensive premise that offensive AI lags human operators broke in public.
Security Architecture Breaks: Full Network Takeover + EDR Transparency
AI offensive capability crossed a discontinuity: Mythos cleared both AISI hardest cyber ranges (a first), EDR agents are now architecturally transparent via AI-assisted reversing, and active exploitation windows collapsed to 4 hours. The 18-year NGINX RCE and Foxconn's 8TB exfiltration confirm the defender's model assumed costs that no longer exist.
Compute Market Being Locked Up Through Bilateral Megadeals
xAI leased 220K GPUs (45% of Colossus) to Anthropic — Musk funding a competitor he publicly despises. Cerebras priced at $56B on a $20B OpenAI anchor. Fervo Energy debuted at $10B+. Microsoft's OpenAI tab passed $100B. The marginal unit of frontier compute now has a named buyer for the decade. The spot market assumption in most AI roadmaps is being deleted.
Agent Execution Layer: Platform Wars Declared Simultaneously
SAP (€100M fund + Knowledge Graph), ServiceNow (headless Action Fabric via MCP), Apple (agent App Store gating), Google (Gemini Intelligence on 3B+ Android devices this summer), and Amazon (Buy for Me cross-retailer agent) all declared claims on the agent execution layer in the same window. The question is no longer whether agents run your workflows. It's whose platform they run through.
Enterprise AI Governance Vacuum: Spending Outruns Controls
ServiceNow blew its full-year Anthropic budget by May. 85% of organizations are spending millions on agentic AI without adequate data foundations. AI liability is being written in courts now — before legislation exists. Duolingo's retreat quantified the 'slop tax' at 20%. The operating model assumes governance that doesn't exist yet.
AI-Native Org Design: Middle Management Economics Invert
Lovable dissolved its growth management layer and found VPs voluntarily taking IC roles for autonomy over authority. Cisco's stock rose 15% on AI orders the same day it cut 4,000 jobs. 103,000 tech layoffs by mid-May already approaches 2025's full-year total. The coordination layer that justified management headcount is being compressed to near-zero cost.
Your EDR Is Glass and the Adversary Has a 4-Hour Clock — The Security Operating Model Needs Rebuilding
The capability threshold moved a step function this quarter
The defensive architecture most security programs are running on was invalidated this week, and the evidence arrived from independent directions at once. TrustedSec ran LLMs against five commercial EDR products and found all five share identical architectural patterns: YARA-style rules, behavioral logic, allowlists, prefilters, and local ML classifiers. Work that used to occupy a skilled reverse engineer for weeks now takes days. Anthropic's Mythos became the first model to clear both UK AISI simulated attack ranges, the benchmarks built specifically to test autonomous offensive cyber capability. OpenAI's GPT-5.5 cleared one of two. Both are outperforming an exponential trend line that was already doubling every few months.
Then the 4-hour exploitation window on PraisonAI: disclosure to active targeting in the time it takes to schedule a change-advisory meeting. An 18-year-old RCE in NGINX's rewrite module, present since 2007, surfaced alongside it, affecting nearly every modern web application.
The patch window used to be measured in months because attackers needed months. Now it is measured in months because procurement needs months; the attacker side moved while the defender side did not.
The AI infrastructure stack is under active exploitation
CISA added five AI tooling vulnerabilities to the Known Exploited Vulnerabilities catalog in a single week. LiteLLM (unauthenticated database queries), Ollama (GGUF model loader data exfiltration at CVSS 9.1), and OpenClaw (six simultaneous critical CVEs) are all being exploited in production. A Raspberry Pi honeypot dressed as an AI endpoint was indexed by Shodan in 3 hours and absorbed 113,000 requests in a month, with tooling that evolved mid-experiment to detect honeypots.
In the same window, Foxconn lost 8 terabytes of confidential designs from Apple, Intel, Google, and Nvidia to the Nitrogen ransomware group. The assumption that contract manufacturers held manageable supply-chain custody risk just proved aspirational.
The defender's response
Microsoft stood up MDASH (multi-model AI vulnerability discovery) and found 16 exploitable flaws in a single Patch Tuesday. Mozilla found 271 bugs in Firefox 150 using Claude Mythos with custom harnesses, against curl's 1 CVE from generic scanning. The variable is harness design, not model quality. The offensive application of these same capabilities by threat actors is a 12-18 month timeline, not a theoretical one.
Congress is routing Mythos access through NSA rather than CISA, which tells you which mission the government has prioritized. The private sector is on its own for the defensive application.
What this forces
A reasonable skeptic would point out that EDR vendors have weathered every prior architectural critique and shipped through it. The reasonable skeptic is correct about the past. What the skeptic does not explain is why a posture calibrated to an adversary that needed human researchers to chain exploits should hold against one that does not. The compensating controls, identity and network telemetry and behavioral analytics above the endpoint, are the ones that matter in the next eighteen months. The endpoint agent is no longer the load-bearing control.
The security model, the compute market, and the platform layer all moved this week — not incrementally but structurally. AI offensive capability cleared full network takeover for the first time while EDR architectures became transparent to AI-assisted reversing in days. Compute is being locked up through $20-100B bilateral deals that delete the spot-market assumption most AI roadmaps depend on. And five major platforms simultaneously declared claims on the agent execution layer that will determine who your customers interact with versus who becomes invisible infrastructure underneath. The three decisions being made this quarter whether you make them or not: where detection actually lives when the endpoint is transparent, whether your compute access survives a world of named bilateral buyers, and which side of the agent boundary your product sits on in 2028.