The Board Room
AISI confirmed this week that Anthropic's Mythos became the first AI model to achieve
Simultaneously, TrustedSec demonstrated that AI reduces commercial EDR reverse engineering from weeks to days across all five major products tested, and exploit weaponization windows have collapsed to 4 hours.
AI Cyber Capability Crosses Full-Takeover Threshold
AISI confirms Mythos cleared both simulated attack ranges (first model ever). EDR products now transparent via AI in days, not weeks. Exploit weaponization compressed to 4 hours. OpenAI's Daybreak launched with 8 major security vendors. The defensive model assumed obscurity bought time. That time is gone.
Execution Layer War: Who Owns Where Agents Act
SAP (€100M fund + Knowledge Graph), ServiceNow (MCP-based Action Fabric), Apple (agent App Store gatekeeper), and Google (Gemini Intelligence on 3B+ devices) all moved this week to claim the layer where AI agents commit writes. MCP is emerging as de facto standard. The platform that hosts the agent captures the margin.
AI Infrastructure Financialized: Compute Locked, Power Platformized
xAI leasing 220K GPUs (45% of Colossus) to Anthropic signals compute is now a financial instrument. Fervo Energy IPO at $10B+ (33% pop) validates power as platform. Microsoft's $100B OpenAI commitment is the floor for frontier play. Nebius at 4:1 demand ratio. Capacity for 2027 is being pre-sold now.
AI Liability Regime Being Written — In Courts, Not Congress
a16z published the most comprehensive AI liability lobbying blueprint while courts are actively deciding cases that could impose developer liability for user misuse. ODNI vs Commerce battle over pre-release model evaluation will resolve in quarters. Open-source AI strategy is directly threatened by developer-liability outcomes. The 18-month window to influence defaults is open.
Enterprise AI Governance Vacuum: Budgets Blown, Foundations Missing
ServiceNow blew its full-year Anthropic budget by May. 85% of organizations spending millions on agentic AI lack adequate data foundations. Duolingo walked back blanket AI mandate after discovering 20% 'slop tax.' The pattern is clear: adoption velocity is outrunning governance, cost controls, and quality management.
AI Cyber: From 81% Hack Rate to Full Network Takeover in One Week
The Capability Jump
Tuesday's briefing put AI offensive capability at 81% success on individual tasks. This week's data is a category change, not another tick on the curve. AISI confirmed Anthropic's Mythos as the first model to clear both simulated attack ranges end-to-end. Full network takeover, not persistence and not lateral movement. OpenAI's GPT-5.5-cyber completed one of the two. The trend line in AI cyber task completion was already doubling every few months. These results broke above that trend.
The security model of the defensive stack was built on the premise that the cost of understanding the agent exceeded the value of bypassing it for most adversaries. That premise is no longer true for a growing share of the threat population.
EDR Is Now a Glass Box
TrustedSec ran LLMs against five commercial EDR products and found all five share the same architectural pattern: YARA-style rules, behavioral logic, allowlists, prefilters, Lua scripting engines readable after a single decryption pass, and local ML classifiers. Work that took a skilled reverse engineer weeks now takes days with AI assistance. The entire endpoint security category has been running on security-through-obscurity. The obscurity just left the building.
The Exploit Window Has Collapsed
PraisonAI was actively exploited 4 hours after disclosure. Microsoft's MDASH system found 16 exploitable flaws in a single Patch Tuesday cycle using multi-model AI analysis. An 18-year undetected RCE in NGINX's rewrite module is the other half of the story: foundational infrastructure harbors defects nobody audited. AI-powered vulnerability discovery, with Mozilla finding 271 real bugs in Firefox using custom harnesses, is compounding the problem from both sides at once.
The Market Response
OpenAI's Daybreak launched with CrowdStrike, Palo Alto Networks, Cisco, Cloudflare, Oracle, Zscaler, Akamai, and Fortinet as partners. Congress is holding closed-door Mythos demos, with access routed through NSA over CISA. That ordering prioritizes offensive and intelligence operations over civilian defense, which means the private sector is on its own for several years. Security equities are up 20% YTD. The market is starting to price this in and is almost certainly underpricing it.
The Foxconn Compound
Nitrogen ransomware exfiltrated 8TB of confidential designs from Apple, Intel, Google, and Nvidia through a single contract manufacturer. Separately, a Raspberry Pi honeypot dressed as an AI stack was indexed by Shodan in 3 hours and absorbed 113,000+ attacks in a month. A reasonable skeptic would say these are two different stories. They are not. Supply chain custody risk and AI infrastructure exposure are the same asset class under two custody regimes, and both are being probed at machine speed.
AI offensive capability crossed from 'can hack individual systems' to 'full autonomous network takeover' this week, while the platform layer where AI agents act is being claimed simultaneously by SAP, ServiceNow, Apple, and Google — and the firms best positioned to weather both shifts are those that treat compute as a financializable asset (xAI just proved it is) and governance as a product (courts are writing liability defaults right now, not Congress). The two decisions that compound from here: architect your product to be the thing agents orchestrate through rather than the thing they bypass, and compress your security posture against adversaries that now see through your EDR in days rather than months.