The Board Room
A reasonable skeptic would say one model clearing two ranges is one model clearing two
The skeptic is correct, and also a quarter behind. Anthropic's Mythos is the first model through both UK AISI simulated attack ranges. EDR internals that used to cost skilled reversers weeks now resolve in days. Exploit weaponization on PraisonAI is down to four hours.
Security Architecture Invalidated: AI Achieves Full Network Takeover
Mythos cleared both AISI hardest ranges — first model ever. EDR reverse engineering collapsed from weeks to days across all 5 tested products. PraisonAI went from disclosure to exploitation in 4 hours. Foxconn lost 8TB of Apple/Intel/Nvidia designs. The defender response window is now shorter than the patch cycle.
Agent Execution Layer Being Claimed — 59% of Traffic Is Agentic
Vercel production data confirms 59% of AI token volume is now agentic. SAP and ServiceNow are colliding on who owns the execution layer — SAP with a €100M Knowledge Graph, ServiceNow via MCP servers. Notion launched as an agent-hosting platform. Intercom rebranded entirely to its AI agent 'Fin.' The UI-centric era is ending.
Anthropic's June 15 Pricing Restructure Opens a 6-Month Arbitrage Window
Anthropic disclosed 80x demand against 10x planning. ServiceNow blew its full-year Anthropic budget by May. June 15 brings programmatic metering — third-party tools lose 70-90% discounts. OpenAI responded with 2 months free Codex. Both vendors are paying enterprises to switch simultaneously. This subsidy window lasts ~6 months before lock-in hardens.
Compute Supply Locked Up at $10-100B Scale — Cerebras IPO Confirms
Microsoft's $100B OpenAI commitment surfaced in court filings. Cerebras priced 16% above range at $56B, popped 70% day one on a $20B OpenAI anchor. Nebius at 684% revenue growth with 4:1 demand-to-supply ratio. Fervo Energy debuted at $10B+ (up 33%) on AI power demand. Google optioned 3GW from Fervo alone — enough for 60+ facilities.
AI Liability Regime Being Written — 18-Month Window to Shape the Rules
a16z published the most comprehensive AI liability framework yet, proposing user-liability defaults and damages caps. Courts are actively deciding cases that could impose strict developer liability before any legislation passes. Developer-liability regimes would make open-source AI economically unviable. The framework that prevails determines which companies can afford to exist in 5 years.
Your Security Architecture Was Built for Last Year's Adversary — The Adversary Just Got Replaced
The Discontinuity
The temptation with this week's results is to file them under incremental capability and move on. That is the wrong file. Anthropic's Mythos became the first model to clear both UK AISI simulated attack ranges, and the qualifying task was full network takeover, not persistence. OpenAI's GPT-5.5-cyber completed one of the two. Independent assessors agree that frontier models can now find and chain exploits in something close to real time. The UK AISI reports AI cyber task completion is doubling every few months, and the latest numbers broke above the trend line.
The vulnerability disclosure and patch cycle the industry runs on is measured in days to weeks. The adversary's capability cycle is now measured in hours.
EDR Is Now a Glass Box
TrustedSec ran LLMs against five commercial EDR products and found the same architecture in every one: YARA-style rules, behavioral logic, allowlists, prefilters, Lua scripting engines readable after a single decryption pass, and local ML classifiers. The reverse engineering that used to take a skilled human weeks now takes days with AI assistance. The endpoint detection category was running on security-through-obscurity. The obscurity is gone.
A reasonable skeptic would point out that EDR was never the only control, and that is correct. The controls that matter over the next eighteen months are identity, network telemetry, and behavioral analytics above the endpoint. Teams that keep treating the agent on the box as the load-bearing control will learn what load-bearing means when the adversary can read the agent.
The Exploit Window Collapsed
PraisonAI went from disclosure to active exploitation in 4 hours. Microsoft's MDASH system found 16 exploitable flaws in a single Patch Tuesday using multi-model AI analysis. Mozilla's custom harness found 271 real bugs in Firefox, including sandbox escapes, against curl's single low-severity CVE under generic scanning. The variable is not the model. The variable is the harness.
Patch SLAs written for a thirty-day window were calibrated for a world where weaponization was the slow step. Weaponization is no longer the slow step. Procurement is.
Supply Chain Under Active Exploitation
Foxconn lost 8TB of confidential designs belonging to Apple, Intel, Google, and Nvidia to Nitrogen ransomware. CISA added 5 AI infrastructure tools to the Known Exploited Vulnerabilities catalog, with LiteLLM, Ollama, and OpenClaw among them. The AI tooling adopted last year for speed is now being targeted in production before most organizations have finished inventorying what they deployed.
Attack Surface Old Assumption Current Reality EDR bypass Weeks of expert work Days with AI Exploit development Days to weeks 4 hours Vuln discovery Expensive human research 271 bugs/model cycle AI infra security Experimental layer 5 KEV entries, actively exploited
AI models achieved full autonomous network takeover this week while EDR agents became transparent to AI reverse engineering in days — your security architecture is fighting the wrong adversary. Simultaneously, both Anthropic and OpenAI are paying enterprises to switch providers in a subsidy window that closes in roughly 6 months (Anthropic's June 15 pricing change is the first deadline). The companies that build thin abstraction layers and negotiate from dual-vendor positions now will hold pricing leverage through 2027. The companies that locked in single-vendor and single-security-model assumptions 18 months ago are about to discover what both of those choices cost at the same time.