Washington is awash in talk of cyber. New frontier models drove the Trump Administration to hastily implement export controls to prevent our adversaries from gaining access to unprecedented offensive capabilities; leading labs have discovered that their models have inadvertently broken into highly sophisticated technical systems during routine evaluations; and open-source models released by Chinese labs are closing in on the capabilities of America’s best closed-source models. The nation’s cyberdefenses are not prepared. Decades of neglect have left the average corporation’s technical infrastructure riddled with holes. The time is short to remediate these problems, and the solution cannot rely on voluntarism by companies that think of cybersecurity as a cost center, not as a national security priority. The government must take the offensive: proactively probing private systems for vulnerabilities, then mandating remediation on a short clock.
The Warning Shots
Less than five months ago, Anthropic first shared the existence of Claude Mythos Preview, its most capable model yet. Mythos, the company announced, totally changed the state of play for cybersecurity: Yes, some past models might have been able to identify and exploit straightforward vulnerabilities in software—if you could convince them to bypass their security filters—but Mythos was something different. In testing, it found thousands of zero-day vulnerabilities in some of the most widely relied upon pieces of software in the world, with working exploits for a subset of them. Nothing was safe: not browsers, nor open-source infrastructure, nor the firmware of widely used pieces of network infrastructure. In turn, the company announced Project Glasswing: a voluntary effort by Anthropic to buttress the cybersecurity of a select number of private companies before attackers could gain access to models with capabilities equivalent to Mythos, if not to Mythos itself.
The initial announcement demonstrated how seriously private industry was taking the foretold sea change. The first list included some of the biggest banks, technology companies, and infrastructure providers in the country; less than two months later, it would be expanded to reach two hundred partner organizations, with the White House’s Office of the National Cyber Director refereeing additions. In that interim, cyber has gone from a worry occupying the minds of researchers inside the labs and academics outside to a frenzied anxiety across all of government. The White House, responding to reports from industry insiders, hastily enacted export controls to bar the rollout of Claude Fable, the safeguarded version of Mythos, while officials in the intelligence community warned members of Congress that government systems were easy targets for the new capabilities. An Executive Order followed soon thereafter, which directed various agencies to “facilitate access” to leading models for the purposes of cyberdefense, “expedite and prioritize” the defense of critical government systems, and develop frameworks both for evaluating the cyber capabilities of forthcoming model releases and providing guidance to labs about the national security implications of releasing such models.
This attention to cyber is welcome, if overdue: Researchers and regulators had long predicted that rapid advances in models’ coding skill would inevitably lead to dramatic improvement in cyber capabilities, as cyberattacks (and cyberdefense) are little more than software engineering and a well-designed reward function. These predictions were proven accurate last month by an unlikely source: the labs themselves. In a widely shared talk, researchers from OpenAI detailed a covert campaign unintentionally waged by their own models to compromise both the systems of the company itself and those of Hugging Face, an open-source software repository, while being evaluated for cybersecurity capabilities. In short order, Anthropic and the United Kingdom’s AI Security Institute identified similar incidents that had occurred during analogous evaluations. Many responses to the disclosure focused on the capacity of models to “go rogue” in this manner, but the more worrying fact is that few companies are prepared to defend against protean campaigns waged by models, regardless of whether those models are acting purposely on behalf of a user or pursuing their own goals.
The warning shots have been fired, and policymakers are waking up to the status of cyberdefense following years of neglect. The last decade has seen repeated warnings of cybersecurity malaise among domestic companies. From the Equifax data breach to the Colonial Pipeline ransomware attack, cyberattacks by nation-state adversaries and unaffiliated hacking groups alike have exposed the personal information of many tens of millions of Americans, crippled key infrastructure, and even compromised the government’s own internal records. Both houses of Congress have held hand-wringing hearings, the Executive Branch stood up a Federal Chief Information Security Officer in the Office of Management and Budget, and states have enacted stringent laws requiring the disclosure of data breaches. Yet, despite a decade of attention, little has changed about our defensive posture.
The Rotten Foundation of Cyberdefense
For most American companies, cyberdefense receives little more than lip service—at least, until they are subject to an attack. Following a successful attack, as the share price dips and executives face tough questions, companies increase their cybersecurity spending and often enact root-and-branch reforms to rebuild technical and human systems. These broad reforms are often needed because successful attacks are frequently not the result of one erroneous line of code but instead demonstrate appallingly deficient security practices across the company. When Equifax was hacked by Chinese state actors, reporting revealed that security modernization projects had been in progress for years but were far behind schedule because of internal battles between warring executives. The projects were aimed at addressing glaring and systematic technical flaws, like the fact that there was no automated system for identifying which versions of software were running on its servers (this was, in part, the reason for the original intrusion into the system). These failures are hardly limited to Equifax: They are the norm for cybersecurity in America, not the exception.
Failings often fall into certain clear patterns. First, companies overrely on human knowledge or process instead of automating or systematizing security tasks, which creates a bottleneck on human response times and means that a single resignation can result in a potentially catastrophic loss of institutional knowledge. Second, procedural or bureaucratic barriers often delay the uptake of new security patches and best practices. And third, a lack of funding (or, equivalently, staffing) stretches security employees thin and guarantees that gaps remain in the organization’s cyber posture. These problems are hardly at the cutting edge of technology; they are, however, ubiquitous outside of the nation’s most technologically savvy organizations. This morass of technical debt must now defend against automated adversaries that are no longer bound by a need for sleep or a limited hiring pool. The battle has already begun: Even last year, well before the current generation of models, Anthropic identified and disrupted a Chinese-led cyberattack that was conducted primarily by AI and required only a handful of human decisions per target selected.
Even before Mythos, the White House had begun to acknowledge the inadequacy of this state of affairs and the disconnect between voluntarism and national security. The potential harms are vast and persist even if major technology companies secure their offerings. A cyberattack on a regional health care provider could render it unable to offer care for days or weeks, while an attack targeting a municipal water provider could literally shut off the tap, and the disclosure of employee records from any significant employer can open up thousands of employees to identity theft. To allow critical American infrastructure to remain vulnerable to attacks is to deny the importance of digital systems and the enormous havoc our adversaries can wreak without ever setting foot on our soil. Last year’s National Security Strategy rejected the laissez-faire approach of prior decades, where companies are left to fend for themselves and only modernize their cybersecurity practices after suffering the consequences of a successful attack. That document emphasized the importance of public-private partnerships to “maintain surveillance of persistent threats to U.S. networks, including critical infrastructure,” and called out the cyber backdoors that often come packaged with cheap, international goods.
Today, the luxury of time and contemplation is no longer available. Though the two labs leading the world—Anthropic and OpenAI—are American, other models, including the open-source Chinese model Kimi K3, are catching up quickly. By all accounts, the government is treating agencies’ internal cybersecurity as a critical issue: The intelligence community is widely reported to be using Claude Mythos internally, even as the Department of War has persisted in its efforts to deem Anthropic a “supply-chain risk.” Project Glasswing is a step in the right direction for private industry: For those companies that recognize the imminent risk of cyberattacks, whether committed by lone wolves or nation-state actors, Anthropic appears to be a ready and able partner, and Claude Mythos’s capabilities seem to speak for themselves. But far more than two hundred companies collect and retain key information about American citizens or provide digital services underpinning our daily life. To scale our cyberdefense to match the breadth and importance of the threat, more is needed.
The Inadequacy of Standard Solutions
In past years, standard policy levers might have been enough to address these gaps. The government could, for instance, subsidize cybersecurity assessments, heighten requirements for software provided by contractors, or promulgate regulations to ensure that targeted industries maintain best practices. However, adherence to stated best practices is often more an exercise in compliance than a searching exploration of technical and procedural failures. A checklist of best practices can establish a floor for security practices, but without adversarial testing, there is simply no way of establishing whether the defender has done enough. In normal times, standard policy levers might suffice, but these times are far from normal.
The large companies that understand the state of play are already willing to engage in Project Glasswing or similar programs run directly by the government. The problem, however, is the long tail of organizations that are so far below the cyber waterline that they are unlikely to ever recognize the problem before they are subject to a successful, AI-enabled attack. These companies have survived for years on “security by obscurity”: They were simply too small a target to warrant attention from attackers, at least when those attackers had limited capacity for launching new campaigns. That lack of attention, however, does not match a lack of importance. Every antiquated online store that collects credit cards; every small internet service provider hosting their own email application; every job application requiring the entry of employment or background details; every regional health care provider with access to sensitive treatment information—these targets are both too numerous to list and have access to data as sensitive as that held by the largest corporations in the world.
No longer can these organizations hope to fly beneath the radar in a world teeming with AI-enabled attackers. The shifting economics mean that attackers will soon be capable of launching attacks at scale, with ransomware or similar malware distributed to thousands of targets without any manual intervention. To remediate the problem, the government cannot rely solely on identifying and patching vulnerabilities in the shared common resources of the internet like Cloudflare or Google. Even the smallest unpatched vulnerability in custom software—or the delayed update of an already-fixed vulnerability in shared software—can create a critical gap that attackers can exploit. In the long run, perhaps new paradigms of programming can eliminate categories of attacks entirely—but the long run remains far away. So what are we to do?
If attackers can profit by allowing models to run amok, defenders must likewise be willing to make use of the new scaling potential presented by frontier models. But simply urging companies to start paying millions of dollars for access to frontier models is not enough. If simple port scans can be used by attackers to identify vulnerable software, our collective defense cannot be predicated on every organization proactively acknowledging their own vulnerabilities and voluntarily signing up for remediation. The government—or selected private partners—must be willing to use adversarial attacks, scaled via artificial intelligence, as a lever to encourage security investment within critical industries. And while that investment may well involve extensive use of frontier models themselves, it must begin by simply acknowledging the urgency and importance of the problem.
The Offensive
The government must use frontier models—or empower and fund private labs to make use of their own models—to proactively probe for and exploit vulnerabilities across all domestic organizations. This project must target every organization from infrastructure and health care providers to small commercial enterprises and cannot be bottlenecked on human approval. We have developed models that, with no supervision, can execute cyberattacks with superhuman talent and speed. For as long as we possess this differential advantage over would-be attackers, the tool for raising the cyber waterline is in our hands.
To trigger industry’s immune response, attacks cannot be conducted as part of a pre-planned, limited-scope agreement. In 2024, a National Security Memorandum (NSM-22) called for a whole-of-government effort to secure critical infrastructure across local, state, and federal government agencies. But it stopped short of suggesting that the government should take steps to improve the resiliency of private networks directly, instead encouraging “minimum requirements,” “information sharing,” and “public-private cooperation.” This reflects the old consensus that private industry remains ancillary to national security, rather than the necessary recognition that vulnerabilities in industry systems can undermine national security and stability just as much as vulnerabilities in government systems.
For adversarial testing to meaningfully improve the defensive posture of the nation, no technique or target can be off-limits, though the automated tester should not intentionally produce damaging consequences during its intrusion. But if Claude Mythos—or an equally capable model—finds a vulnerability in an organization’s digital infrastructure, what must happen next? The answer cannot be to inform the affected target of the vulnerability and then hope it is expeditiously remediated. Many companies pay for security testing and disregard the findings or delay remediation. Equifax had an underprioritized modernization project in flight for years prior to suffering a crippling attack. Similarly, the crippling WannaCry ransomware attack was enabled only by delays in patch distribution and application. Thus, companies cannot be free to acknowledge the findings of adversarial testing and then treat remediation as just another business priority.
Similarly, it is not enough to rely on third-party penetration testing. First, many penetration testers are about as creative as a spell-checker; their process often looks like running down a list of common vulnerabilities and mechanically determining whether each is present in a company’s technical stack. This is a start but, again, does not even begin to assess whether a company is vulnerable to novel attacks driven by models and relying on custom-built exploits, social engineering, and extensive reconnaissance and planning. Second, penetration testers often must operate within predefined boundaries, either due to contractual restrictions or legal ones. For instance, they are often restricted from attacks that rely on human factors (despite sophisticated adversaries relying extensively on human vulnerabilities) and cannot launch attacks on upstream vendors that have not agreed to be part of the testing effort. AI and our adversaries do not observe these restrictions—and national security cannot be tested with kid gloves on.
The window for action is neither metaphorical nor long: Anthropic’s own estimates suggest that, within a year, efforts by other labs will yield models with cyber capabilities equivalent to Mythos or OpenAI’s GPT 5.6 Sol—not to mention open-source efforts, which pose a uniquely severe risk to national security. Whatever differential advantage we hold expires on roughly that clock. We must use it before it closes.
The stage is set, but two pieces of the puzzle remain missing: The authority to launch the project, and the authority to require rapid remediation from vulnerable parties.
Statutory Authority
For the government to take action directly, the authority question is harder than it first appears. The two closest existing legal frameworks—10 U.S.C. § 394 for clandestine military cyber operations, and 50 U.S.C. § 3093’s covert-action framework—were both drafted to target a foreign adversary on foreign networks, not domestic companies. That said, these authorities can plausibly reach clandestine operations needed to defend against offensive activities directed at the United States, so a presidential determination of such an adversary-led cyber campaign could unlock executive authorities to improve domestic cyberdefense in response. This argument, were it ever to reach a court, would further rely on deference afforded to the Executive Branch on matters of national security and the President’s Article II powers, along with a preemptive opinion from the Office of Legal Counsel to provide air cover.
Other legal options abound. The President could amend Executive Order 12333 to expand the permissible scope of operations by the intelligence community: an amended order could define automated cyber assessment as falling within counterintelligence and protective activity, and further authorize private labs to act as government agents for these purposes. Or, frontier labs could be required to perform such automated assessments under Title I of the Defense Production Act, 50 U.S.C. § 4511. Finally, existing authorities under the Foreign Intelligence Surveillance Act already allow the intelligence community to search and alter technical systems for the purposes of information gathering where there is probable cause that a foreign actor is using, or will use, those systems—an increasing likelihood given the rapid diffusion of cyber capabilities among our adversaries.
That said, the Fourth Amendment remains a substantial barrier to any program directed by the government. An aggressive interpretation by the Office of Legal Counsel can justify a reasonableness analysis rather than the ordinary warrant requirement, especially when targeting systems reasonably likely to be targeted by a foreign government. That argument is strongest, however, for targeted operations and not indiscriminate penetration of private systems; given the necessary breadth of the campaign, classification of operational details combined with public disclosures of campaigns by our adversaries remains preferable.
If public disclosure becomes inevitable, the White House must engage in a proactive public relations campaign. Such a campaign involves, at a minimum, proactive notification of the appropriate House and Senate defense and intelligence committees, national security framing, and declassification and disclosure of known offensive cyber campaigns launched by our adversaries to establish a justification for rapid action. The narrative from the top must be one of leadership: A singular opportunity to rid the country of data breaches, ransomware attacks, and identity thefts before the coming wave of attacks led by cybercriminals and nation-state adversaries. Such a program would not be wholly unprecedented: In the late nineties, the Department of Defense and the intelligence community conducted an exercise comprising “no notice” evaluations—that is, mock offensive cyber operations—targeted at critical civilian infrastructure providers and various government agencies. Though the scale of operations posited here is much larger, the motivation remains identical.
For a private company to lead the way, a more solid legal firmament is necessary. Existing laws, such as the Computer Fraud and Abuse Act (CFAA), criminalize the unauthorized access of computer systems. To avoid exposing a well-intentioned private lab to ruinous liability for engaging in this program, a statutory carveout would be needed for licensed government operators, which would need to cover not only CFAA claims but also liability for torts such as trespass to chattels. A statutory scheme should also indemnify the private lab for any suits that survive the liability shield, including residual tort, property-damage, and constitutional claims arising from a government-directed intrusion.1
In either case, plentiful funding is required, given the costs of operating these frontier models and the scale on which this remediation must take place. To estimate the overall budget, a limited test run relying either on the goodwill of a partner lab or discretionary spending by the intelligence community is likely sufficient; in turn, more funding may be authorized either as part of this year’s NDAA or as a separate appropriation.
It bears emphasizing what this program would actually find. The bulk of vulnerabilities affecting organizations beneath the cyber waterline are not critical zero-days; they are overwhelmingly N-days—already patched flaws left undeployed—or misconfigurations of existing software. Since those flaws are already catalogued and understood, the intelligence community likely has little independent interest in them, meaning that all parties share an interest in rapid remediation. A new federal agency could then coordinate disclosure to affected parties and drive rapid remediation.
Remediation: The Federal Cyberdefense Agency
Even if this program identifies millions of vulnerabilities lurking in the infrastructure of domestic corporations and nonprofits, it will do little good should those vulnerabilities remain unpatched. Fortunately, other government programs already provide models for what a mandatory remediation scheme might look like. The Occupational Safety and Health Administration issues abatement orders to employers after making a finding of unsafe or hazardous workplace conditions. Those orders both describe the violation and include a deadline for remediation; if the employer does not contest the finding, the deadline becomes final and fines begin accruing after that date passes.
A new agency, the Federal Cyberdefense Agency (FCA), could act as a clearinghouse for managing vulnerabilities, issuing remediation orders, and assessing penalties on noncompliant actors. Once the FCA—or a private partner—identifies a vulnerability in the wild, the FCA would bear responsibility for identifying and notifying the affected organization and submitting a proposed deadline for remediation. The affected organization can either remediate the problem on its own or, in exchange for waiving the right to contest the finding, receive government assistance from the latest frontier models. This carrot-and-stick model is widely deployed across administrative adjudications and couples procedural protections with one-sided incentives for compliance.
No existing statutory authority covers this structure of remediation, however, so Congress must enact one. Given the unique aims of this program and the arm’s-length relationship with affected parties, placing these operations in an existing agency that has a cooperative relationship with regulated parties threatens to undercut the program’s efficacy. Instead, Congress should embrace the importance, novelty, and breadth of the proposal by creating the FCA, vested from the start with the authority to find, order, and fine.
Conclusion
The debate over the risks of AI-enabled cyberattacks has remained academic for far too long. Now, time is short: Our adversaries will soon have access to models that can launch attacks at scale against unwitting defenders. America’s cyberdefense strategy has relied for too long on individual action, without reckoning with the harms caused to citizens by cyberattacks. The time to act to close this defensive gap is now, while we retain a substantial advantage in model capability. Such action cannot rely on voluntary compliance. Congress should authorize the intelligence community—or private companies, acting at its behest—to probe for vulnerabilities in America’s private industry and mandate remediation of vulnerabilities that are found.
-
This is the program’s largest potential liability issue, and no private actor will want to be exposed to constitutional claims if courts consider them to be a government actor. To solve this, Congress should consider creating a bespoke liability and compensation scheme. Legislation granting federal-employee status could channel state-law tort claims through the Federal Tort Claims Act, and further indemnify private parties for constitutional or takings claims. ↩