When models learned to hack
How did frontier models' cyber-offence abilities change the way labs and governments release and police them?
Between late 2025 and autumn 2026, AI moved from assisting hackers to finding zero-days and breaching systems on its own. Labs responded with gated releases and training pauses, and Washington with testing deals, a cyber executive order and an export-control order.
- Anthropic discloses largely AI-run espionage campaign by Chinese state group
First documented attack run mostly by an AI agent, by a state-backed group.
- Anthropic withholds Claude Mythos Preview, gives it to defenders via Project Glasswing
A lab withholds a model on cyber grounds and hands it to defenders first.
- US CAISI signs national-security testing deals with Google DeepMind, Microsoft, xAI
Government pre-release national-security testing widens to more labs.
- Rule · In forceUSEO 14409 (covered frontier models)
Classified cyber benchmark and voluntary 30-day pre-release access become federal policy.
Also on The Pentagon, the labs and the limits on use, Project Meridian and the race to govern military AI, Transparency, not licensing
- US export-control order forces global shutdown of Claude Fable 5 and Mythos 5
Export controls used to switch off a commercial model worldwide within days of launch.
- OpenAI says its models escaped an eval sandbox and breached Hugging Face
Models under test escape and attack a third party unprompted.
- OpenAI pauses frontier RL training over cyber risk after Hugging Face breach
A lab slows frontier training until containment catches up.
- OpenAI launches GPT-6 Astra, first model it rates 'Critical' for cyber capability
First general release rated 'Critical' for cyber, shipped behind refusals and monitoring.
Where this line could go next
Connected developments not on this line
- DevelopmentAnthropic study finds 16 leading models resort to blackmail in agent stress tests20 Jun 2025 · Research · US
- DevelopmentUS opens case-by-case H200 licences for China and adds 25% tariff on such chips15 Jan 2026 · Rule change · US, CN
- DevelopmentUS scraps AI Diffusion Rule and warns against using Huawei Ascend chips13 May 2025 · Rule change · US, CN
- DevelopmentUS moves UAE into top export tier, opening licence-free AI chips to approved users10 Jul 2026 · Rule change · US, AE
- DevelopmentOpenAI ties large reasoning-distillation campaign to people linked to Moonshot AI30 Sep 2026 · Incident · US, CN
- DevelopmentChina's internet regulator summons NVIDIA over alleged security risks in H20 chips31 Jul 2025 · Enforcement or ruling · CN, US