Skip to main content

AI's Democratic Era Ended in April 2026


For about three years, every big AI lab behaved like a teenager with a new car.

Look what mine can do. Look at my benchmark. Look at my context window. Every few weeks somebody published a chart where their bar was taller than everybody else's bar, and we all went along with it, because the bars kept getting taller and the models kept getting better and it was fun to watch.

Meanwhile China said almost nothing. Then once in a while DeepSeek dropped something that knocked everyone off their feet, everyone spent a week arguing about training costs, and the noise started again.

That era is over. It ended in April 2026, and I don't think we noticed how completely.

The race we thought we were in

The mental model everybody used was Formula 1. Whoever builds the fastest car wins the season. Speed was the whole point, and speed was something you showed off, because showing off is how you raise the next round.

Some people preferred the Manhattan Project comparison. I used to think that one was overdramatic. Now I think it was just early.

Because a race to build the fastest car and a race to build a bomb look identical right up to the moment the thing works. Same funding, same secrecy about method, same public bragging about progress. The difference only shows up at the first successful test, when somebody in the room does the arithmetic and goes quiet.

The test that went too far

Anthropic ran that test. They built Claude Mythos, pointed it at real codebases, and it turned out to be far better at finding and exploiting vulnerabilities than anyone had planned for.

The numbers are public and they are not modest. Across more than a thousand open-source projects, the model surfaced over 23,000 issues, of which more than 6,000 were rated high or critical severity. Of the findings that got human review, over 90% held up. A 27-year-old TCP SACK bug in OpenBSD. A 16-year-old flaw in FFmpeg's H.264 codec. A remote root vulnerability in FreeBSD's NFS server that had been sitting there for 17 years, found and exploited fully autonomously.

Seventeen years. Read that again. That code was reviewed by humans who knew what they were doing, for seventeen years, and a model found the way in without being told where to look.




So what did Anthropic do with it?

They did not ship it. There is no API key you can buy. There is no waiting list you can join by entering your email. They started Project Glasswing, handed access to roughly fifty organisations — AWS, Apple, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, NVIDIA, Palo Alto Networks, the Linux Foundation — and told everyone else to wait. By June the circle had grown to about 150 organisations in fifteen-plus countries, plus NATO, plus ENISA, plus the US government.

Their own explanation is the part worth quoting, because it is unusually blunt for a company statement:

no company, including Anthropic, has developed safeguards strong enough to prevent such models from being misused and potentially causing severe harm.

That is not marketing. That is a vendor saying they built something they cannot make safe, and choosing not to sell it.

I heard the Oracle half of this in person. On 4 and 5 September I was at POUG, the Polish Oracle User Group conference, and Glasswing came up in a session given by an Oracle employee.

Anthropic's own update on the project names Oracle directly and says it is now finding and fixing vulnerabilities across its products and cloud multiple times faster than before. Per-company figures are published for exactly two partners — 271 in Firefox, two thousand at Cloudflare — and beyond that the update says only that most partners have each found hundreds of high- or critical-severity issues. Oracle's number is not among them. A figure was mentioned in the room; I am not going to repeat it, because I cannot verify it and a wrong number attached to the right argument is how you lose the argument.

The magnitude is not the interesting part anyway. Whatever the count turns out to be, the question that follows it is the same. Patched in which versions?

Because the Oracle install base is not a fleet of current releases. There are 8i, 9i and 10g instances in production right now, all over the world, and they are never getting patched. Not "not yet" — never. No fix will be written for them, and in most cases they cannot be upgraded either: the application on top is unsupported, the vendor is gone, the integration was never documented, or somebody costed the migration once and the number ended the conversation. So the box keeps running, because it works, and because switching it off is not something anyone is willing to sign.

That is where this stops being an industry story. Those instances sit in public institutions and in the systems a country needs to function — tax, health, registries, utilities, transport. Somewhere right now there is an Oracle database with a hole in it that nobody will ever close, and as of this year there is a model that knows exactly where the hole is.

Tsar Bomba

This is where the nuclear comparison stops being a metaphor and starts being a description.

The Soviets detonated Tsar Bomba in 1961. Fifty megatons. It worked exactly as designed, and it was so obviously excessive that it was never repeated and never weaponised in any practical form. It was one test too far. The test itself became the argument for stopping.

The United States had its own versions of that moment. Castle Bravo went roughly two and a half times bigger than predicted and contaminated an area nobody had evacuated, because the physics turned out to be different from the model.


Mythos is the software version of that. It worked better than expected, and working better than expected was the problem.

What AI actually is now

Here is the part I want you to sit with.

An AI model is now a weapons system. Not metaphorically. Structurally.

You cannot buy a Patriot PAC-3 because you have money and a use case. You cannot order Shahed drones because you filled in a form. There is a licence, an end-user certificate, a government that signs off, and a list of countries that are allowed to be on the receiving end. Access is a political decision, not a commercial one.

That is now literally how frontier AI capability is distributed. Mythos-class access runs through verification programmes — a Cyber Verification Program for defensive security work, a Life Sciences Verification Program built with the US government. The expansion went to countries described in the reporting as friendly to the US. Allied nations. Approved list.

I went looking for Poland on the published list of those fifteen-plus countries. Australia, Canada, France, Germany, Italy, Switzerland, the Netherlands, Spain, Belgium, Sweden, India, Japan, New Zealand, South Korea. I did not find us. Maybe we are in the part of the list that was not published. Maybe not. Either way, I now know what it feels like to read an export-control list and check whether your country is on it, and I did not expect to learn that from a software announcement.

The obvious objection

Someone will say this is overblown, and there is a real argument there, so let me make it properly.

Researchers at AISLE took the specific vulnerabilities Anthropic showcased, isolated the relevant code, and ran them through small open-weight models. Eight out of eight detected the flagship FreeBSD exploit — including one with 3.6 billion active parameters costing eleven cents per million tokens. A 5.1B-active open model recovered the core of the 27-year-old OpenBSD chain.

If that holds up, the gate is leakier than it looks. The scarce resource was never a magic model. It was the willingness to spend enormous compute grinding at a codebase until something fell out. Compute gets cheaper every year. Willingness is not export controlled.

I think that objection is correct and I think it makes things worse, not better. It means we have built a licensing regime around a capability that does not fully respect the licence.

Where this leaves us

The democratic phase of AI is done. It lasted about three years, it was genuinely great, and it ended not because of regulation but because a company looked at its own product and flinched.

I don't think they were wrong to flinch. Given the same numbers, I would have flinched too.

But be honest about what changed. We spent three years being told AI would be democratised, put in everyone's hands, the great equaliser. The most capable model of this generation is available to about 150 approved organisations in a set of allied countries, and you are almost certainly not one of them.

Anthropic also named the real bottleneck, and almost nobody quoted this part: finding vulnerabilities is easy compared to fixing them. Ten thousand critical flaws is not the finish line. It is a work order, and it lands on the same maintainers who were already overloaded, on the same patch cycles that already took months, on the same containers and base images and vendor appliances nobody has touched since deployment.

The model is gated. The bugs it found are not. They are in your dependency tree right now, and the patches are coming down the waterfall whether or not you have capacity to absorb them.

Check your patch cycle. That is the part you actually control.

Comments

Popular posts from this blog

Diskless server iSCSI boot disk XCP-NG installation

 For Cisco UCS chassis, eg. 5108 for installation it's required to set FC or iSCSI disk for boot ( boot disk ). They are called diskless servers. Unfrtunatelly XCP-NG - 8.2.1 Jan 2025 - in my case cannot boot as it is from iSCSI. Here is a guide, how to do it.

Replacing a failing disk in AIX rootvg

A disk in a mirrored rootvg is the one disk you cannot just pull. It holds the boot image, it probably holds the primary dump device, and half of every logical volume on the system lives on it. Pull it without preparation and reducevg refuses, or worse, the machine comes up on nothing after the next reboot. This is the full sequence for a two-disk mirrored rootvg on AIX, replacing hdisk0 . Non-root volume groups are much simpler and I have noted the difference at the end. Decide whether you actually have a problem Disks rarely die cleanly. They complain first, and the complaints show up in the error log: errpt | more 1581762B 0727203502 T H hdisk0 DISK OPERATION ERROR 1581762B 0727203502 P H hdisk0 DISK OPERATION ERROR The third column is the one that matters. T is temporary, P is permanent. A single temporary error on a busy system is noise. A cluster of them over a few hours is a drive on its way out. A permanent error is not a warning, it is a report of ...