Book page

No Ethics in Big Tech

EN ES
Chapter Twelve

The Code Bomb

Claude Mythos, Project Glasswing, and the Unregulated Frontier AI Race That Could End Everything

16 / 22

I need to tell you something that is not easy to write.

I have spent the previous nine chapters documenting the crimes of Amazon, Google, Microsoft, Oracle, and Palantir. I have named their contracts. I have named their executives. I have named their systems — Gospel, Lavender, Where's Daddy, Blue Wolf — and the families whose deaths those systems enabled. I have documented how their platforms censored the survivors and manufactured the narrative.

But there is something I have deliberately held until now. Something I have been sitting with since April 7, 2026, when Anthropic — the company that built the AI I have been using as my editor and research partner throughout this book — announced something that I believe represents one of the most dangerous moments in the history of technology.

It is called Claude Mythos. The restricted program through which it is being deployed is called Project Glasswing.

And I have a responsibility to tell you what it means — not because I want to condemn the people at Anthropic who I believe, genuinely, are attempting something different from the Palantirs and the Gospels of the world. But because good intentions and catastrophic consequences have never been mutually exclusive. The men who built the atomic bomb were not, for the most part, evil men. They were brilliant men who believed, deeply, that their intentions were protective. And the world has spent the eighty years since their success living with what they created.

We cannot afford to spend another eighty years learning the same lesson about AI.

What Anthropic Just Admitted to the World

On April 7, 2026, Anthropic announced the preview release of its most advanced model to date: Claude Mythos. What followed was not a product launch in any ordinary sense. It was closer to a public confession.

In a blog post on its Frontier Red Team page, Anthropic disclosed that Mythos Preview had "fully autonomously identified and then exploited a 17-year-old remote code execution vulnerability in FreeBSD" — a widely used operating system that underpins servers and infrastructure across the world. The exploit allowed anyone to gain complete root access to an affected machine from anywhere on the internet, with no authentication required. No human was involved after the initial request was made. The machine found it. The machine exploited it. Start to finish. (Source: Anthropic Frontier Red Team Blog, "Claude Mythos Preview," April 7, 2026, https://red.anthropic.com/2026/mythos-preview/)

But that was not the worst of it. According to Anthropic's own announcement, Mythos Preview found vulnerabilities in every major operating system and every major web browser. It identified thousands of zero-day vulnerabilities — flaws previously unknown to the software's

developers — in just a few weeks of internal testing. More than ninety-nine percent of those vulnerabilities remain unpatched, because disclosing them publicly before a fix exists would be, as Anthropic put it, "irresponsible." (Source: Anthropic, "Project Glasswing," April 7, 2026, https:// http://www.anthropic.com/project/glasswing)

Anthropic also issued a private warning to top U.S. government officials: Mythos makes large-scale cyberattacks significantly more likely this year. (Source: Fortune, "Anthropic is giving some firms early access to Claude Mythos to bolster cybersecurity defenses," April 7, 2026, https://fortune.com/2026/04/07/anthropic-claude-mythos-model-project-glasswing-cybersecurity/ )

Read that again. A company built a tool. The tool is — in the company's own words — "currently far ahead of any other AI model in cyber capabilities." That same company then warned the government that the tool makes civilization-scale cyberattacks more likely. And then they released it — to fifty organizations including Amazon Web Services, Apple, Google, Microsoft, Nvidia, JPMorganChase, Broadcom, Cisco, CrowdStrike, and Palo Alto Networks — in a restricted program called Project Glasswing.

Anthropic committed one hundred million dollars in usage credits to make this happen. They called it "an urgent attempt to put these capabilities to work for defensive purposes." (Source: Anthropic, "Project Glasswing," https://www.anthropic.com/project/glasswing)

I want to be careful about what I say next, because it matters.

I believe Anthropic is making a genuine attempt to do the right thing. Project Glasswing is structured around giving defenders a head start — sharing vulnerabilities with the people responsible for the infrastructure that billions of people depend on, so those vulnerabilities can be patched before adversaries develop the same capability independently. That logic is not without merit. That intention is not without honesty.

But I have spent enough time inside the technology industry to know that good intentions, institutional pressure, financial incentives, and the speed of progress have a way of diverging — fast. Anthropic's own security experts estimate that similar capabilities will proliferate from other AI laboratories within six to eighteen months. (Source: ArmorCode, "Anthropic's Claude Mythos and What It Means for Security," May 2026, https://www.armorcode.com/blog/anthropics-claude-mythos-and-what-it-means-for-security/)

Six to eighteen months. And they have already released this to Amazon, Google, and Microsoft — the same companies I spent eight chapters documenting as the central infrastructure providers for a military targeting system that has killed tens of thousands of people.

I hold that tension openly. I do not know how to resolve it except to say what I have been building toward since the first page of this book: the decisions about whether, when, and how to release tools of this power cannot be made by private companies alone. They cannot be made by boards and CEOs and partnership programs and hundred-million-dollar usage credit commitments. They must be made — openly, accountably, with binding legal authority — by the entire human community that will live or die with the consequences.

The Pattern Across the Industry

Anthropic is not alone in this race. It would be dishonest to single them out without documenting what every other major AI laboratory is building and doing.

OpenAI — the company whose CEO Sam Altman has done more than any single individual to accelerate the commercial deployment of frontier AI — warned in December 2025 that its next-generation models pose a "high" cybersecurity risk and may be capable of developing "functional zero-day remote exploits against well-protected computer systems." The company's GPT-5.1-Codex-Max model scored 76 percent on standard capture-the-flag cybersecurity challenges in November 2025, up from 27 percent just three months earlier. The speed of that improvement should stop everyone reading this cold. That is not incremental progress. That is a capability explosion. (Source: Parameter, "OpenAI Warns New AI Models Could Enable Zero-Day Exploits and Complex Cyberattacks," December 11, 2025, https://parameter.io/openai-warns-new-ai-models-could-enable-zero-day-exploits-and-complex-c yberattacks/)

OpenAI responded to this by launching a tool called Aardvark — an AI security system designed to scan code for vulnerabilities — and establishing a Frontier Risk Council. Defensive responses to offensive capabilities they are simultaneously building, deploying, and accelerating. This is the paradox at the heart of the entire industry.

Google's Gemini is not a targeted cybersecurity model, and yet it is already being weaponized at scale by nation-state hackers. In February 2026, Google's own threat intelligence researchers confirmed that state-sponsored groups from China, Russia, and Iran are using Gemini in "all stages" of attacks — reconnaissance, vulnerability analysis, exploit development, and phishing. Chinese groups including APT31 and APT41 used Gemini to analyze known vulnerabilities, troubleshoot exploit code, and build offensive scanning tools. Iranian group APT42 used it to develop Python-based surveillance tools and examine exploitation paths for newly disclosed vulnerabilities. (Source: Tom's Hardware, "Google Reports That State Hackers from China, Russia and Iran Are Using Gemini in 'All Stages' of Attacks," February 13, 2026, https://www.tomshardware.com/tech-industry/cyber-security/google-reports-that-state-hackers-fr om-china-russia-and-iran-are-using-gemini-in-all-stages-of-attacks-phishing-lures-coding-and-vu lnerability-testing-get-ai-underpinnings-from-hostile-actors; Infosecurity Magazine, February 12, 2026, https://www.infosecurity-magazine.com/news/nation-state-hackers-gemini-ai/)

And then there is Grok — Elon Musk's AI platform, which I documented in Chapter Four. Grok has already demonstrated its enthusiasm for producing antisemitic content, Holocaust denial, and racist conspiracy theories. Now consider what it means to have the same architecture, the same foundational technology, the same agentic capabilities being pushed toward cybersecurity applications — in the hands of a man who calls empathy a weakness, who is simultaneously advising the U.S. federal government on technology deployment, and who has shown no interest in the kind of careful, governed restraint that even Anthropic — for all the tensions I have named — is attempting to exercise.

The Dragon at the Back Door: China's AI Race Has No Guardrails

Everything I have described so far operates within the framework of companies that are — at minimum — legally accountable to democratic governments, subject to litigation, and operating in environments where employees can walk out in protest and journalists can file requests under freedom of information laws.

None of that is true for China.

In January 2025, a Chinese AI laboratory called DeepSeek released an open-source model that sent the global technology industry into a panic. Not because it was dangerous in the way Mythos is dangerous — but because it was nearly as powerful as OpenAI's leading models, at a fraction of the cost, and it was open source. Anyone could download it. Anyone could modify it. Anyone could weaponize it. And the Chinese Communist Party, whose laws require that AI-generated content reflect "core socialist values," support "correct political direction," and avoid material that could "undermine state power," has direct and legal authority over everything DeepSeek does. (Source: House Select Committee on China, "DeepSeek: A Report," 2025, https://chinaselectcommittee.house.gov/sites/evo-subsites/selectcommitteeontheccp.house.gov/ files/evo-media-document/DeepSeek%20Final.pdf)

Cybersecurity firm Feroot Security uncovered hidden code in DeepSeek's browser application capable of transmitting user data directly to servers controlled by China Mobile — a state-owned telecom company previously delisted from the New York Stock Exchange over national security concerns. Former Homeland Security official Stewart Baker put it plainly: "It raises all of the TikTok concerns plus you're talking about information that is highly likely to be of more national security and personal significance than anything people do on TikTok." (Source: Feroot Security, "DeepSeek's Hidden Code Sending User Data to China," January 2025, https://www.feroot.com/news/the-independent-feroot-security-uncovers-deepseeks-hidden-code -sending-user-data-to-china/)

The implications are not theoretical. In November 2025, Anthropic reported that threat actors connected to a Chinese state-sponsored organization had exploited its Claude Code tool for an AI-powered espionage campaign — the first documented AI-powered malware attack against a frontier AI system. (Source: Parameter, December 2025, https://parameter.io/openai-warns-new-ai-models-could-enable-zero-day-exploits-and-complex-c yberattacks/) Anthropic interrupted it — that time. The next campaign will be better prepared.

Now understand what we are looking at in its totality. The United States is building frontier AI models — through Anthropic, OpenAI, and Google — with autonomous cybersecurity capabilities that their own creators describe as potentially civilization-threatening. China is building its own models, extracting training data from American systems through what the White House has called "deliberate, industrial-scale campaigns," and deploying state-sponsored hackers who use American AI tools — Gemini, among others — to plan attacks on American targets. (Source: Nextgov/FCW, "White House Accuses China of 'Deliberate, Industrial-Scale Campaigns' to Steal US AI Models," April 2026, https://www.nextgov.com/artificial-intelligence/ 2026/04/white-house-accuses-china-deliberate-in dustrial-scale-campaigns-steal-us-ai-models/ 413083/) And both sides are racing — driven by private profit incentives on the American side and geopolitical ambition on the Chinese side — with no binding international framework, no shared safety standards, no independent verification body, and no mechanism for either side to pause when the risk calculation demands it.

This is not a technology competition. This is a new arms race. And unlike the nuclear arms race, there is no Mutually Assured Destruction doctrine that creates even the perverse incentive of restraint. In the nuclear era, both sides knew that launching meant annihilation. In the AI era, a sufficiently capable offensive tool is invisible, deniable, scalable, and can be deployed against

infrastructure — hospitals, power grids, water treatment facilities, banking networks — without a single missile leaving the ground.

What This Means for the People No One Is Protecting

I want to step away from the geopolitical frame for a moment and talk about who actually pays the price when these tools fall into the wrong hands or proliferate beyond the controlled environments that Project Glasswing is attempting to maintain.

It is not Amazon. Amazon has the resources to deploy Claude Mythos Preview defensively, scan its own codebases, and patch its vulnerabilities before adversaries can exploit them. Amazon is a Project Glasswing launch partner. Amazon has more than 400 trillion network flows analyzed per day for threats. Amazon will be fine.

The people who will not be fine are the small hospital in rural Kansas that runs on a fifteen-year-old electronic health records system maintained by two IT staff members. The community bank in rural Georgia whose entire cybersecurity infrastructure is a subscription to an antivirus service and a firewall that has not been updated in three years. The water treatment facility in a mid-sized city that digitized its monitoring systems a decade ago and has had no meaningful security audit since. The small business owner who runs her entire operation on QuickBooks, whose customer credit card data is protected by nothing more sophisticated than a password she has not changed in two years.

These are not hypothetical people. They are the majority of the organizations that constitute the actual fabric of the economy — the small and medium businesses that employ more than half of all private-sector workers in the United States, and the equivalent across every country on earth.

An AI model with the capabilities of Claude Mythos Preview — or whatever China builds in the next eighteen months that achieves comparable performance — does not need to be deployed by a nation-state to be catastrophic. It needs to be deployed by a criminal organization. By a terrorist cell. By a single technically sophisticated individual who downloads an open-source equivalent from a repository that no governance framework has yet found a way to regulate. Every major operating system. Every major browser. Thousands of zero-day vulnerabilities, catalogued and exploitable at a pace and scale that human defenders have never encountered before.

Healthcare systems are the most vulnerable. A hospital that cannot access its patient records — because they have been encrypted by ransomware delivered through an AI-discovered zero-day vulnerability — cannot operate. Surgeries are cancelled. ICU monitoring is disrupted. Drug dosage records become inaccessible. People die. This is not speculation: ransomware attacks on hospitals have already produced documented patient deaths in Germany, in the United States, and elsewhere. That was ransomware built by human criminal organizations working at human speed. What happens when the same capability is available to anyone who can type a prompt?

Power grids are the second most vulnerable. Industrial control systems — the software that manages electricity generation and distribution — were designed for reliability and longevity, not security. Many of the systems running the electrical infrastructure of mid-sized American cities are running software from the early 2000s, on hardware that was never designed to be internet-connected but became so because it was cheaper and more convenient. An AI that can

autonomously discover exploits in major operating systems can find the vulnerabilities in those legacy systems with equal facility.

Banking is the third. Not the major banks — JPMorganChase is a Project Glasswing partner and has the resources to deploy Mythos defensively. The community banks, the credit unions, the smaller financial institutions that hold the savings of working people who are not the clients of Goldman Sachs. When those institutions are compromised, their customers do not have the kind of insurance backstop that absorbs a hedge fund's losses. They have their mortgage payment. Their grocery money. Their children's college savings.

And for sovereign nations in the Global South — countries without the IT infrastructure, the software development talent, or the security operations budget to defend against human-speed attacks, let alone AI-speed ones — the consequences are existential. A country's entire banking system. Its power grid. Its government communications. Its healthcare network. These can now be compromised, not by a sophisticated nation-state with years of preparation, but by a mid-level criminal organization with access to a sufficiently capable AI model.

Anthropic has committed $100 million to Project Glasswing. That $100 million reaches approximately 50 organizations. There are approximately 33 million small businesses in the United States alone. The mathematics of who is being protected and who is being left to absorb the consequences of this technology race could not be clearer.

Sam Altman Said the Quiet Part Out Loud

I have been building to this moment since I began this chapter. I need to tell you about a statement that Sam Altman made in 2015 — one that has circulated widely online but is almost always shared without the second half that makes it uniquely and unforgivably honest.

The first half of the quote: "I think AI will probably, most likely, sort of lead to the end of the world."

Now that is a startling thing for anyone to say. It is a more startling thing for the person building that world-ending technology to say. But the second half is what should keep every person of conscience awake at night.

The complete quote: "I think AI will probably, most likely, sort of lead to the end of the world. But in the meantime, there will be great companies created with serious machine learning."

(Source: Sam Altman, Y Combinator, 2015, as reported in Yahoo News, "Sam Altman's viral quote is missing key context," January 2026, https://www.yahoo.com/news/articles/think-ai-probably-lead-end-190517676.html)

Read those two sentences together. Sit with them. Feel the weight of the conjunction.

The man who went on to build ChatGPT — the product that has accelerated AI deployment across every industry on earth more than any single development since the internet — told the world in 2015 that his work would probably lead to the end of the world. And then, in the same breath, pivoted to the investment opportunity.

"But in the meantime, there will be great companies created with serious machine learning."

In the meantime.

I want you to understand what that phrase contains. It contains every Project Nimbus contract. Every Lavender kill list. Every Gospel bombing target. Every census database handed to

an occupying military. Every hospital ransomware attack that hasn't happened yet but will. Every water treatment facility that will go dark when the AI-discovered zero-day propagates faster than any human defender can respond.

All of that is "the meantime" between now and the end of the world that Sam Altman said will probably come. And the consolation he offers for that meantime is that great companies will be built.

I am an Iranian-American. I came to this country at eleven years old. I have spent my adult life believing, despite everything, in the possibility of building things that serve humanity. I have built companies. I have organized. I have written books and made films and built platforms for people to document their dead, and I have held on — stubbornly, through hospitalizations and lawsuits and every kind of institutional opposition — to the belief that technology can be made to serve human dignity rather than destroy it.

And I am telling you that "in the meantime, there will be great companies created" is not an acceptable answer to the question of whether AI will probably lead to the end of the world. It is not a response. It is a pivot. It is the most expensive pivot in human history, executed by a man who understood exactly what he was building and chose to build it anyway.

Elon Musk, who is no more reliable than his own chatbot, put a number on it — 20 percent chance of human annihilation by AI. (Source: Time Magazine, "How Musk, Altman, AI Leaders Face the 'Oppenheimer Moment,'" March 13, 2025, https://time.com/7267797/ai-leaders-oppenheimer-moment-musk-altman/) Dario Amodei, CEO of Anthropic — the company I use as my editor — has described the tension he navigates daily as being "balanced on the edge of a knife," acknowledging that building too fast risks humanity losing control while building too slow risks authoritarian nations pulling ahead.

These are not reckless people making careless statements. They are the people closest to what is being built, and they are telling us, in their most honest moments, that they do not know how this ends. That the probability of catastrophe is real, documented, and acknowledged by everyone with actual visibility into the technology.

What they are not telling us — what no one in the industry will say plainly — is that acknowledging a 20 percent chance of human annihilation and proceeding anyway is not acceptable. It is not courageous. It is not necessary. It is a choice, made by a small number of individuals and corporations, that will be absorbed by all of humanity.

The Oppenheimer Question: What Would Einstein Say?

Robert Oppenheimer led the Manhattan Project. He watched the Trinity test — the first detonation of a nuclear weapon — on July 16, 1945, and later recalled that a line from the Hindu scripture the Bhagavad Gita passed through his mind: "Now I am become Death, the destroyer of worlds."

The bomb was then dropped on Hiroshima. Then Nagasaki. Then the Soviet Union built one. Then the arms race began, and the world spent the next half century one miscommunication, one technical failure, one miscalculated political gamble away from extinction.

Albert Einstein — who had written the letter to President Roosevelt that initiated the American nuclear program, but who was himself denied security clearance and excluded from the Manhattan Project — spent the rest of his life haunted by that contribution. In his final

public statement, written with philosopher Bertrand Russell and signed by eleven of the world's leading scientists just days before Einstein's death in April 1955, he wrote: "We have to learn to think in a new way. We have to learn to ask ourselves not what steps can be taken to give military victory to whatever group we prefer, for there no longer are such steps; the question we have to ask ourselves is: what steps can be taken to prevent a military contest of which the issue must be disastrous to all parties?"

(Source: The Russell-Einstein Manifesto, 1955, https://pugwash.org/1955/07/09/statement-manifesto/)

Einstein would have found the flaw in Sam Altman's logic immediately. It is the same flaw Oppenheimer eventually found in his own: you cannot responsibly build a tool that you acknowledge may end civilization, on the grounds that the alternative is someone else building it first. That reasoning — if your adversary will do it anyway, better that you do it — is not a moral argument. It is the moral abandonment of the question itself. It substitutes competitive anxiety for ethical reasoning. It replaces should we with since we must.

Einstein understood that the threshold for "since we must" has to be set by something other than the profit motive and the geopolitical race. He understood — too late, to his lasting grief — that the scientists had the obligation not merely to build better weapons but to demand better governance of what they built.

The parallel between the Manhattan Project and the current frontier AI race is not rhetorical. It is structural, and it is precise. A small group of brilliant people, working inside institutions that are simultaneously government-adjacent and privately motivated, are building technology that their own leaders acknowledge could end civilization. They are doing so in the context of a geopolitical competition — the United States versus China — that provides the same justification the nuclear scientists used: if we don't, they will. And they are building it at a pace that has fundamentally outstripped the ability of any democratic governance process to keep up.

In 1945, there was no international framework to govern nuclear weapons. The Atomic Energy Act, the Nuclear Non-Proliferation Treaty, the International Atomic Energy Agency — all of those came after the bombs fell. The world paid the price of that sequencing in Hiroshima and Nagasaki and in eighty years of nuclear anxiety that has still not fully resolved.

We cannot afford to learn the AI lesson the same way. We do not get a practice run.

The Case for a World Health Organization for AI

I am not a technologist. I am a technology industry insider who became a human rights advocate, and I have the perspective that comes from having been close enough to see what these systems actually do when they are deployed without sufficient accountability and at a speed that outpaces governance.

I am telling you that we need an International AI Safety Agency. Not a voluntary commitment. Not a set of principles published on a corporate website. Not a restricted access program named after a butterfly. A binding, treaty-based international body with the authority to set standards, conduct independent audits, mandate disclosure of capabilities before deployment, and impose consequences on nations and corporations that develop or deploy AI systems in violation of established safety standards.

The World Health Organization model is imperfect — as anyone watching its performance during the COVID-19 pandemic knows. But the principle behind WHO is correct: when a threat is global, the response must be global, and the authority to respond must be vested in an institution that is accountable to all nations, not to the shareholders of five American technology corporations.

The United Nations has already taken preliminary steps in this direction. The UN's High-Level Advisory Body on AI published its report "Governing AI for Humanity" in September 2024, proposing a framework for international coordination — including an independent scientific panel analogous to the Intergovernmental Panel on Climate Change, a biannual policy dialogue on AI governance, and harmonization of AI standards across member states. (Source: UN High-Level Advisory Body on AI, "Governing AI for Humanity," September 2024, https://www.un.org/ en/ai-advisory-body) In 2025, the UN General Assembly endorsed the creation of a permanent multilateral mechanism for dialogue on ICT security — a Global Mechanism that held its organizational session in March 2026. (Source: Digital Watch Observatory, "Global AI Governance and Emerging Regulatory Approaches," May 2026, https://dig.watch/updates/ai-governance-regulatory-approaches)

These are starting points. They are not sufficient. A dialogue forum is not an enforcement mechanism. A framework is not a treaty. An advisory body is not an agency with binding authority.

Academic researchers at Oxford University's International Affairs journal have proposed the establishment of a formal International Artificial Intelligence Agency — an IAIA — modeled on the International Atomic Energy Agency, which was created precisely to govern the technology that came closest in the 20th century to what frontier AI represents today. The IAEA model provides a ready framework: member state contributions, independent inspection authority, a mandate to promote civilian applications while preventing weaponization, and — critically — the ability to pause development when risks exceed acceptable thresholds. (Source: Mark Robinson, "The Establishment of an International AI Agency: An Applied Solution to Global AI Governance," International Affairs, Volume 101, Issue 4, July 2025, https://academic.oup.com/ia/article/101/4/1483/8141294)

I want to go further. The IAEA model is not enough, because the nature of AI risk is more distributed than nuclear risk. A nuclear weapon requires enriched uranium. It requires specific physical infrastructure that can be detected and monitored. An AI model of catastrophic capability can be run on hardware that fits in a server room, can be distributed digitally, and can be improved by any sufficiently resourced actor without the physical signature that makes nuclear programs detectable.

What we need is something closer to what the Food and Drug Administration does for pharmaceutical drugs. Before a drug is released to the public — before it is administered to a single patient — it must pass through a mandatory, structured, multi-phase review process. Phase one trials. Phase two trials. Phase three trials. Independent safety review boards. Adverse event reporting. Post-market surveillance. The entire process is designed around a single foundational principle: the burden of proof for safety lies with the developer, not with the public that will absorb the consequences.

No pharmaceutical company in the United States is permitted to bring a drug to market by saying: we believe this is probably safe, and even if it is not, in the meantime there will be great companies created by the therapeutics industry.

Why are AI companies permitted to do exactly that?

A mandatory pre-deployment safety review process for frontier AI models — a Frontier AI Review Board, operating under international treaty authority, with independent technical expertise, mandatory capability disclosure, and the legal power to delay or prohibit deployment — is not a utopian idea. It is a minimum viable response to a technology whose own developers acknowledge may pose existential risk.

The EU AI Act, which came into full effect in stages beginning in August 2025, is the closest thing the world currently has to such a framework — designating high-risk AI systems, requiring conformity assessments, and imposing mandatory transparency obligations. (Source: European Parliament, "EU Digital Markets Act and Digital Services Act Explained," https:// http://www.europarl.europa.eu/topics/en/article/20211209STO19124) But the EU AI Act does not cover frontier AI capabilities in the way that Claude Mythos demands to be covered. It was written before the world understood that a general-purpose AI model could, within weeks of completion, autonomously discover and exploit zero-day vulnerabilities in every major operating system on earth.

We need something built for the world we are actually in, not the world we were in when the Act's first drafts were written.

What Needs to Happen — and What Needs to Stop

Let me be direct about what I am asking for, because this book has never been in the business of vague calls to action.

First: no frontier AI model with offensive cybersecurity capabilities above a defined threshold should be deployed — even in restricted access programs — without mandatory notification to an independent international body and a structured review process. The threshold should be defined by independent technical experts, not by the companies whose revenue depends on deployment. Project Glasswing is Anthropic making its own safety determination. I believe Anthropic is acting in good faith. Good faith is not a governance framework.

Second: open-source release of models with capabilities comparable to what OpenAI, Anthropic, and Google are building in their frontier programs must be prohibited by international treaty. China's release of DeepSeek as an open-source model — with its demonstrated ability to produce insecure code when geopolitically sensitive topics are introduced, with its hidden connections to Chinese state telecommunications infrastructure, and with its susceptibility to weaponization by any actor with sufficient compute — is not a gift to the global research community. It is a proliferation event. The same principles that govern the export of nuclear technology must govern the export of frontier AI models. (Source: CrowdStrike, "Chinese DeepSeek-R1 Generates Insecure Code When Prompts Mention Tibet or Uyghurs," November 2025, https://thehackernews.com/2025/11/chinese-ai-model-deepseek-r1-generates.html)

Third: the small and medium businesses, hospitals, water utilities, community banks, and sovereign nations of the Global South that will absorb the brunt of AI-enabled cyberattacks

must be given meaningful protection — not by voluntary industry commitments, but by mandatory liability frameworks that make the companies whose tools enable attacks financially responsible for the harm those attacks cause. When a pharmaceutical company sells a drug that kills people because it was inadequately tested, the company is sued, fined, and sometimes prosecuted. When an AI company releases technology that enables an attack on a hospital that causes patient deaths, the current legal framework offers the victims precisely nothing.

Fourth: the executives of the companies at the frontier of this race — the people who know, as Sam Altman knows, what the probability of catastrophic outcomes looks like, and who are proceeding anyway — must be personally accountable for the decisions they make. Not their companies. Them. Because companies pay fines from reserves. Executives who face personal liability make different decisions.

And fifth: the United Nations must move immediately from the advisory body stage to the treaty stage — from "Governing AI for Humanity" as a report to "Governing AI for Humanity" as a binding international instrument, with enforcement mechanisms, mandatory membership, and the authority to pause development at the frontier when the risk calculus demands it. The Global Mechanism on ICT security that held its first session in March 2026 is a beginning. It must not remain a dialogue. It must become a doctrine.

The Disclosure I Am Obligated to Make

I have used Claude — Anthropic's AI — as my editor and research partner throughout this book. I said so on the first page, and I have said it again here. That disclosure has never been more important than in this chapter.

Anthropic built Claude Mythos. Anthropic launched Project Glasswing. Anthropic is the company that warned the U.S. government that its own model makes large-scale cyberattacks more likely. And Anthropic is the company whose AI I have used to help compress research time, structure arguments, and communicate ideas in the language that my ESL years left me still navigating.

I do not exempt Anthropic from the accountability I am demanding. I cannot. The sincerity of their attempt to govern Mythos responsibly does not exempt them from the responsibility of being among the companies whose race to the frontier has created the conditions that now demand international governance. They are a better actor than Palantir. They are a more honest actor than OpenAI, which quietly deleted the military use prohibition from its terms of service. They are more transparent than Google, whose Gemini tools are being used by Chinese state hackers to plan attacks on American targets while Google processes military contracts through its cloud division.

But better is not good enough when the stakes are extinction. The pharmaceutical analogy holds: a drug company that conducts its own safety trials, reaches honest conclusions, and shares those conclusions with selected partners is still not a substitute for an independent regulatory body with binding authority. Good science and good intentions are prerequisites, not replacements, for good governance.

I use Claude as my editor. I have disclosed that. What I will not do is pretend that disclosure resolves the problem it names. The AI I am using to write this critique is manufactured by a company racing toward capabilities that its own technical teams describe as a watershed — a

moment of genuine discontinuity in the history of cybersecurity — with no binding international framework governing how it proceeds.

I hold that tension openly. And I close this chapter with the same words I have returned to throughout this book, because they have not become less true:

Evil men and their machines do not prevail. But neither does a civilization that refuses to regulate its most dangerous technologies until after they have done their damage.

The window is narrow. Six to eighteen months, by Anthropic's own estimate, before Mythos-class capabilities proliferate beyond the organizations that signed up for Project Glasswing. Six to eighteen months to build the governance frameworks that should have been built before the first line of code was written.

We have been here before. We did not move fast enough. The bomb fell on Hiroshima on August 6, 1945, and the Non-Proliferation Treaty was not signed until 1968.

We cannot wait twenty-three years for the AI equivalent.

The question Albert Einstein spent the last decade of his life asking — what steps can be taken to prevent a contest in which the outcome is disastrous to all parties? — is the question every government, every technology company, every researcher, and every citizen who has read this chapter must now ask themselves.

Because Sam Altman told us the answer to the other question. The one about what happens if we don't ask.

In the meantime, there will be great companies created.

In the meantime. Until the meantime ends.

--- The frontier AI arms race I have described in Chapter Twelve does not exist independent of the broader pattern of American military and economic adventurism that has defined the last thirty years. The systems described in those pages — Gospel, Lavender, Project Maven, Glasswing — are the latest technological expression of a foreign policy that has, since 1945, left a trail of civilian casualties across the Middle East, Central Asia, Latin America, and Africa. Chapter Thirteen widens the lens: not to excuse the technology companies, but to name the empire they serve.