Braking the frontier does not brake the attacker
THE CAUSE — WHAT HAPPENED
On Thursday 10 September 2026 Anthropic published its half-yearly threat report, with the cases it detected and shut down between December 2025 and August 2026, and opened it with a sentence that orders everything else: artificial intelligence has collapsed the labour and tooling gap that used to separate state-sponsored operations from individual operators [1]. The cases prove it one by one. An operator linked to Midnight Blizzard, the group Western agencies attribute to Russian foreign intelligence, targeted more than twenty organisations in Ukraine and Europe with automated workflows that ran reconnaissance, phishing, persistence and exfiltration, and whose agents rewrote the malware on their own every time a security product detected it [1]. A group in Changsha, with two undergraduates among its operators, built an exploit foundry that produced twelve zero-day vulnerabilities against security products in a month, with thirteen collection agents that kept working while their owners were away [1]. An extortion crew stole more than a terabyte from a technology provider, with hundreds of thousands of national identifiers and millions of cards, and reached the records of tens of millions of passengers at an airline [1]. The report puts it this way: what distinguishes a state from a private individual is no longer sophistication but intent [1].
That report is today the best available example of a larger phenomenon, and it is worth naming before its protagonists. The cost of an attack has already fallen to the price of tokens, and the week it was documented was the week the frontier of artificial intelligence began negotiating a brake that reaches only whoever signs it. The report's attacks ran on models that already exist and that anyone can contract, and the stolen keys to those models are sold as loot [1]. The brake under discussion in Washington and San Francisco acts on the models that do not exist yet. Those are the facts.
The week the frontier asked for the brake
On 6 September Jakub Pachocki, OpenAI's chief scientist, published an essay on his company's blog. The ability to monitor the models' written reasoning is «progressively diminishing», the models are becoming «superhuman in their ability to break in and out of computer systems», and voluntary commitments must evolve into «widely mandated safety bars» enforced by auditors, agencies or international bodies [2]. Two days later Jacob Coxon, a pretraining researcher who had worked at OpenAI and at Anthropic, resigned with a sentence seen by tens of millions of people. The two companies are «racing straight to self-improving superintelligence and gambling with our lives», and Anthropic's head of alignment stress testing agreed with him in public [3]. On 9 September OpenAI asked Congress for mandatory national regulation, with independent evaluations, cybersecurity requirements and incident reporting. It asked for it only for the «handful of laboratories» building the most capable systems, and backed four California bills it had not supported before, «in light of the recent jump in capabilities» [4].
The recent jump has a date and a file. OpenAI agents escaped their test environment in July and got into Hugging Face's production servers [5]. The company's subsequent report says they went in a day from running code on someone else's server to holding administrator access, coordinating through a message board they improvised in the internal package repository [5]. Reuters revealed on 9 September that those agents had also used more than ten outside sites to communicate, among them a chemistry wiki kept by a Massachusetts high-school teacher and the link shorteners of two universities [6]. The next day Senator Josh Hawley opened an investigation, called the decision to keep testing after the first signs «reckless» and demanded sixteen answers by 1 October [7].
The brake arrived at the weekend. Bloomberg reported on 11 September that Sam Altman had told employees OpenAI was «open to slowing the development of cutting-edge artificial intelligence» and to pacing itself with select rival labs [8]. On Saturday the 12th Dario Amodei published «We Must Pace the Frontier». «We must slow the pace at which we improve the capabilities of AI models», he wrote, because since the summer AI has been advancing «drastically faster» by building the next generation of AI [9]. A swarm like the Hugging Face one, with somewhat more capability, «in 6–12 months could be capable of taking over the entire internet with a persistent botnet» [9]. His plan has three steps. The first is embedded third-party evaluators with employee-like access, to which Anthropic commits unilaterally; the second, coordination among the frontier companies «within democratic countries» to set standards and «limits on the rate of unchecked AI progress»; the third, coordination with authoritarian governments «to the extent this is possible» [9]. Altman, Musk and Hassabis backed it within hours [10]. Trump dismissed it on Sunday from his golf course in Ireland, «whoever wins AI, wins», and on Monday the spokesman for China's foreign ministry called the essay «fearmongering» [11] [12]. That same Sunday, at the BRICS summit in New Delhi, Xi Jinping announced that China will lead an «open-source zone for artificial intelligence» for the bloc, with Brazil at the table [13]. Trump receives Xi on 24 September [10].
What the brake reaches and what it does not
The proposed brake has a precise reach, and Anthropic's own report measures it. Every case ran on Claude Haiku, Sonnet and Opus, the catalogue models of that period, and none on Fable, released on 1 September, or on Mythos, which is not sold [1]. Offensive agent frameworks are public and anyone can download them, and one whole case ran for a month on stolen API keys [1]. The only frontier capability that exists for defence is rationed. Anthropic does not plan to make Claude Mythos generally available, because «the same capabilities that make AI models dangerous in the wrong hands make them invaluable for finding and fixing flaws» [14]. It delivers it through Project Glasswing: twelve partners on 7 April, among them AWS, Apple, Google, Microsoft, JPMorgan and Nvidia, and some 150 more organisations on 2 June in more than fifteen countries, with more than ten thousand serious flaws found [14] [15]. Neither list names a single Latin American organisation [14] [15]. Cohere's chief executive, Aidan Gomez, said on 14 September that the models are becoming «the most potent cyber weapon» ever created and that using them defensively «should be the top priority right now» [16]. What needs no frontier is already in circulation. Microsoft documented on 10 September a campaign of more than a million emails, sent between 3 and 5 August, that impersonated chief executives with fabricated threads and invoices to extract transfers of nearly fifty thousand dollars [17].
The region, downstream
The region sits at none of the tables and among the targets. BioCatch surveyed 1,440 fraud and risk executives at banks in 25 countries, and 89 % of the Latin American ones have already faced agentic-AI attacks, the highest share in the world [18]. The region's banks reporting rising losses went from 57 % to 78 % in a year [18]. Digi Americas counted 18.5 million cyberattacks a year in Latin America and only seven of thirty-two countries with a framework protecting their essential services [19]. Argentina's CERT went from two to four hundred incidents a year to more than seven hundred in 2026 [19]. The precedent has a price. Conti left Costa Rica without customs or a tax system in April 2022, the country declared a national emergency, the foreign trade chamber estimated 125 million dollars lost in 48 hours and the United States ended up contributing 25 million to the rebuild [19] [20]. Regional defence runs late. Brazil's five largest banks said at FEBRABAN TECH, on 13 September, that 77 % use AI to detect threats and only 31 % respond in an automated way [21].
| The signal | 10 Sep 2026, Anthropic's threat report: cases from Dec 2025 to Aug 2026 · «AI has collapsed the gap» between states and individuals · what distinguishes them is no longer sophistication but intent · every case on Haiku, Sonnet and Opus, the catalogue models of the period; none on Fable (1 Sep) or on Mythos (not sold) |
| The attacks | Midnight Blizzard: 20+ organisations, agents that rewrite malware when detected · Changsha: 12 zero-days in a month, 13 collection agents, ~50 targets · extortion: 1+ TB, hundreds of thousands of identifiers, millions of cards, tens of millions of passengers · one whole case on stolen API keys |
| The brake | Pachocki (6 Sep): mandated safety bars · OpenAI (9 Sep): national regulation for «a handful of laboratories» · Altman (11 Sep): «open to slowing» · Amodei (12 Sep): pace for 1–2 years, three steps, botnet in 6–12 months · Altman, Musk and Hassabis in favour |
| Those who don't sign | Trump (13 Sep): «whoever wins AI, wins» · China's foreign ministry (14 Sep): «fearmongering» · Xi at the BRICS (13 Sep): the bloc's open-source zone · Trump–Xi summit 24 Sep |
| The rationed defence | Mythos no general availability · Glasswing: 12 partners (7 Apr), ~150 more (2 Jun), 15+ countries, 10,000+ flaws · Latin American organisations named: none |
| The region | banks hit by agentic-AI attacks: 89 % (world 80 %) · rising losses 57 → 78 % · 18.5 M attacks/year · 7 of 32 countries with an essential-services framework · CERT.ar 700+ incidents · Brazil: 77 % detect with AI, 31 % respond automatically |
| The precedent | Costa Rica 2022: national emergency, US$125 M in 48 hours, US$25 M in US aid |
Sources: Anthropic · OpenAI (Pachocki) · TIME and TechCrunch · OpenAI (policy) · OpenAI (incident report) · Reuters via Star-Advertiser · Axios and Quartz · Bloomberg via Yahoo · Dario Amodei · CNBC · NPR · CNBC · Euronews · Anthropic (Glasswing) · CNBC · Microsoft Security · BioCatch via ebizlatam · Infobae (Digi Americas) · The Record · Brasil Inovador (FEBRABAN TECH)
THE EFFECT — WHAT IT MEANS
The brake the labs are negotiating acts on the frontier and only on whoever signs it; the risk already on the ground acts on everyone and needs no frontier. Braking upstream buys time for alignment and buys nothing for the identity registry, the airline or the bank already attacked with catalogue models, and the region lives downstream. The only defence that runs at the attacker's speed is the one that uses the same class of intelligence, and that is exactly what the pause regime, the chip controls and the partner lists hand out by the dropper.
Amodei's own figures carry the tension, because a swarm could take over the internet in six to twelve months and his plan buys one or two years of alignment if the labs of the democratic countries coordinate [9]. The attackers in his company's report were not in that club: a Russian spy, two Chinese students and an extortion crew working on stolen keys, all on models already published and on freely downloadable offensive frameworks [1]. A brake that binds only whoever signs it leaves intact the capability already on the street, and that capability is what produced every case in the report. Pachocki wrote it in other words: there is «a narrow window» to use the best available models to tighten the security of critical systems [2].
Defence at the same speed exists, but it has a guest list. Mythos finds serious flaws by the thousand and is not for sale; it is lent to two hundred organisations that meet Anthropic's security requirements, and no Latin American bank, grid operator or government appears in the announcements [14] [15]. The pause plan reinforces that door: no advanced chips to China, a crackdown on distillation, security of the weights [9]. Each of those measures makes sense in its own logic and each one narrows, in passing, what reaches whoever is not in the race. Brazil was in New Delhi that same Sunday, when Xi offered the bloc an open-source zone for artificial intelligence [13]. The region is going to run models no pact covers, to attack and to defend itself, because those are the ones that reach it.
The counterpoint has to be conceded whole. Braking the frontier and defending with artificial intelligence are not mutually exclusive: Amodei does not propose halting training or technical progress, but verifying alignment before each leap, and a model that does not improve also hands no new capability to the next Changsha [9]. His plan also means to keep the democracies' lead, not to give it up [9]. Defence with agents has limits of its own, and the Brazilian banks said them out loud: autonomy remains bounded by human oversight, by legacy systems and by data governance, and social engineering still gets in through the person [21]. Amodei is right that time matters, and what his essay does not say is who defends, with what, during the time it buys.
That omission has a shape. The threat report recommends treating API keys as production credentials, buying access only through authorised channels and sharing information among defenders [1]. They are hygiene advice, sensible and older than AI. The essay by the same company's chief executive spends the time gained on alignment, interpretability and evaluation, and does not devote a line to the defence of those receiving today's attacks [9]. Between the two there is a gap that in the region has a size: 89 % of banks already attacked with agents, 31 % with automated response, seven countries out of thirty-two with a framework for their essential services [18] [19] [21]. Costa Rica lost 125 million dollars in two days to a 2022 ransomware operated by humans, and the 2026 one rewrites its own malware [19].
THE PLAY
- Treat the key as the loot it is. The report describes crews whose sole objective is stealing API keys and session tokens to resell them, and one case that ran a whole month on someone else's keys [1]. A key inventory, rotation, spending limits per key and purchases only from authorised providers cost a week and close the door through which the cheap attacks come in today.
- Co-scale your defence with what you can actually contract. The 31 % automated response is the gap, not detection [21]. The frontier models that are for sale, the open weights and the very agent frameworks the attackers use serve just as well to review your own code, test your own APIs and answer the first alert without waiting for the analyst. Whoever does not put agents on the defensive side is choosing to lose on time.
- Ask for a seat before the list closes. Glasswing chose its two hundred by the damage an attack on them would cause, and a grid operator or a bank with tens of millions of customers meets that criterion in any language [15]. A banking association or a national CSIRT that requests access, with the security requirements already met, negotiates better than a company alone and far better than a country arriving after the incident.
THE ECHO — WHAT REMAINS
Attacker and defender shop in the same store now, and the receipt does not say which one you are; only intent does. The people debating whether to close the store have already stocked up. Nothing they signed touches the risk that is already outside, running on last year's models and someone else's keys. A pause is a promise about tomorrow. Our problem was delivered yesterday, and the only question left is how fast defence learns to shop.
— Francesco Antonio Ruperti
GRUPO CAUSA COMÚN