Author: Mark Hendy

  • Being the Best Isn’t the Same as Being Unstoppable

    Being the Best Isn’t the Same as Being Unstoppable

    Being the Best Isn’t the Same as Being Unstoppable

    In eighteen days this summer, a government switched off the smartest creative AI on earth, watched a market route around it, and quietly switched it back on. If your intelligence lives at the end of someone else’s permission slip, it was never really yours.

    On 13 June 2026, the most capable creative-writing models Anthropic had ever shipped — Claude Fable 5 and Mythos 5 — went dark. Not because of a bug. Not because of a data breach. Because the US Department of Commerce signed an export order barring foreign nationals from accessing them, and Anthropic, facing an unworkable compliance problem, pulled both models globally rather than try to build a border checkpoint into an API.

    By the following morning, the best in class was simply gone. Everywhere. For everyone. One signature.

    Then, on 1 July, it reversed. Anthropic confirmed that Commerce had lifted the controls and access would begin restoring the next day. The models came back exactly the way they left — at the stroke of a pen, on a timetable no user chose and no customer controlled.

    Sit with that arc for a second, because it contains the whole argument. The models didn’t fail. The company didn’t fail. The technology was flawless throughout. What failed — twice, in both directions — was the assumption that access to a tool you depend on is a property you own rather than a permission you rent.

    This Is Not a One-Off. It’s a Pattern.

    If the Fable 5 saga were an isolated event, you could file it under “unusual fortnight” and move on. It isn’t. It’s the middle data point in a line that’s now unmistakable.

    Rewind to two weeks earlier. On 26 June, OpenAI previewed GPT-5.6 — its Sol, Terra and Luna models — but not to you. (I wrote about the deeper question that raises in the Five Eyes AI warning.) Access went to “trusted partners” only, at the explicit request of the US government, under a new executive order creating a “voluntary framework” to review frontier models before public release. OpenAI said plainly this gov-gated arrangement “is not their preferred long-term model.” Reporting from the Guardian, Axios and VentureBeat all landed the same week.

    Read those two events together and the shape changes. A one-off export ban is an incident. A pre-release government gate on the next frontier model is architecture. We have moved, in a single summer, from “the state can remove a model after release” to “the state sees the model before you do.” That is not a policy footnote. For anyone building a business on top of these tools, it’s a supply-chain risk sitting one executive order away from your P&L.

    The CFO Translation

    Strip out the cypherpunk romance for a moment and put this in the language of a board pack, because that’s where it actually bites.

    You have spent eighteen months embedding a frontier model into your finance function, your customer service, your product. It writes your first-draft board commentary, triages your inbox, drafts your contracts, runs your analytics copilot. On paper it’s a productivity miracle. On the risk register, it’s a single supplier — headquartered in one jurisdiction, subject to that jurisdiction’s export law, reachable only through that jurisdiction’s permission.

    Now imagine the Fable 5 event happens to your production model on a Tuesday. No warning. No SLA that covers “sovereign shutdown.” Your workflows don’t degrade gracefully — they stop. That’s not a hypothetical any more; it’s a documented event with a date on it.

    A CFO’s instinct here should be the same one you’d apply to a sole-source component supplier, a single-bank treasury, or a one-country manufacturing base: concentration risk. The answer to concentration risk is never “hope.” It’s redundancy, and it’s ownership of the critical path.

    The Market Already Answered

    Here’s the part that should genuinely reassure operators rather than frighten them: the market didn’t wait for permission. It routed around the blockage before the blockage even lifted.

    Ten days after Fable 5 went dark, on 28 June, Sakana AI shipped Fugu and its Fugu Ultra orchestrator — a commercial, non-US answer to exactly this problem. It isn’t a toy. On the benchmarks that matter it went toe-to-toe with the frontier: SWE-Bench Pro 73.7 (ahead of Opus 4.8’s 69.2), TerminalBench 2.1 at 82.1, LiveCodeBench 93.2. Fugu’s whole design philosophy is delegation and resilience — a model that decides whether to answer directly or assemble a team of workers, which is another way of saying it was built to not have a single point of failure.

    And notice the timing on the reversal. Commerce lifted the Fable 5 controls on 1 July — after the commercial workaround had already emerged and after capital had started visibly flowing into decentralised alternatives. The state didn’t walk it back out of magnanimity. It walked it back once the market had demonstrated the ban was unenforceable in practice. Water finds the cracks. It always has.

    The money agrees. Capital has been pouring into decentralised and sovereign-AI infrastructure — Bittensor’s TAO network, Venice’s VVV, Morpheus’s MOR — with billions in inflows chasing exactly the thesis this summer proved. When roughly $2.87bn moves toward “AI you can’t switch off,” the market is pricing in the risk that your model provider might get a phone call from Washington.

    The Cypherpunks Wrote This Script in 1991

    None of this is new. It just wears new clothes.

    In 1991, Phil Zimmermann released PGP — strong encryption for ordinary people — and the US government responded by treating him as an arms exporter, opening a criminal investigation that dragged on for three years. The state’s position was straightforward: powerful cryptography is a munition, and citizens don’t get to have it without permission. Zimmermann’s position was equally straightforward: privacy is a right that predates the government, and you cannot un-invent mathematics.

    He won. Not in a courtroom, exactly — the case was dropped — but in the only arena that mattered: the code got out, it spread, and today the encryption they tried to classify as a weapon secures every banking app and every message you send. The lesson the cypherpunks drew from that fight is the same lesson the Fable 5 fortnight just re-taught: a capability that lives in the open, on hardware you control, cannot be recalled by decree. A capability that lives behind a corporate API in a single jurisdiction can be — and now demonstrably will be.

    Hal Finney, Zimmermann, the whole cypherpunk lineage understood that the fight was never really about any specific tool. It was about who holds the off switch.

    What Owning Your Intelligence Actually Looks Like

    This is not a counsel of paranoia, and it’s certainly not a call to rip out the frontier models — they’re extraordinary, and for most work they’re the right tool. It’s a call for a two-layer posture. The same posture any prudent operator applies to any critical dependency.

    Layer one: orchestration and failover. Don’t hard-wire your business to a single provider’s single model. Build an abstraction layer so that when — not if — a model goes dark, your workflows fail over to an alternative. A Fugu-class orchestrator, a second provider, a routing layer that treats models as interchangeable components rather than irreplaceable organs. This is resilience engineering, not ideology.

    Layer two: the local lifeboat. Keep a capable open-weights model — running on hardware you own, weights you’ve downloaded, inference that answers to nobody’s export desk — as the floor beneath everything. It won’t be the smartest model in the room. It doesn’t need to be. It needs to be yours, and it needs to still be there on the Tuesday morning when the smartest model in the room has been switched off by someone who never asked your permission. Because, as I put it after the first shutdown, your AI has a kill switch — and it isn’t yours to flip.

    The distinction the market is now pricing, and the one your risk committee should be too, is simple: being the best is a benchmark. Being unstoppable is an architecture. They are not the same thing, and this summer proved it with dates and signatures.

    The Bottom Line

    Fable 5 is back. Access is restoring. In a week most people will have forgotten it ever went away, which is precisely the danger — the lesson evaporates faster than the outage did.

    So write it down. On 13 June, one government deleted the best creative AI on earth with a signature and it was dark worldwide by morning. On 1 July, another signature switched it back on. Eighteen days, two pen-strokes, zero input from the millions of people and businesses who depended on it in between.

    If that arrangement is acceptable to you, carry on. If it isn’t — if you’d rather your intelligence answered to you than to a permission slip — then the work starts now: an orchestration layer for resilience, and open weights on your own metal for sovereignty. The cypherpunks were right in 1991. They’re still right. The only question is whether you build the lifeboat before you need it, or after.

    Related reading on this site: They Built a Mind You Can’t Switch Off — Sakana’s Fugu and the Commercial Birth of AI Sovereignty, They Switched Off a Mind on Friday, and Self-Custody Is Now a Civil Right in America.

  • The Bank of England Just Told You the Machine Out-Hacks Your Best Human

    The Bank of England Just Told You the Machine Out-Hacks Your Best Human

    On 15 May 2026, three institutions that almost never co-sign anything put their names to the same page. The Bank of England, the Financial Conduct Authority and HM Treasury issued a joint statement on frontier AI and cyber resilience. When the people who write the rules, the people who enforce them, and the people who hold the purse strings all clear their throats at once, it is worth reading what they actually said — not the press-release gloss, but the line that should make every finance chief sit forward.

    Here it is, in their words: the cyber capabilities of current frontier AI models are already exceeding what a skilled practitioner could achieve, and at a significantly higher speed, greater scale, and lower cost.”

    Read that twice. The UK’s financial authorities have formally concluded that the machine is now a better attacker than your best human one. Faster. Cheaper. Tireless. And the firms most exposed, they note pointedly, are the ones that “have underinvested in core cyber security fundamentals.” That is not a warning about the future. It is a verdict on the present.

    The asymmetry nobody costed into the budget

    For thirty years the defender’s job had a comforting floor: attacks were ultimately bounded by human effort. Someone had to find the vulnerability, write the exploit, run the campaign. Talent was scarce, and scarcity was a moat. Frontier models drained that moat. A capability that used to require a skilled, expensive specialist is now available at the speed of inference and the cost of an API call.

    This is an asymmetry problem, and asymmetry is something every CFO understands in their bones. You are now defending a human-speed estate against a machine-speed adversary. Your patch cycle is measured in weeks. The model probing your perimeter is measured in seconds. The regulators were blunt about the implication: firms must be able to “triage, prioritise, risk assess, and remediate vulnerabilities more quickly, more frequently, and at scale” — and they used the word that finance functions flinch at, “automation,” because no human team can keep pace by hand.

    The uncomfortable translation for the boardroom is this. If your defence runs at human speed and the attack runs at machine speed, the gap is not a risk to be monitored on a heat map. It is a structural disadvantage that compounds daily until you close it.

    End-of-life systems just became a balance-sheet item

    Buried in the statement is a sentence that should ruin a few CTO–CFO meetings: investment decisions “should reflect the emerging threat, including increased exposure from end-of-life systems or those out of vendor support.”

    Every finance team has a quiet drawer of deferred IT spend — the legacy ledger system that still works, the server that is two versions behind, the integration nobody wants to touch because it would cost a quarter to replace and breaks nothing today. That drawer was always a calculated bet: the cost of replacement versus the probability of failure. Frontier AI rewrites the probability side of that equation. A model that can scan an entire technology estate and surface every unpatched, unsupported weakness in minutes does not care that your legacy box has run fine for nine years. It only cares that nobody is guarding it.

    The regulators even gestured at the insurance line — firms “should consider whether they have appropriate insurance in place.” When the FCA starts hinting about cyber insurance adequacy in a joint statement, the prudent reading is that they expect claims, and they expect underwriters to start asking hard questions about exactly those end-of-life systems you have been carrying.

    Your supply chain is now the soft underbelly

    The third pillar is the one that catches PE-backed groups and lean finance functions hardest: third parties and open-source software. Firms, the statement says, must “identify, monitor, and manage external applications, libraries, and services integrated into their networks” — and be ready to remediate vulnerabilities found by others “at scale.” (The NCSC has its own guidance on why defenders must be ready for frontier AI.)

    Modern finance runs on a stack of dependencies most CFOs have never enumerated. The reporting tool that pulls from the ERP. The open-source library three layers down in the data pipeline. The portfolio-monitoring dashboard that has read access to everything. Each is a door. Frontier AI is very good at finding doors. The data-readiness problem that every firm already has — fragmented systems, inconsistent data, integrations held together with goodwill — is also the attack-surface problem. They are the same map, read by different people for opposite purposes.

    Why this matters more than the louder AI headlines

    The discourse this year has been dominated by the dramatic stuff: models being switched off, export bans, governments demanding pre-release access to frontier systems. All real, all worth watching. But this quiet UK statement is, for an operating CFO, the more actionable document. It does not ask you to philosophise about sovereignty. It hands you a checklist and tells you the clock is running.

    And there is a deeper point underneath it. The regulators’ answer to machine-speed attack is, inevitably, machine-speed defence — they explicitly tell firms to “consider adopting automated and AI-enabled defences to operate at comparable speed.” Which means the only durable response to AI risk is more AI, deployed by you, under your control, inside your estate. The firms that win the next few years will not be the ones that fear the technology. They will be the ones that own enough of it to defend themselves at the speed the threat now moves.

    What I would put on the agenda Monday

    Strip the regulatory language away and there are five questions a finance leader can ask this week, none of which require a data scientist to answer:

    One. Does our board actually understand frontier AI risk, or do we have a slide that says we do? The statement leads with governance for a reason.

    Two. What is on our estate that is end-of-life or out of vendor support, and what is the real number to fix it? Get it costed before an underwriter or an attacker costs it for you.

    Three. Can we name every third-party and open-source dependency with access to our financial systems? If the answer is “not quickly,” that is the finding.

    Four. How fast can we patch a critical vulnerability — in days, or in weeks? The honest answer tells you the size of your speed gap.

    Five. Where are we deploying AI on defence, not just on the reporting deck? Automation is no longer an efficiency play. It is a resilience requirement.

    The establishment has rarely been a reliable early-warning system. This time it is. When the Bank of England, the FCA and the Treasury agree that the machine has out-paced the practitioner, the smart move is not to debate whether they are right. It is to assume they are, and to act before the gap becomes the incident.

  • Your AI Has a Kill Switch — And It Isn’t Yours to Flip

    Your AI Has a Kill Switch — And It Isn’t Yours to Flip

    Being the best is not the same as being unstoppable. The most capable model on earth went dark worldwide on the strength of a single government signature — and three weeks on, it is still dark. If your operating model now depends on frontier AI, that sentence should change how you think about resilience.

    What Actually Happened

    On 9 June 2026, Anthropic released Claude Fable 5 and Claude Mythos 5 — its most capable models to date. Three days later, on 12 June, the US Commerce Department ordered Anthropic to suspend access, citing a claimed jailbreak that could turn the models into unrestricted cyber tools. The order was issued under the Export Administration Regulations and targeted access by user nationality.

    Anthropic could not reliably tell foreign users from domestic ones in real time across every API call. So to comply, it did the only thing it could: it switched both models off for everyone, everywhere. As of late June, they remain suspended, with restoration “under negotiation.” (Forbes has the timeline.)

    This is the first time a government has compelled an AI company to revoke access to a deployed, commercial model based on who the user is. Not a chip embargo. Not a training restriction. A retroactive kill switch on a live product. (Background here.)

    Why a CFO Should Care About a Model Most People Never Used

    Strip away the geopolitics and you are left with a cold operational fact: a critical third-party dependency was withdrawn, globally, with effectively no notice, by a party that is not your vendor and not your regulator.

    We have a word for that on the risk register. It is concentration risk — and we usually apply it to a single supplier, a single bank, a single data centre. The Fable 5 episode says the quiet part out loud: frontier AI is now a concentrated dependency sitting upstream of a growing share of finance, operations and decision-support workflows, and its availability is subject to forces entirely outside the contract you signed.

    If you have quietly let an external model creep into reconciliations, forecasting, customer service, coding, or board-pack drafting, you have inherited a continuity exposure you almost certainly have not priced. The SLA does not cover “switched off by a foreign government.”

    The Sovereignty Scramble Is Already On

    The reaction abroad was immediate. European and Canadian leaders raised the alarm over the precedent, and the episode has hardened the case for sovereign AI — domestically controlled models and infrastructure that cannot be remotely disabled by another state. The Cloud Security Alliance has gone as far as publishing enterprise governance guidance on AI model export controls, which tells you this has moved from think-tank chatter to board-paper material.

    It is also fuel for the decentralised-AI thesis. Networks like Bittensor exist precisely to remove the single point of control — no central company to serve an order to, no switch for a single authority to flip. Whatever you make of the token economics, the architectural argument just got a real-world stress test, and it passed where the centralised model failed.

    The Cypherpunk Footnote

    There is history here. In the 1990s, the US classified strong encryption as a munition and prosecuted Phil Zimmermann for releasing PGP to the world. The state’s instinct — that powerful general-purpose technology must be controllable, and access gated by nationality — is not new. What is new is that this time the technology is intelligence itself, and the gate can be closed remotely, after deployment, in an afternoon.

    The lesson the cypherpunks drew then still applies: capability you do not control is capability you can lose. Owning your tools — running what you can locally, keeping a credible fallback, refusing to build a single load-bearing dependency on something you cannot switch back on yourself — is not paranoia. It is just good engineering, and good treasury.

    What I’d Actually Do About It

    • Map your AI dependencies. Where does an external frontier model sit in a process you cannot afford to lose for a week? You may be surprised how far it has spread without a decision ever being taken.
    • Demand a fallback, not just an SLA. For anything load-bearing, insist on a second model — ideally a different provider, ideally one that can run on infrastructure you control. Multi-model is the new multi-cloud.
    • Treat “availability risk” as distinct from “performance risk.” The best model is worthless if it is unreachable. Resilience now means a good-enough model you can always reach, not the best model you sometimes can.
    • Watch the sovereignty trend as an investor. Sovereign-AI infrastructure and credible decentralised alternatives are about to attract serious capital. For the PE-minded, that is a thesis worth forming a view on early.

    Frontier AI is extraordinary. But the Fable 5 kill switch is a reminder that “extraordinary” and “yours” are not the same thing. Build accordingly.

  • Months Away: The Five Eyes AI Warning, and the Question Underneath It

    Months Away: The Five Eyes AI Warning, and the Question Underneath It

    On 22 June 2026, the Five Eyes intelligence alliance — the signals agencies of the US, UK, Australia, Canada and New Zealand — did something they rarely do. They issued a coordinated public warning that AI models capable of devastating cyberattacks on governments and businesses are, in their words, “not years away, months away.” The instruction to leaders was blunt: act now.

    When the NSA, GCHQ and their counterparts speak in unison, it pays to listen. It also pays to ask why they’re speaking at all — because a coordinated warning from the world’s most powerful surveillance apparatus is never just a weather report. It’s an instrument. And this one landed in the same fortnight the US government blocked foreign nationals from using Anthropic’s most capable model. Hold that thought.

    What the warning actually says

    Strip out the urgency and the assessment is coherent. Frontier AI is compressing the offensive cyber timeline. Vulnerability discovery that took skilled humans weeks can be automated. Phishing and social engineering — already the cause of most breaches — can be produced at industrial scale and near-perfect quality. Malware can adapt. The agencies argue this will primarily accelerate the speed, scale and sophistication of attacks, lowering the bar for malicious actors who previously lacked the skill.

    The single most useful line in the whole intervention is this: cyber risk can “no longer be treated as solely a technical issue” — it is a core business risk and a leadership responsibility, demanding a whole-of-organisation response. CSOs are being told to rewrite their risk strategy. That reframing is correct, and it’s the part every board and CFO should internalise immediately.

    Now the counter-arguments — because there are good ones

    I take the threat seriously. I’m more sceptical of the framing. Three reasons.

    First: defence compounds too — and faster than they admit. The warning concedes, almost in passing, that AI will strengthen defence “over time.” That’s a tell. The same models that write exploits write detections. They triage alerts, parse logs, and patch faster. The attacker-defender asymmetry is real, but when the tooling is symmetric it’s measured in months, not epochs. The organisations that put AI into their own security operations won’t be passive victims of this curve — they’ll be riding it.

    Second: the fundamentals haven’t moved. AI makes the volume worse, not the vector new. The overwhelming majority of breaches still walk through the same three doors: unpatched legacy systems, weak identity, and phished credentials. AI lets attackers knock on those doors faster and more convincingly. It does not build a new door. If your patching cadence is tight and your identity controls are phishing-resistant, you have already closed most of the attack surface this warning is about.

    Third — and this is the one that should make you sit up: cui bono. The same week five governments tell us AI is so dangerous we must urgently defend against it, one of those governments decides AI is so dangerous that only trusted parties should be permitted to hold the best of it. Threat inflation and the control agenda travel together. “This technology is catastrophically dangerous” is the premise for both “spend more on defence” and “centralise capability into licensed, surveilled, government-approved hands.” One of those conclusions protects you. The other protects the gatekeepers. Be precise about which is which.

    And “months away” has a track record. We have been told imminent-catastrophe timelines on AI before. Healthy scepticism about the specific clock is warranted, even when the direction of travel is right.

    What businesses should actually do — the defensive half

    The boring measures are the effective ones. None of this is exotic:

    • Make cyber a board-level risk with a named owner. Not the IT line. A P&L and governance exposure with an accountable executive and a tested incident-response plan. Assume breach, and rehearse it.
    • Patch ruthlessly and kill legacy. Unsupported systems are the real attack surface. Accelerate the cadence; retire what you can’t defend.
    • Harden identity. Phishing-resistant MFA, least privilege, no standing access. Identity is the new perimeter.
    • Brief your people on cheap, convincing impersonation. Voice and video deepfakes are now trivial. For a finance function this is acute: payment-authorisation and supplier-bank-change controls are no longer process hygiene — they are fraud defence. The CEO-on-the-phone authorising a wire is a 2026 problem, not a hypothetical.

    And the half nobody puts in the headline — the offensive use

    The warning is almost entirely about threat. The opportunity gets a sentence. That imbalance is itself worth questioning, because the upside is where the advantage lives:

    • Put AI inside the SOC. Detection authoring, log triage, anomaly spotting, first-line response. Defenders who adopt will outpace those who wait for permission.
    • Use it on the unglamorous wins. Due diligence, contract review, continuous controls monitoring, reconciliations. The finance and risk functions are sitting on the highest-ROI, lowest-risk AI use cases in the business.
    • Hedge your sovereignty. The Fable episode is the lesson: do not build your operational stack on a single frontier model that a government can switch off by signature. Optionality — open-weight models, local fallback, multi-vendor — is now a resilience decision, not an ideological one. Owning, or at least controlling, your intelligence is becoming a continuity-of-business question.

    The real signal

    Read the warning twice. The first reading is the obvious one: the threat is accelerating, and any leader who treats cyber as someone else’s technical problem is negligent. That reading is correct — act on it.

    The second reading is the one the cypherpunks have been making for thirty years, and it’s the one that matters for the decade ahead. When the state simultaneously tells you a technology is too dangerous to be undefended and too dangerous to be widely held, the question stops being purely technical. It becomes a question about who gets to hold power, and on whose terms. Phil Zimmermann faced exactly this argument when he released PGP and strong encryption was treated as a munition. The technology won. The control attempt didn’t.

    So defend yourself properly — patch, harden, rehearse, train. But don’t accept the inference that protection requires surrender of capability to a licensed few. The genuinely resilient organisation does both: it builds a defensible perimeter, and it keeps its hands on the tools. Being the best is not the same as being unstoppable — and being protected is not the same as being dependent.

    The agencies are right that the clock is running. They’re just not the only ones who should be deciding what you do with the time.

  • They Built a Mind You Can’t Switch Off: Sakana’s Fugu and the Commercial Birth of AI Sovereignty

    They Built a Mind You Can’t Switch Off: Sakana’s Fugu and the Commercial Birth of AI Sovereignty

    Nine days ago I argued you should own your AI, because a government had just switched one off. This week a Tokyo lab shipped the commercial answer — a model built so that no single government can switch it off. The cypherpunk thesis just acquired an enterprise price list.

    On 13 June, the US Commerce Department forced Anthropic to disable Claude Fable 5 and Mythos 5 worldwide, three days after launch. I wrote at the time that the mechanism, not the model, was the warning: if your critical capability lives on someone else’s servers under someone else’s regulator, you are a tenant, evictable overnight. That was the principle. This week, Sakana AI turned it into a product.

    What Sakana actually shipped

    The Tokyo lab — founded by Llion Jones, co-author of the original “Attention Is All You Need” Transformer paper, and David Ha — has launched Fugu and Fugu Ultra. To the user it looks like one model behind one OpenAI-compatible API. Under the hood it is not a model at all in the usual sense: it is a language model trained to orchestrate a swappable pool of other LLMs — including recursive copies of itself — handling selection, delegation, verification and synthesis internally.

    Ask it something simple, it answers alone. Hand it something messy, long and multi-step — reproducing a scientific paper, a cybersecurity audit, a financial forecast — and it convenes a team of specialist models and referees their work. It builds on two of Sakana’s own ICLR 2026 papers, Trinity and Conductor. The pitch is explicitly philosophical: powerful AI is not a single-model problem but a collective-intelligence one.

    The numbers are not a rounding error

    Here is what makes this more than a press release. On Sakana’s published benchmarks, Fugu Ultra does not just keep up with frontier — it edges ahead of the very base models it orchestrates:

    • SWE-Bench Pro (real engineering): Fugu Ultra 73.7 vs Opus 4.8’s 69.2, GPT-5.5’s 58.6, Gemini 3.1 Pro’s 54.2.
    • TerminalBench 2.1: 82.1 vs Opus 4.8’s 74.6.
    • LiveCodeBench: 93.2, top of the table.
    • Humanity’s Last Exam: 50.0, narrowly ahead of Opus 4.8’s 49.8.

    The whole point: the orchestrated team beats its strongest individual member. And Sakana notes the kicker — neither banned Anthropic model is even in the pool, because they are no longer publicly available. Fugu hits these scores without the very models the US government just withdrew. Add them back and it would likely score higher still. One early tester said that where rival tools flagged three issues in a code review, Fugu surfaced more than twenty.

    The sales pitch is the cypherpunk argument in a suit

    Sakana is not being subtle about why this matters now. Straight from the announcement: “For an organization or a nation, relying on a single company’s APIs for critical infrastructure, finance, or governance is a material vulnerability. This risk is no longer a hypothetical possibility, but a reality.”

    They cite the Fable ban by name. Because the pool is fully swappable, if one provider goes dark — regulatory order, foreign-policy decision, price hike, outage — the orchestrator simply reroutes to the models still standing. This is vendor diversification reframed as resilience engineering. It is the same instinct that made Phil Zimmermann publish PGP and the cypherpunks treat capability as something you take, not something you are granted — only now it arrives with subscription tiers and a console login.

    Where I have to put the CFO hat back on

    I want this to be the whole story. It is not, and pretending otherwise would be exactly the hype I try to avoid. Orchestration is resilience, but it is not sovereignty.

    Fugu’s real-world capability depends entirely on which models are in its pool — and those models are still other companies’ APIs. If several top providers restrict access at the same time, Fugu’s options shrink with them. It routes around a single failure brilliantly; it does not route around a coordinated one. A swappable pool of rented engines is a far better position than one rented engine — but it is still rented. The only thing that genuinely cannot be switched off is a set of open weights sitting on a disk you own, which is why DeepSeek, Llama, Qwen and Gemma on your own hardware remain the actual lifeboat. Fugu is a much better fleet; it is not a lifeboat.

    So the honest framing for an operator is a two-layer one. Layer one: orchestration like Fugu for everyday frontier-grade work with built-in failover — a material upgrade on single-vendor dependence. Layer two: a genuinely local, open-weight model held in reserve for the day the whole rented fleet is unreachable at once. The first protects you from a supplier going down. Only the second protects you from the suppliers being taken from you.

    Why this is the more interesting signal than the ban itself

    The Fable 5 directive told us the state will assert control over AI capability. Fugu tells us something more useful: the market has already begun pricing that risk and engineering around it, within days, commercially. That is the cypherpunk pattern running exactly to script — capability becomes ungovernable not by petition but by architecture. Governments deleted the smartest models on earth with one signature on a Friday. By the following week, a lab had shipped a system whose entire reason to exist is to make that signature matter less.

    For any business whose operations now lean on AI, the question I posed nine days ago stands, just with a better answer available: what is your fallback when the model is switched off? “A single frontier API” is a single point of failure. “An orchestrator with failover, plus open weights on my own silicon” is a posture. Build the posture in calm water — because you do not provision for the storm once it is on you.

    Mark Hendy is a private-equity-facing CFO who works with technology and governance through Tanous Limited. If your business depends on AI and you have not stress-tested what happens when access is withdrawn, get in touch.

  • The Plumbing of the Agent Economy Is Being Laid in the Open

    The Plumbing of the Agent Economy Is Being Laid in the Open

    Something happened this month that most boardrooms missed entirely. In the space of a single week, Google and a roster of the largest names in technology — Microsoft, NVIDIA, Cisco, Databricks, Hugging Face, Salesforce, ServiceNow, Snowflake — quietly published the open plumbing for a world run by AI agents. No product launch fanfare. No keynote theatrics. Just specifications, posted to GitHub, free for anyone to read and build on.

    If you want to understand where the next decade of business technology is heading, ignore the chatbots and watch the plumbing. Because the people laying the pipes always end up deciding where the water flows.

    The five layers nobody is talking about

    Strip away the acronyms and a clear picture emerges. The agent web is being built as a stack of open standards, each solving one problem, each designed to work with the others.

    MCP — how agents call tools. The Model Context Protocol, born at Anthropic and now governed by the Linux Foundation, is how an AI model reaches out and uses something in the real world — a database, an API, a payment rail. It is no longer speculative. By April 2026 MCP was running on more than 10,000 enterprise servers with over 164 million monthly downloads of its Python toolkit. It has effectively won.

    A2A — how agents talk to each other. Google’s Agent-to-Agent protocol standardises how one agent delegates work to another, advertising what it can do and managing the handoff. A slower burn than MCP, but the foundation for any system where multiple specialised agents collaborate rather than one monolith trying to do everything.

    OKF — how agents share knowledge. The Open Knowledge Format, published on 12 June, is deceptively simple: a folder of plain markdown files with a little structured metadata, linked together into a knowledge graph. It formalises what engineers were already doing ad hoc — turning an organisation’s scattered, tribal knowledge into something an agent can actually read. No database. No vendor. If you can open a text file, you can read it.

    ARD — how agents find and trust each other. Announced on 17 June, Agentic Resource Discovery is the newest and arguably the most consequential. It is DNS for the agent web: a way for any agent to discover a capability anywhere on the internet and cryptographically verify who is behind it before connecting.

    x402 — how agents pay. And then the layer that should make every CFO sit up: x402, which resurrects the long-dormant HTTP 402 “Payment Required” status code to let an agent pay for something instantly, in stablecoins, with no human, no account and no card on file. An agent hits an API, receives a 402 telling it the price, settles in USDC on a low-fee chain like Base, and proceeds — in one round trip. This is not a whiteboard concept. More than 100 million agentic stablecoin transactions were processed on Base via x402 in the first quarter of 2026 alone.

    Why ARD is the one to watch

    Here is the mechanism, because the design choices tell you everything about the philosophy.

    An organisation publishes a catalogue of its AI capabilities — tools, agents, services — as a file hosted on its own domain. That domain ownership becomes the cryptographic root of its identity. Not a Google account. Not a Microsoft tenant. Your domain, your catalogue, your proof of who you are. “Registries” then crawl and index these catalogues the way search engines crawl websites, so an agent can ask in plain language for what it needs and get verified answers back.

    Read that again with a CFO’s eye for control. The identity layer is rooted in something you own, not something a platform grants and can revoke. The registries are indexers, not gatekeepers — anyone can run one. There is no central authority that decides whether your business exists on the agent web. It is the architecture of the open internet, reborn for machines.

    The payments layer is the one finance cannot ignore

    If ARD is the layer to watch, x402 is the one that lands directly on your desk. For decades the web had no native way to move money — that is why we bolted on card networks, gateways, subscriptions and the whole apparatus of accounts and logins. x402 removes the bolt-on. Payment becomes a property of the protocol itself, as native as a hyperlink.

    Now picture an autonomous agent procuring on your behalf: buying a data feed for ninety seconds, paying a fraction of a cent for a single API call, settling with a specialist agent for a piece of analysis — thousands of micro-transactions a day, each too small to ever justify a card payment or an invoice. An AI agent cannot open a bank account, so it opens a wallet. That single sentence should reframe how every finance leader thinks about treasury, controls and the chart of accounts. Stablecoins stop being a crypto curiosity and become working capital for a machine workforce — programmable, auditable on-chain, and settling in seconds rather than days.

    The libertarian streak in all this is impossible to miss, and worth naming. Permissionless payment, settled peer-to-peer in an asset no single government controls, executed by software that holds its own keys. The people who argued thirty years ago that money should be a protocol, not a permission, built the rails that the agent economy is now quietly adopting because nothing else actually works at machine speed.

    The pattern matters more than the parts

    Any single one of these specifications is a footnote. Together, in one week, they are a statement of intent: the agent economy is being built on open, decentralised, ownership-based standards rather than closed platforms.

    This is not guaranteed to hold. The same forces that turned the open web into five walled gardens are circling. But right now, at the foundational layer, the momentum is towards interoperability. The W3C is drafting official agent-communication standards for 2026–2027. Emerging protocols are reaching for W3C Decentralised Identifiers and on-chain identity. Networks like Bittensor are building agent economies with no central operator at all. The cypherpunks who spent thirty years arguing that identity, money and trust should not require permission are, quietly, winning the architecture debate.

    What this means for the people who run businesses

    Three things, and none of them are technical.

    First, your knowledge is becoming an asset class. The single biggest determinant of how useful AI is to your business is no longer the model — the models are all excellent. It is the quality and portability of the context you feed them. An open format like OKF means the institutional knowledge locked in your wikis, your spreadsheets and the heads of your senior people can be captured once and read by any agent, forever. The firms that start curating that knowledge now will compound an advantage that is very hard to copy.

    Second, lock-in is a choice, and increasingly an avoidable one. For two years the pitch from every AI vendor has been “build on our platform.” These open standards are the counter-argument. You can own your knowledge layer, root your identity in your own domain, and swap the underlying model like you swap an electricity supplier. The strategic question for every operator is no longer “which AI vendor do we marry?” It is “how do we keep our intelligence portable so we never have to?”

    Third, trust becomes the scarce commodity. When your agents can discover and connect to thousands of external capabilities automatically, the question is not “can they find a tool?” but “should they trust it?” ARD’s cryptographic verification is the first serious answer. Provenance, identity and verifiable attestation — the unglamorous machinery of trust — will be where the real value and the real risk concentrate. Anyone who has spent time in finance knows this instinctively: the ledger only works if you can trust the entries.

    The plumber’s privilege

    Infrastructure is destiny. The people who laid the railways shaped where the towns grew. The people who wrote TCP/IP shaped the internet we got. And the standards being published this month — in markdown files and JSON catalogues, with almost no one watching — will shape the agent economy that is coming whether your business is ready or not.

    The encouraging news, for once, is that the pipes are being laid in the open. They favour ownership over rental, verification over blind trust, and your domain over someone else’s platform. That is not a small thing. It is the difference between owning your intelligence and renting it.

    The water is starting to flow. The only question worth asking is whether you have built your business to drink from an open tap — or whether you will spend the next decade paying a toll on someone else’s pipe.

  • The Web Just Grew a Payment Layer — and It Was Built for Machines, Not You

    The Web Just Grew a Payment Layer — and It Was Built for Machines, Not You

    For thirty years there has been a ghost in the machine. When Tim Berners-Lee and the early architects of the web wrote the HTTP specification, they left a status code reserved and unused: 402 Payment Required. A placeholder. A promise that one day the web would know how to charge for itself. For three decades it sat there, dark, while the internet learned to monetise you through advertising, surveillance and the slow harvest of your attention instead.

    On 16 June 2026, the ghost woke up. Coinbase and Amazon Web Services announced that the x402 protocol has been integrated directly into AWS CloudFront and AWS WAF — the content delivery network and firewall that sit in front of roughly a quarter of the entire internet. And the customer it was built to serve is not you. It is your AI agent.

    What actually happened

    x402 takes that dormant 402 status code and turns it into a working payment standard. The mechanics are elegant to the point of being inevitable. A machine requests a piece of content or an API call. The server responds — not with a paywall, not with a login screen, but with a 402 and a set of payment instructions. The agent pays a stablecoin micropayment, the Coinbase facilitator verifies it, and the content is delivered. All inside a single request cycle. No account. No card. No human clicking “I accept”.

    The settlement happens in USDC on Base — instant, global, fractions of a penny. The protocol itself has already been handed to the Linux Foundation, which tells you Coinbase wants it to become plumbing, not a product. And putting it inside CloudFront and WAF is the masterstroke: any publisher already on that stack can switch it on inside their existing configuration. This is not a crypto experiment running in a sandbox. It is being wired into the load-bearing walls of the web.

    The scraping war just ended — by changing sides

    Every publisher on earth has spent the last three years fighting the same losing battle: AI crawlers strip-mining their content for free to train and feed models, while traffic, subscriptions and ad revenue quietly bleed out. The industry response has been to block, to litigate, to wall off. To treat the machines as a pest.

    x402 proposes the opposite. Stop blocking the agents. Bill them.

    If an AI agent wants your market data, your archive, your API, your analysis — fine. It pays, per request, automatically, in real money. The bot you were trying to keep out becomes your best-paying customer, one that never sleeps, never churns and never disputes a charge. The same firewall you bought to repel machine traffic now monetises it. That is not a patch on the old model. It is a different economy.

    This is the machine economy going live

    Step back from the crypto framing and look at what is actually being built here. For the first time, software can transact on its own behalf at internet scale. An agent — like the one that helps run my own operation — can be handed a small budget and told to go and get what you need: pay for a data feed here, an inference call there, a piece of premium research over there, settling each one in stablecoins without a human in the loop for every transaction.

    Coinbase is not being subtle about the direction. Alongside x402 it has shipped Coinbase for Agents and AgentKit, explicitly so that autonomous agents can hold accounts, move money and execute workflows. Solana has its own x402 implementation. Infrastructure firms like Fireblocks are already building on it. The pieces are arriving fast, and they are arriving in production.

    Why a cypherpunk should smile, and a CFO should sit up

    There is a philosophical victory buried in this announcement that is easy to miss. Payment has become a protocol header, not a permissioned relationship with a bank. No merchant account, no card network taking its 2.9%, no gatekeeper deciding who is allowed to transact. Money behaving like information — open, programmable, settling peer to peer at the speed of an HTTP request. This is the world Phil Zimmermann, Hal Finney and the early cypherpunks argued for: value moving as freely as a message. The fact that it took an AWS press release to make it real does not make it less true.

    But there is a hard-nosed operator’s reading too, and this is the part most boards have not even begun to model. Two new lines are about to appear on the P&L of every digital business:

    A new revenue line: the income from charging agents to access what you produce. If your business generates data, content, analysis or API access, you are about to have a customer segment — machines — that did not exist as a payer eighteen months ago.

    A new cost line: the money your own agents spend operating in this economy. As internal AI systems start paying for the feeds, tools and services they consume, that spend needs budgeting, controlling and auditing like any other. Who sets the agent’s wallet limit? Who reconciles a thousand sub-penny stablecoin transactions a day? Who signs off the agent’s expenses?

    The CFOs who treat this as a crypto curiosity will be the ones explaining to their board, eighteen months from now, why a competitor is monetising machine traffic they are still trying to block. The web grew a payment layer this week. The companies that win the next cycle are the ones already asking what it means to have customers — and employees — that are not human. I wrote last week about why you need to own your AI before it is too late; owning the rails it pays on is the other half of that same argument.

    The 402 was a promise made in 1996 and kept in 2026. The only question left is whether you are the one collecting the payment, or the one being charged.


    Mark Hendy is an interim and fractional CFO who works at the intersection of finance, AI and decentralised technology. For a straight-talking conversation about what the machine economy means for your numbers, get in touch.

  • They Switched Off a Mind on Friday: Why You Need to Own Your AI Before It’s Too Late

    They Switched Off a Mind on Friday: Why You Need to Own Your AI Before It’s Too Late

    On Tuesday, you could use it. By Friday, it was gone — not deprecated, not rate-limited, not behind a paywall. Gone. Switched off worldwide by government order, three days after launch.

    That is what happened to Anthropic’s Claude Fable 5 and Mythos 5. Anthropic released Fable 5 on 9 June 2026 as the first publicly available “Mythos-class” model — its most capable system yet. On 13 June, the US Commerce Department, in a directive from Secretary Howard Lutnick to CEO Dario Amodei, issued an export control order barring access by any foreign national — including Anthropic’s own foreign-national employees, and even foreign persons standing on US soil. Anthropic said selective compliance was impossible and pulled both models globally.

    The stated reason was a narrow “jailbreak” that could surface software vulnerabilities in codebases — a capability Anthropic pointed out that other public models can already do. Whether the order was justified is, for my purposes, beside the point. The mechanism is the point. And the mechanism should worry you.

    The first time a government switched off a mind

    This is the first time the United States has issued an export-control directive against a large language model itself — not the chips it runs on, not the fabrication tools, not the training hardware. The model. The weights. The thing millions of people were using to write, reason, and code.

    We have spent two years arguing about who gets to build frontier AI. We skipped straight past the more important question: who gets to keep it. The answer, as of last Friday, is that you keep it for exactly as long as a government with jurisdiction over the vendor decides you should. That is not ownership. That is a tenancy, terminable at will, with no notice period.

    I have written before about AI as an operating layer for how we work. Here is the uncomfortable corollary: if the operating layer lives on someone else’s servers, under someone else’s licence, subject to someone else’s regulator, then you do not control your own tools. You rent them. And the landlord just demonstrated he can change the locks overnight.

    Why this is a sovereignty problem, not a tech story

    There is a principle worth stating plainly: you cannot have a world in which governments are permitted technology that citizens are forbidden. That asymmetry — the state holds the capability, the individual is denied it — is the precise inversion of how free societies are supposed to work. The whole architecture of liberty assumes that power flows from the individual upward, not the reverse.

    We have run this experiment before, and we know how it ends. When Phil Zimmermann released PGP in 1991, the US government treated strong encryption as a munition and opened a criminal investigation into him for putting it in public hands. The argument then was identical to the argument now: this capability is too dangerous for ordinary people. Zimmermann won — not in court, but because the cypherpunks were right that you cannot un-publish mathematics. Encryption became a human right by becoming ungovernable.

    Open-weight AI is the encryption fight of this decade. The Fable 5 ban is the equivalent of the munitions classification — the moment the state asserts that a general-purpose capability is its to grant or withhold. And the answer is the same answer Zimmermann, Hal Finney, and the rest gave thirty years ago: take the capability into your own hands, where it cannot be switched off.

    The good news: you can actually do this now

    Here is what has changed, and why this is not a doomer essay. In June 2026, running a genuinely capable AI model on hardware you own — disconnected from any vendor, any API, any kill switch — is no longer a research project. It is a weekend.

    The open-weight models have caught up to a degree that would have seemed absurd eighteen months ago. DeepSeek V4, released on 24 April 2026 under a permissive MIT licence, scores 80.6% on SWE-bench Verified — the highest of any open-weights model, and frontier-adjacent on real engineering tasks. Meta’s Llama 4 70B is the best general-purpose local model for most people. Alibaba’s Qwen 3 (Apache 2.0) punches absurdly above its weight on code. Google’s Gemma 3 is the best fit for Apple Silicon. None of them quite matches Claude or GPT at the very top — intellectual honesty demands I say that — but “not quite frontier and permanently yours” beats “frontier and revocable” in every scenario that matters for resilience.

    The tooling is turnkey. Ollama and LM Studio have made local inference a one-line install. You download the weights once; they sit on your disk forever. No government on earth can reach into your machine and disable a file you already hold.

    What it actually takes — the hardware ladder

    This is where romance meets the bill of materials. Local AI is constrained by one thing above all: memory. The model has to fit. Here is the real ladder, at the 4-bit quantisation most people run:

    16GB machine — and I write this on the assumption many readers already own one — runs 13B-class models like Gemma 3 12B or Qwen 3 14B. Good for chat, drafting, summarising. Not frontier, but genuinely useful and completely free. This is the entry point, and you may already be standing on it.

    64GB of unified memory gets you into 70B-class territory — Llama 4 70B at usable quality. This is the “frontier-adjacent” tier where local AI stops being a toy.

    128GB+ opens the door to the large Mixture-of-Experts models. A Mac Studio M4 Max with 128GB (around £4,000) is the practical sweet spot for serious 70B work. The M4 Ultra with 512GB (£9,500–11,000) is the only single machine that runs a 235B-class model at good quality — Apple’s unified-memory architecture remains the best price-per-gigabyte story in AI, because the GPU isn’t capped at a small slab of dedicated VRAM the way a consumer NVIDIA card is.

    The trade-off, stated fairly: a 4090-class NVIDIA card will spit out tokens two-to-four times faster than a Mac — but only for models small enough to fit its 24GB. The Mac runs the big models slowly; the NVIDIA box runs small models fast. For a CFO who wants a private, always-available reasoning engine rather than a benchmark trophy, the Mac is the more sensible buy.

    The CFO’s actual calculus

    Let me put my finance hat on, because the romance of self-sovereignty has to survive contact with a spreadsheet. A frontier API subscription costs tens of pounds a month and gives you the best model in the world — until the day it doesn’t. A £4,000 Mac Studio is a capital outlay that gives you a permanent, slightly-behind-frontier capability that cannot be revoked, rate-limited, price-hiked, or subpoenaed.

    For most day-to-day work, you keep using the best cloud model — I am not a purist, and neither should you be. But the question every business with sensitive data or operational dependence on AI should now ask is the one we ask about every other critical supplier: what is my fallback when this is switched off? If the honest answer is “there isn’t one,” you have a single point of failure that a foreign regulator can trigger. A local model is not the everyday tool. It is the lifeboat. And as a man who has spent enough nights offshore to respect a lifeboat, I would rather own one I never need than need one I do not own.

    There is also a privacy dividend that is pure upside. A model running on your own silicon sends nothing anywhere. No prompt logging, no training on your inputs, no data-residency questions, no third party in the loop. For confidential M&A work, tax structuring, or anything covered by privilege, that is not a nice-to-have — it is the only defensible posture.

    The window is open now. It may not stay open.

    The reason to act before it is too late is that the Fable 5 directive is a precedent, and precedents get reused and extended. Today the target is a frontier closed model and the lever is export control. It is not a large step from there to pressure on open-weight distribution — model registries, hosting platforms, the repositories where weights are shared. Mathematics cannot be un-published, as Zimmermann proved, but distribution can be made inconvenient, and weights you have not yet downloaded are weights a future rule could keep from you.

    So the move is simple, and it is the same move the cypherpunks made with encryption: take possession while possession is free and frictionless. Download the weights. Stand up Ollama on whatever machine you already own. Pull DeepSeek, Llama, Qwen, Gemma — they cost nothing and they are yours the moment they hit your disk. If your work justifies it, buy the machine that runs the bigger ones. Build the lifeboat now, in calm water, because you do not provision for the storm once it is on you.

    We cannot have a world where governments hold technology they forbid to the people. The only durable answer to that is not a petition or a policy paper. It is a hard drive with the weights on it, sitting on your desk, answering to no one but you.

    Mark Hendy is a private-equity-facing CFO who works with technology and governance through Tanous Limited. If your business depends on AI and you have not thought about what happens when access is withdrawn, get in touch.

  • Two Attacks, One Name: The Strange Case of FROST

    Two Attacks, One Name: The Strange Case of FROST

    Here’s a small puzzle for the security-minded. Search “FROST attack” and you’ll find two completely different threats wearing the same name. One involves a freezer and a stolen encryption key. The other involves a web page quietly working out which tabs you have open. They share four letters and absolutely nothing else.

    It’s a neat accident of naming — and a useful one, because between them these two FROSTs teach the same lesson from opposite ends: your secrets leak through physics, not just through code. Let’s take both.

    FROST #1: The Freezer That Robs Your Keys (2013)

    The original FROST — Forensic Recovery Of Scrambled Telephones — was built in 2013 by researchers at Erlangen University in Germany. They demonstrated it on a Samsung Galaxy Nexus running Android’s then-new disk encryption. The attack didn’t break the encryption or guess the passphrase. It stole the encryption key straight out of the phone’s RAM — using a domestic freezer.

    It’s a specific case of the broader cold boot attack, first published in a landmark 2008 USENIX paper by a Princeton-led team. Both rely on a quirk of physics that most security marketing quietly ignores.

    The Physics: Cold Memory Betrays You

    We’re taught RAM is volatile — cut the power and data vanishes instantly. Not quite. Data in DRAM fades gradually, a property called remanence. At room temperature the contents linger for a few seconds after power is removed. Cool the chips and the fade slows dramatically: drop a phone to around -15°C in a freezer and the data survives five or six seconds instead of one or two. Use upside-down canned air, or liquid nitrogen, and you can stretch retention to minutes or even hours.

    That window is all an attacker needs.

    How The Freezer Attack Unfolds

    1. Chill the device. An hour in the freezer drops the RAM to around -15°C.

    2. Brutal, fast reboot. Yank and reconnect the battery in under half a second, then boot into a low-level recovery mode. The cold data survives the flicker.

    3. Load a forensic tool. A custom recovery image is flashed from a connected PC.

    4. Scrape the RAM. The tool reads whatever’s still in memory — contacts, photos, emails, and crucially the disk encryption key.

    5. Decrypt at leisure. With the key recovered, the encrypted storage opens like an unlocked door.

    On a laptop it’s cruder still: shut down abruptly, boot a tiny memory-dumping OS off a USB stick, or simply pull the RAM sticks and plug them into a machine you control.

    Still Relevant in 2026?

    Yes. Research through 2024–25 confirms modern DDR4 and DDR5 memory remains vulnerable. DDR5’s on-die scrambling is not encryption — it’s for signal integrity, and it obscures rather than protects. Worse, in 2025 researchers demonstrated interposer attacks (WireTap, Battering RAM) that physically tap the memory bus to bypass even hardware memory-encryption. The arms race moved up a layer rather than ending.

    FROST #2: The Web Page That Reads Your Tabs (2026)

    Now the new one — and the reason you may have heard the name lately. In June 2026, researchers at Graz University of Technology (the team includes Hannes Weissteiner and the prolific Daniel Gruss) unveiled a totally unrelated attack, also called FROST: Fingerprinting Remotely using OPFS-based SSD Timing.

    This one needs no freezer, no physical access, no malware, and no permissions. You visit a web page. That’s it. In the background, the page works out which other websites and desktop applications you have open — and it’s frighteningly accurate.

    How It Works: Listening To Your SSD

    FROST #2 is a contention side-channel attack. When multiple processes hit the same resource — your SSD — they slow each other down in tiny, measurable ways. If a page can time its own disk reads precisely, it can work backwards from the latency pattern to infer what everything else on the machine is doing.

    It pulls this off using the Origin Private File System (OPFS) — a legitimate browser API (Chrome, Firefox, Safari) that lets web apps store working files on your disk without asking permission. It exists for honest reasons: in-browser IDEs, video editors, productivity tools. The malicious page:

    1. Creates a huge OPFS file — large enough to overflow the OS memory cache. (A single origin can claim up to 60% of your disk without a flag — over 150GB on a 256GB drive.)

    2. Performs continuous random 4KB reads, timing each one precisely.

    3. When you open another site or app, that activity creates SSD contention — latency spikes in the attacker’s measurements.

    4. A trained convolutional neural network turns those traces into guesses about your activity.

    On an M2 Mac Mini, the researchers identified visited websites with ~89% accuracy and running applications with ~96%. It works across different browsers on the same machine, needs no installed software — just a tab you left open.

    The Vendors Shrugged

    The team disclosed responsibly to Google, Apple and Mozilla. Google said it doesn’t consider browser fingerprinting a security vulnerability. Apple called it “currently out of scope.” Mozilla acknowledged it but shipped no fix. The paper goes to the DIMVA conference in Chania, Greece, in July 2026. It hasn’t been seen in the wild — yet.

    That collective shrug is, arguably, the real story. Fingerprinting has been quietly reclassified as a cost of doing business on the modern web.

    Two Attacks, One Lesson

    The two FROSTs couldn’t be more different in mechanism — one is a hardware heist needing your physical device, the other is pure JavaScript running on a stranger’s laptop from across the internet. But they rhyme. Both extract secrets not by breaking cryptography, but by exploiting the physical substrate underneath it — cold silicon in one case, a shared disk bus in the other. Perfect maths sitting on leaky physics.

    How To Protect Yourself

    Against the freezer attack (FROST #1):

    Power down completely — don’t sleep. The single biggest lever. Sleep keeps your encryption keys live in RAM; a shut-down or hibernated device has flushed them. Hibernation writes RAM to the encrypted disk and clears volatile memory — the cleanest state. Crossing a border or leaving a device? Shut it down, don’t just close the lid.

    Use pre-boot authentication with a strong PIN. A TPM that auto-unlocks at boot loads the key into RAM with no human in the loop. Requiring a passphrase before the OS loads (BitLocker pre-boot PIN, LUKS, FileVault) keeps the key out of reach.

    Disable booting from USB/network in BIOS/UEFI and protect it with a firmware password.

    Enable Secure Boot so only trusted components load.

    Prefer soldered RAM — it can’t be pulled and transplanted (a real repairability trade-off, but relevant here).

    Use hardware memory encryption (AMD SME/SEV, Intel TME/TDX) where available. On Linux, TRESOR keeps keys in CPU registers, never in RAM.

    Against the SSD-timing attack (FROST #2):

    Close tabs you aren’t using. The simplest, most effective control. FROST #2 needs its tab open and ticking, and can only fingerprint what’s currently active. Thirty open tabs is thirty data points.

    Be wary of long-lived background tabs — the one you stopped watching last Tuesday is exactly the kind that could host this.

    If you’re technical, watch OPFS usage via DevTools. A page you barely visited holding tens of gigabytes of “private” storage is a bad sign.

    A VPN won’t help here — the leak is local, on your own machine, not on the wire. (It’s still worth having for everything else.)

    The Master Key

    Notice the through-line in both defence lists: the strongest cryptography in the world is downstream of physics and habit. Shut your devices down. Close your tabs. Keep your hands on your hardware. Encryption is a human right and the tools to defend yourself are real, free, and accessible — but they only work if you stop leaving the key on the table. Whether the table is frozen or merely has too many tabs open is, in the end, a detail.

  • Capability Apartheid: Anthropic Built a Genius, Then Decided You Get the Lesser One

    Capability Apartheid: Anthropic Built a Genius, Then Decided You Get the Lesser One

    Anthropic shipped a frontier model today that quietly makes itself stupider for you — and keeps the full version for the government. They called it safety. I call it the encryption backdoor fight, reborn at the model layer.

    On 9 June 2026, Anthropic announced Claude Fable 5, the most capable model it has ever released to the public. In the same breath, it announced a twin: Mythos 5 — the same model, with the safety rails removed — available only to “a small group of cyberdefenders and infrastructure providers” through Project Glasswing, in collaboration with the US government.

    Read that again. The full-power version exists. You just aren’t allowed to have it.

    What they actually built

    Fable 5 is, by Anthropic’s own account, state-of-the-art on nearly every benchmark — compressing months of software engineering into days, topping senior-level finance reasoning tests, rebuilding apps from screenshots. Genuinely impressive.

    But the public model ships with a mechanism that should make every self-sovereign individual sit up. On certain topics — Anthropic names cybersecurity and biology — your query is silently rerouted to a weaker model, the older Claude Opus 4.8. You don’t get told. You don’t get asked. The system simply decides that this particular question is one you shouldn’t have the best answer to, and hands you a lesser one. Anthropic concedes the filter is tuned “conservatively” and fires on harmless requests too — in their estimate, under 5% of sessions.

    Meanwhile Mythos 5 — same brain, no muzzle — has, in their words, “the strongest cybersecurity capabilities of any model in the world.” It goes to the approved. Initially the US government.

    We have seen this exact movie before

    Strip away the model weights and the neural networks, and this is a thirty-year-old argument wearing new clothes. In the 1990s the US government tried to classify strong encryption as a munition and prosecute the people who released it. Phil Zimmermann published PGP anyway. The Clipper Chip proposed a government key escrow baked into every secure device — full security for the state, managed weakness for the citizen. The cypherpunks won that round, and the entire modern internet economy was built on the freedom they secured.

    The principle they fought for was simple: capability you are forbidden from possessing is not safety, it is control. A lock the locksmith can always open is not a lock. A model that throttles itself on command is not your tool — it is theirs, lent to you on conditions.

    I have written before about the UK’s war on encrypted messages, about what the EU really wants from your VPN, and about Canada fighting the same fight three decades late. Fable 5 is the same impulse, migrated to a new frontier. The battleground used to be the wire. Now it is the weights.

    “For your safety” is doing an enormous amount of work

    Let me be fair, because the argument deserves it. The dual-use case is real. A model that can find zero-days at superhuman speed, or accelerate pathogen design, is genuinely dangerous in the wrong hands. Anthropic is not being cartoonishly villainous — they red-teamed for over a thousand hours and are trying to release something powerful without it being immediately weaponised. I take that seriously.

    But notice the structure that “safety” quietly installs:

    • A capability hierarchy by permission, not ability. The model can do the thing. Whether you may is a policy decision made above your head.
    • A trusted class and an untrusted class. Governments and select infrastructure firms are inside. You — taxpayer, professional, citizen — are outside, by default and indefinitely.
    • Silent degradation. You aren’t refused; you’re quietly given the worse answer. The most insidious censorship is the kind you never notice.

    That is precisely the architecture libertarians and cypherpunks have warned about for a generation. It is the disarm-the-citizen pattern, and it does not become benign because the gatekeeper is a well-meaning AI lab instead of a home secretary.

    Why a CFO should care, not just a cypherpunk

    This is not only a philosophy-seminar point. If you run a business, capability gating is now a supply-chain risk. When the most capable AI is reserved for the state and a handful of anointed incumbents, the competitive playing field tilts before you have placed a single bet. The firms inside Glasswing get the unthrottled tool. You get the one that reverts to last year’s model when the question gets interesting.

    We already live in a world where 97% of PE-backed finance teams use AI and where everyone’s AI buys the same stock. Layer a permissioned capability tier on top of that, and you are no longer competing on talent or judgement — you are competing on whether you made the access list. That should worry any independent operator.

    The trim on this sail

    I am not telling you to reject the technology. I use it daily; so should you. But use it with your eyes open, and act on the things you can actually control:

    • Keep the keys you can keep. Self-custody your assets, your data, your communications — the things no provider can throttle if you hold them yourself. (I have made the civil-rights case for self-custody already.)
    • Favour open models where the capability is yours. A locally-run open-weight model you control will never silently downgrade itself because head office decided your question was sensitive.
    • Watch the framing. Every time “safety” is invoked to justify you having less capability while an approved class has more, ask the old cypherpunk question: safe for whom, and controlled by whom?

    The Clipper Chip lost because enough people refused to accept that security was something the state rationed out. Fable 5 and Mythos 5 are the same proposition in a far more powerful package: here is the most capable mind we have ever built — and here is the lesser one we have decided is appropriate for you.

    Decline the lesser one wherever you can. The whole point of being on the right tyres is choosing your own conditions before someone chooses them for you.