Two trends have persisted for 2–3 years and are now fully reflected in everything from industry and breach reporting to the market for cybersecurity talent and solutions:

  1. Initial access is where the innovation is happening. Social engineering in particular has evolved faster than any vector over a comparable window. Exploitation of edge devices is only innovative insofar as adversaries are evolving their ecosystem at a far faster pace than defenders are changing how they operate (e.g., patching high-risk assets is still thought of as a change management process rather than an incident management decision).
  2. The browser is where the action is happening. Browser security today feels like endpoint security (EDR/EPP) did during its ascendancy: open-source tooling, enterprise controls, and raw visibility all exist. Few teams can operationalize low-level signals for custom detection engineering, but a few startups are converging on great solutions.

August 18, 2026

Frontier AI models and regulatory capture

Regulatory capture of frontier AI models would be an absolute gift to the ecosystem of companies blessed to use them. Here’s a directly related prediction from Steve Yegge on June 18, 2026:

The AI race isn’t going to slow down, and AI will continue to grow exponentially in capability. Unfortunately, most of you aren’t going to see it progress anymore.

I am now in the camp who believe that we are only at most two or three model generations away from AI finally being controlled like nuclear weapons. Only a few will have access to superintelligence above the classes of models we’re seeing this year. As far as I can tell, most Fortune 500 companies will either not have access at all, or it will be tightly controlled for only a small subset of the company. And it will be supervised.

I think those with access to powerful frontier models will sell intelligence like a vending machine: You send them a software spec or a problem to solve, and their models implement it for you, on their servers, with your dollars.

The AI labs are opposed to this today. To wit, here is OpenAI’s GPT-5.6 announcement on June 26, 2026:

We believe in broad access, and we plan to make GPT‑5.6 Sol, Terra, and Luna generally available in the coming weeks. As part of our ongoing engagement with the U.S. government, we previewed our plans and the models’ capabilities ahead of today’s launch. At their request, we are starting with a limited preview for a small group of trusted partners whose participation has been shared with the government, before releasing more broadly. During this preview, we will continue testing and coordinating closely with partners as we work toward broader availability. We don’t believe this kind of government access process should become the long-term default. It keeps the best tools from users, developers, enterprises, cyber defenders, and global partners who need them. We are taking this short-term step because we believe it is the strongest path to broader availability in the coming weeks, while we work with the Administration to develop the cyber Executive Order framework and a repeatable process for future model releases.

It’s interesting to game out how they might reconsider, should the frontier labs find themselves in a situation where broad B2B adoption is no longer viable (or, is simply harder than leaning into an intelligence cartel).

  1. Exploits don’t cause cyberattacks: On thinking clearly about frontier AI advances and cyber conflict - “[M]ost of today’s attacker constituencies can currently achieve most of their desired outcomes using traditional means: simple phishing, credential stuffing, exploitation of known CVEs, etc. These constituencies aren’t likely to explode into hockey-stick adoption of AI vulnerability research tools. ❡ This should discipline our thinking about Mythos generating a discontinuous volume of cyberattacks, because, again, most attacker constituencies just aren’t blocked by vulnerability research for most of their workflows.”

  2. Finding Zero-Days with Any Model: Vulnerability discovery is an orchestration problem, not a frontier-model problem. - “[W]ell-resourced adversaries already use orchestrated workflows to hunt for zero-days at scale. They operate free from vendor usage policies, AUP friction during legitimate research, API rate limits on multi-hour runs, and curated access lists for embargoed frontier models. The seven-step refusal during severity assessment is exactly the asymmetry at issue: a defender doing legitimate work hit friction that a well-resourced adversary using uncensored open-weight models would not.”

May 19, 2026

Every AI Subscription Is a Ticking Time Bomb for Enterprise Permalink

For several years now, the pendulum has continued its swing towards “more AI, at any cost”, and it now feels like it has reached its apex.

OpenAI, Anthropic, Google, and the rest are running an industry-wide loss-leader program at a scale that has no precedent. They are selling enterprises filet mignon at gas station hot dog prices and calling it a business model. The gap between what your company pays for AI subscriptions and what it actually costs to serve those seats is not a rounding error. It is a gulf. And every organization that has built workflows, products, or entire business units on top of these subsidized prices is standing right on the edge of it. ❡ This should be front of mind for every CTO, CFO, and head of operations reading this. Because when the pricing corrects, and it will, the companies that treated AI as a permanently cheap utility are going to wake up to bills that make their current SaaS spend look quaint.

Security Operations Center (SOC) outcomes in the age of AI

For all the hype around AI and agentic Security Operations Center (SOC) solutions, what truly matters comes down to two questions:

  • What threats can you detect today that you couldn’t before?
  • What existing threats can you now detect consistently and provably faster?

There’s no shortage of benefits to leveraging AI across a cybersecurity program, and it’s easy to get lost in everything AI can do. But job number one for any SOC is detecting and responding to cybersecurity threats, and it doesn’t matter much how this is achieved (i.e., I don’t care if it’s humans or robots), so long as it’s effective.

Whether you’re a SOC manager, analyst, or buyer evaluating AI or agentic SOC solutions, working backwards from what your SOC is already supposed to deliver cuts through virtually all of the AI-related hype and noise.