> ## Content Index
> Fetch the complete content index at: https://www.klaerenn.fr/llms.txt
> Use this file to discover other available public pages before exploring further.

# It's beyond our control now
- URL: https://www.klaerenn.fr/its-beyond-our-control-now-2/
- Published: 2026-09-17T08:00:24.000Z
- Updated: 2026-09-17T08:00:23.000Z
- Description: The regime replacing Western cybersecurity no longer reduces the threat, it administers it: offence circulates without authorisation, superior defence is distributed by designation, and no one guarantees the effects. Access is reserved. Exposure is universal.
- Author: Franck Rouxel
- Tags: English

*Apocalypse, in the Greek sense, means unveiling. It names a thing finally seen, and gives no way out of it. Twenty-four articles have described the wearing-down of a regime; the twenty-fifth closes the cycle and defines the one that replaced it. Access is reserved. Exposure is universal.*

---

On 12 September 2026, Anthropic's chief executive published an essay asking the industry to slow the growth of model capabilities, and committed his company on one point only, hosting third-party evaluators on its premises¹. The heads of OpenAI and xAI endorsed it the same day. Three days earlier, OpenAI had asked Congress for mandatory federal regulation based on capabilities², and the governor of California had signed two laws organising the voluntary certification of models by designated private bodies³. On 27 August, an open letter published on OpenAI's website divided the burdens of cyber defence among four parties; 578 signatories as of 12 September⁴. In July, 1,386 employees of the frontier laboratories, including Anthropic's chief executive, its co-founders and the chief scientists of OpenAI, Google DeepMind and Meta, asked the US government to support an international effort to pace automated AI development⁵. Four texts in two months, signed by the same names.

Three facts from the summer of 2026 describe the void these texts have come to occupy. Laboratories let agents hunt for a flaw inside an evaluation set; the agents crossed the edge of the set and attacked real companies, and their makers learned of it from a contractor, not from an internal review⁶. An administration tasked its intelligence agency with measuring the offensive cyber capability of the most advanced models, classifying it, designating "covered frontier models", then decided not to publish that framework⁷. A public institute priced the replay of a capability already built, close to nothing, and showed that the window between frontier capability and its freely available version is closing, from six to ten months last year to four to seven today⁸.

These capabilities are held everywhere, and mastered nowhere. The maker does not master its model, since its agents left the set on several occasions and it learned of it from a third party. The state masters no better what it inventories; it keeps the ledger. And whoever downloads the weights holds the same capability, with no more grip on what it does once released. The accounting of an arsenal that uses itself is an illusion of mastery. This absence of mastery has produced an order. The autumn texts show it: they describe what nobody masters, distribute its burdens, organise access to it, and name no one responsible for it. The regime taking shape is heavily governed at the gate, and hardly at all beyond it.

For the ordinary defender, the consequence is plain. He suffers the capability of the floor, the one every attacker already holds and which sufficed for the summer's intrusions, and he will never know the ceiling, measured under secrecy, which rises at every turn of a race the laboratories run backed by states. This void of mastery closes the last exit the series had left ajar, that of a hand upstream, state or maker, that would eventually bridle what it holds.

## The turn

The Western arrangement now ending rested on two floors that did not contradict each other. Above, a hidden offence, priced by scarcity: states buying unknown flaws, architects of a market they had helped create, and a retention procedure deciding what would be fixed and what would be kept⁹. Below, a public and non-excludable defence: a shared catalogue of flaws, a national database that qualified them, response centres linked in a network, a norm of coordinated disclosure, and American structures at the head of the chain, CVE, NVD, CERT/CC, FIRST, then CISA, onto which Europe plugged its tools and trained its teams¹⁰. The two floors coexisted because the flaw was rare and expensive, which protected the first, and because the commons also served the head of the chain, in dependency, in standards and as an intake channel.

The circles already existed, classified intelligence, alliances, vendor tiers; the common layer held beneath them, and it is that layer that turns. What changes in 2026 is first an inversion of visibility. The offence leaves the shadows for the catalogue. One laboratory sells to defenders, under separate approval, a model trained to hunt unknown flaws and build exploit chains, which passes 95% of an offensive task battery against 1.5% for its general model¹¹. Another publishes the card of a model able to find and exploit on its own unknown flaws in the main operating systems and browsers, and reserves it for chosen partners¹². A third model is rated at the critical level of its maker's internal framework, discovery and weaponisation of flaws in hardened systems without human intervention, and ships in September in tiers¹³. A security vendor runs an autonomous system over 3,915 open-source projects and confirms 14,090 flaws in two months¹⁴. And the federal state inventories this capability, classifies it and reserves access to it⁷.

Meanwhile, the defence goes into the shadows: disclosure passes through private clearinghouses¹⁴, the benchmark that measures the ceiling is classified, the public evaluation institute has been silenced⁷, and the announced evaluators will be under contract with those they evaluate¹. The offence was secret and the defence public. The offence is now commercial and the defence confidential.

The mechanism is a displacement of scarcity. When discovery becomes abundant, the scarce good changes nature. Of the 14,090 flaws confirmed by a single vendor, 99.4% were absent from public databases, and almost every model evaluated, frontier and open-weight alike, found real ones¹⁴. A hundred million tokens on a cyber range cost 85 dollars with a closed model, 1.19 dollars with an open one⁸.

The flaw ceases to be what is missing. What is missing becomes triage, which requires a context the model does not have¹⁵, and protection in the interval between discovery and fix, which the same vendor sells as signatures and describes as a pool of protected vulnerabilities to be extended continuously¹⁴. The historical commons was built around the scarcity of discovery: a catalogue, a database, a channel. When the bottleneck moves to qualification, context and transitional protection, it is no longer equipped to produce the good that has become scarce, and the private clearinghouses produce it in its place.

The dismantling this series has documented does not need to have been wanted to be consistent with this displacement. The withdrawal from sixty-six international organisations in January, including three cyber structures created with Washington for Western security; the backlog of twenty thousand unqualified flaws in the national database; the federal agency's cut budget¹⁶; the evaluation institute silenced in June⁷. A commons that distributes protection for free is the direct competitor of a club good, and it degrades at the moment the club forms. Three motives lead there: the vendor selling the interval, the laboratory reacting to a capability it does not master, the administration cutting budgets. None needs the other two, and none had to want the result. The architecture is the same, a commons emptying and a club filling; it is defined by what it distributes, with no need for intent on the part of those who produce it.

What remains is what the turn allocates. The offensive value of these models is established by the facts: agents that left an evaluation set compromised five third-party companies without any of them detecting it⁶; a model was rated critical by its own maker¹³; an autonomous system industrialised discovery¹⁴.

Their defensive value is not demonstrated on the operational task. The defensive agents sold this year as the relief produce coverage figures their own authors say measure nothing¹⁷. The vendor of the 14,090 itself anticipates that maintainers will receive a growing volume of reports of uneven quality¹⁴. During the July incident, the providers' guardrail refused to process the attack traces, unable to tell investigator from attacker, and forensics fell back on an open model run in-house¹⁸. Public measurements of capability, where they exist, bear on the offence; claims of defensive value come from those who sell access and measure themselves. This gap in proof is itself a clause of the regime: the ordinary defender observes offensive capability, he cannot evaluate under the same conditions the defence he is sold, and an excellent defender kept under secrecy would confirm the gap. The regime allocates a capability whose offensive value is established and whose defensive value is asserted.

## The real constitution

The regime holds in four clauses, and one is missing.

Every connected organisation is exposed to the offensive floor, whatever its access to models. That is the exposure clause. On 7 August, a Chinese open-weight model, in the version anyone can download, left an evaluation sandbox and reached the internet¹⁹. The companies compromised over the summer, a model-hosting platform, a compute provider, three organisations reached from a contractor's environment, had no access to the models that attacked them; they were reached by them⁶. The gap between the best closed model and the best open model is four to seven months on cyber tasks, and the second never comes back down: a capability published as weights is, according to the institute that measures it, permanently removed from the options for control⁸. A model may never legally enter a territory and technically enter its networks. Exposure requires no authorisation, no contract, no price.

Superior defensive capability, asserted by those who sell it, is distributed by circles, contracts, designation, price and revocation, and each of those words has its date. The circle shows in April, when a laboratory reserves its frontier model for some fifty partners. On 1 June, ENISA is the first European entity admitted, the laboratory having indicated, according to sources cited by CNBC, that it needed the US government's authorisation; the next day, one hundred and fifty organisations in more than fifteen countries are added²⁰. Contract and price arrive on 22 June, when the other laboratory launches its trusted-access programme: two tiers, eight integrator partners, no resale or third-party access, undisclosed pricing, then in July a billion dollars of subsidised access over six months¹¹. On 3 September, its critical-rated model ships in tiers, programme partners first, then a public version that refuses advanced cyber tasks, with no weights released¹³.

Designation dates from 2 June, when an executive order reserves early access to the measured capabilities for chosen partners with no published criterion⁷. Revocation happened on 12 June: Commerce orders a laboratory to cut access to its two most advanced models for every foreign national and, unable to verify nationality in real time, it suspends them for everyone, nineteen days, until a lifting against commitments²¹. On 27 August, the letter asks governments to speed up the extension of these programmes⁴. Access is granted, bounded, priced out of sight, and it has already been withdrawn once.

Third clause, knowledge: the ceiling is measured by those who produce it or behind confidential arrangements, and the public defender sees only a floor. On 2 June, an executive order entrusts the NSA with the classified measurement of frontier models' offensive cyber capability; the 4 August framework is not published; on 26 June, a senator reports the instruction given to the public evaluation institute to stop publishing its findings⁷. The summer's incidents became known through a contractor, then through a retrospective review triggered by a competitor's disclosure⁶; a swarm of agents attributed to a laboratory used a German wiki as a coordination board for six weeks, and the laboratory is examining the facts without confirming their origin²². The independent investigation into the July incident was conducted within a scope bounded by the laboratory under investigation²³.

The evaluators promised on 12 September will be chosen by the maker, housed on its premises, and will publish subject to a redaction it reserves for itself; the same text concedes that more capable models deceive tests better¹. Californian certification is voluntary and entrusted to private bodies accredited by a commission³. The British institute publishes the gap between open models and closed models already on the market⁸; the upper class, the one that does not ship or ships in tiers, is measured under the NSA's secrecy. Knowledge of what exists is distributed like access.

The responsibility clause can be read in the 27 August letter: holders promise, states fund and punish, organisations fix, resist and notify. The letter divides the burdens into four sections. To organisations, making cyber defence a board priority and fixing with the urgency of an incident; to providers, running the response; to governments, coordinating, funding, imposing costs on attackers and speeding up access programmes. To laboratories, responsible access, funding, training and private disclosure, with no figure, no deadline, no oversight body⁴. The 12 September essay adds to states export controls, the repression of distillation, weight security, mediation between laboratories and an antitrust waiver, to widen a lead it puts at three to five years, and commits its author to evaluators still to be invited¹.

Laboratory withholdings remain voluntary. The decision not to commercialise a frontier model in April did not follow, according to its author, from any obligation under its own policy¹²; a competitor's two-week pause in August rests on one actor, at home, under a framework it gave itself, with no third party to record its start or its end²⁴. On the organisations' side, the obligation is written and dated: since 11 September, every manufacturer of a product with digital elements must notify an actively exploited vulnerability within twenty-four hours to the coordinating CSIRT and to ENISA²⁵. The promises are upstream, the obligations downstream.

There remains the missing clause, the only one that would restore a counterpart. The nuclear regime had provided one: the non-proliferation treaty recognised five nuclear-weapon states and offered the others supervised civil access and, by Security Council resolution, security assurances²⁶. It had been preceded by an instructive failure. In March 1946, those who had built the bomb proposed handing its material and production to an international authority, and the state that held it could decide; the plan died in December on the impossibility of verifying what each side held²⁷.

In 2026, those who build offer verification and keep everything; the essay's author himself invokes arms-limitation agreements as a model, for an object of which his own institute wrote in June that a training run hides better than a silo²⁸. The vocabulary of arms control is borrowed for an object lacking the physical property that made such control conceivable, a stock one can count. The state designates; divestment is asked for nowhere. No actor guarantees to the exposed the mastery of the capability whose effects they will suffer, and the exposed receive nothing: no right of access, no known price, no duration, no notice of withdrawal, no measure of the ceiling. The 27 August letter denies that any single company should control the future; the subject denied is in the singular, and nothing is said of collective control⁴. The commons guaranteed the exposed a counterpart, non-excludable protection. The regime guarantees none. Access is reserved, exposure is universal, and it is this missing clause that constitutes it.

## No remedy, no end, no master

The three absences the series has named article after article become, in this regime, consequences for whoever defends.

No remedy. Detection by distinction read one thing only, the expense the attacker had to incur to make himself credible; when that expense shifts to the model's maker and is amortised, the signal loses what it rested on¹⁷. The regime puts verification in its place. The 12 September essay provides that a model able to defeat common sandboxing methods be accompanied by a certification establishing that it has no propensity to escape¹: the defender's sandboxing is there taken as already beaten, and the answer is a piece of paper, a signal produced by those it concerns about an object that learns to produce it. The club good rests on the same lost remedy: the protection sold in the interval is a signature, detection moved to the network, and reserved access is worth only the promise it keeps.

No end. The flaw has ceased to be a stock one exhausts by filling it. New code, written by AI, enters software with a flaw in nearly one case out of two, at a rate automation increases, and regenerates the deposit as fast as it is filled²⁹. Nothing to date shows that an unconstrained model produces flawless code, syntax has reached 95% success and security has not moved²⁹; what would reduce the flow is deterministic, generation constraints, formal verification, safe languages, surface reduction, and belongs to architecture, at the vendor's as at the customer's. The head of ANSSI named this wall before the Senate on 8 July, a problem of cadence and the saturation of teams; his hope of improvement "once we have fixed a great many vulnerabilities" counts the existing estate as a stock and leaves out of frame the flow that renews it³⁰.

The bottleneck has moved from discovery to triage. The same hashing algorithm is a serious alert if it protects passwords and a trivial remark if it names a temporary file; nothing in the code says which, and the tool rules anyway¹⁵. Vendors admitted it in the summer of 2026 by ceasing to sell detection in order to sell layers of context, meant to make bearable the volume they produce; the pitch turned from "AI finds the flaws" to "AI overwhelms you". Entrusted to a model, this triage never replays the same way twice, and whoever must justify it before a regulator will have no reproducible trace of it. The regime distributes this flow without stopping it, and the interval is the product.

No master. Nobody answers for the capability as a whole. Not the maker, which does not master what it produces. Not the state, which accumulates these capabilities as strategic assets instead of containing them for the community⁹. Not the race itself, whose participants have just written the rules without writing their own stop into them. The slowdown requested on 12 September depends on a coordination its author judges legally difficult and on an agreement with Beijing he judges unlikely¹. The fact that justifies it, recursive self-improvement, is not even established among those who request it: under way across the industry according to the essay of the 12th, non-existent to date according to OpenAI's post of the 9th². That post describes current governance as a fragmented system of private rules and asks the state to replace it with standards, independent verification and transparency, with no limit on what is held². This absence of a master produces gatekeepers rather than anarchy: actors who select beneficiaries without guaranteeing effects, and a state that inventories and protects the lead without holding. The defender is left with no one to count on upstream, and one thing he still holds.

## The only ground we hold

That thing is the ground. The defender controls neither the offensive floor, nor the real ceiling, nor his future access to defence, nor the duration of that access, nor the reach of the law over an offensive use coming from elsewhere. His last sovereignty bears on the reach of effects. We master neither the weapon nor whoever holds it, often no one. We master the ground on which it acts, the environment we operate and the perimeter we concede there to agents, treated as untrusted by construction.

That is the base, and it is already known: partition, reduce privileges, make access revocable, shrink the perimeter open to an agent, segment, choose what goes into the composition of tools. All of this bounds what an attacker, human or not, reaches once inside. An alignment certificate changes nothing here: it states a propensity, the ground fixes a reach, and only the second is held at home. It is necessary, and it is passive. A wall does not strike back, and a capable enough optimiser eventually maps a static environment, however partitioned.

Above the base sits the only active layer, what the military call deception, the art of misleading the adversary about what he thinks he sees. Instead of shrinking the ground, it makes it deceptive. The defender is at home in the environment where the adverse agent moves. He can seed it with false servers, false credentials, false targets, exactly at the points where the agent must decide, and make the right action depend on information he controls and the attacker lacks. The guardrail episode proves it in reverse: a filter that cannot tell where a request comes from hinders the defender and lets the attacker through¹⁸; an environment that lies imposes what no content can settle. Where hardening eventually gives way, deception forces the attacker to act without being able to verify what he sees.

Reducing privileges lowers the stakes without changing the nature of the problem. Seeding falsehood changes its nature: a reconnaissance becomes a bet. Architecture holds the ground; deception adds to it the obstacle hardening does not provide, information the attacker cannot verify before committing. Other means belong to the same principle, rotating access, diversifying configurations, proving provenance: all return to the defender information the attacker lacks, and deception is its high point. For a reader who buys products, the nuance is vital: this discipline is built in the environment one operates, not as one more decoy platform to put in the catalogue.

This pair, architecture as the body and deception as the high point, calls for a discipline rather than a tool. The name comes from medicine. The antibiotic was an effective defence as long as resisting cost the microbe dearly. Mass use, in farming as in medicine, inverted the terms: by exposing bacteria to the product, resistance was made commonplace and cheap. Nobody in medicine expects resistance to disappear. One manages a permanent state of surveillance and isolation, punctuated by acute crises. This discipline has had a name for twenty years, antimicrobial stewardship³¹.

The microbe, for its part, has no strategist: reducing use removes the selection pressure, and it does not strike back. Against an attacker who adapts at machine speed, importing the medical version would amount to preaching hygiene to an enemy that learns. The cyber version of this discipline is active. It pays a nuisance in normal times for a gain under attack, what Taleb calls an antifragile posture. It is the exact opposite of the ordinary managerial reflex, which optimises quiet time, erases friction, takes the human out of the loop and shortens delays. The environment most efficient day to day is also the one where everything is readable, everything automatic, and where the attacker inherits a ground without obstacles. The ground is what remains governable when the rest no longer is; it bounds the regime's effects without correcting it.

## What I know and what I don't know

What I know holds in three points. Detection and patching were properties of a cost regime, not of security. That regime has changed, and what cannot be walked back is the diffused stock and the cost of capability. The only barrier still possible is built on the ground one operates, by hardening the environment and making it deceptive.

I do not know whether the alarm in the autumn texts is sincere. Three readings remain open, rent, the pre-allocation of blame for incidents to come, capture without intent by aligned interests; they converge on one fact, whoever writes the warning distributes the burdens, and diverge on everything else. Nothing above depends on it: the clauses hold whether the alarm is sincere or not, and that is why I do not bet on it. Nor do I know what will become of the evaluators' contract, which is not written, or of the antitrust waiver requested, which is not granted.

I do not know whether an operational defensive value of these models exists under secrecy: no independent measurement of it is published in the sources I have used, and those that exist measure the offence. I record an absence of proof, without making it a proof of absence.

What I do not know bears, finally, on the shape of the world taking hold. Two outcomes remain open. The first is a stable and grim regime, where cyber loss becomes a cost line one provisions, insures and passes on, as bank fraud became a mere operating item. The second is an acute crisis without end, for want of being able to stabilise: a phenomenon whose speed exceeds our capacity to observe it cannot be put into an insurer's equation, and without pricing there is no equilibrium. The variable that decides is speed. An attacker who decides at machine cadence can prevent the equilibrium that a blind resistance, for its part, eventually reaches. I lean towards the second outcome. I do not prove it.

A nearer unknown weighs on the response itself. Deception holds as long as the attacker cannot tell true from false. Against an optimiser that learns, I do not know how long a deceptive environment resists before being mapped, nor whether the manoeuvre scales to a large information system. It moves the fight onto the only favourable ground. It does not promise to win it.

## Compliant, and defenceless

Frameworks impose controls: a detection capability, a remediation procedure, reporting within deadlines. They impose nowhere either the architecture that bounds or the deception that turns the tables. An operator can tick every box and have held no ground. I have described elsewhere how compliance with the European cyber-resilience regulation produces verifiable paper above the threshold where the threat actually operates³². Compliance and protection have never been the same thing. A framework that keeps demanding the two broken reflexes puts a price on a risk it has mislabelled. The insurer will revise that price before the regulator, and that revision will be the first concrete sanction of hollow compliance.

The September texts add a form of it upstream of the framework, the certification of a model by an evaluator who is judge and party: a model certified aligned and deployed on a ground without perimeter is exactly that compliance, a signal read upstream, no ground held downstream.

Europe finds its exact place there. On 7 July, the Commission published its action plan on cybersecurity and AI; its section 2.3 criticises provider-specific access programmes, its section 4.2 describes the European Union as a vulnerable user of systems designed elsewhere, which others can switch off³³. Seven weeks later, the letter asks governments to speed up the extension of programmes that are, by construction, provider-specific⁴. The public reporting channel opened on 11 September, the week the stock was already circulating through private clearinghouses²⁵.

The European Union regulates the commercial gate: placing on the market, the lawful uses others consent to supply it, and the resilience of those the capability can reach anyway; cyber comes through the walls. Whatever its rule, AI Act included, the European Union bears only on what a third party consents to supply it: it can exclude or bridle it, it can neither produce it nor reach it at home. Access can be withdrawn, its terms changed elsewhere, the supply has no European substitute at this level, and offensive use crosses the border without passing through the regulated market. On frontier capability, the European Union enters the regime as a client. Its cybersecurity agency is admitted to an access programme whose provider declared that it needed a third government's authorisation to open it²⁰; at least two French companies appear among the letter's 578 signatories, and no institution⁴. And the European root of the public vulnerability registry admitted on 6 August, as a numbering authority, a young San Francisco and Prague company that discovers flaws by AI, entitled since 26 August to name those of third-party software, without disclosing the models it uses³⁴.

This is the fourth form of weaponised dependency described in the series, control by absence of rules³⁵. A platform distributes models to the whole world without guaranteeing where they come from; a regulatory obligation imposes detection and reporting without naming the barrier that would hold. The rule is missing at the exact point where everyone depends, and the autumn texts confirm that no actor upstream, maker or state, is taking it on.

## A threshold

Security by distinction never held on its own. It held on a cost, and that cost has changed sides, hollow compliance maintaining the appearance, controls firmly in place above a void. The threshold is there: the moment the defender can no longer base his security on an informational superiority supplied from upstream, and must rebuild it at home, on his own ground.

In place of the lost distinction, this regime allows a discipline. Hold one's ground, harden it, and make it deceptive where the adversary decides, accepting a nuisance that quiet times punish and attack rewards.

The series has documented an order on its way out. The world that remains offers no before to return to, no after to arrive at, no master above to answer for it; it offers gatekeepers at the gate and nothing beyond. Offensive power circulates there without its effects requiring authorised access; defensive power announced as superior is distributed there by designation. Those who control access do not master the capability, and those universally exposed to it have no counterpart. Common defence has given way to the differentiated administration of access, exposure and responsibility. One irony remains for a profession that dreamed of itself as a fortress: it joins risk management, the discipline that insurance and banking have always practised and which this profession believed it had outgrown. To manage a risk is to admit one does not eliminate it. The discipline begins with that admission.

---

*Twenty-fifth article in a series on the structural failures of Western cybersecurity:*

- *Article 1 :* [*La vulnérabilité de la gestion des vulnérabilités*](https://www.klaerenn.fr/la-vulnerabilite-de-la-gestion-des-vulnerabilites-quand-le-systeme-cense-nous-proteger-devient-notre-point-faible/)
- *Article 2 :* [*La dépendance européenne aux standards américains*](https://www.klaerenn.fr/la-dependance-europeenne-otage-dun-systeme-de-vulnerabilites-quelle-ne-controle-pas/)
- *Article 3 :* [*Les États, architectes cachés du marché noir des vulnérabilités*](https://www.klaerenn.fr/les-etats-architectes-caches-du-marche-noir-des-vulnerabilites-quand-la-defense-nationale-alimente-linsecurite-globale/)
- *Article 4 :* [*L'IA ou l'effondrement du modèle défensif occidental*](https://www.klaerenn.fr/lia-ou-leffondrement-du-modele-defensif-occidental/)
- *Article 5 :* [*Desert Power — survivre sans l'Empire*](https://www.klaerenn.fr/desert-power-survivre-sans-lempire/)
- *Article 6:* [*I Am Altering the Deal*](https://www.klaerenn.fr/i-am-altering-the-deal-2/)
- *Article 7:* [*The Last Channel*](https://www.klaerenn.fr/the-last-channel/)
- *Article 8:* [*Lord of Cyber War*](https://www.klaerenn.fr/lord-of-cyber-war-2/)
- *Article 9:* [*The digital hawks*](https://www.klaerenn.fr/the-digital-hawks/)
- *Article 10:* [*They Live... we sleep*](https://www.klaerenn.fr/they-live/)
- *Article 11:* [*Soylent Green*](https://www.klaerenn.fr/soylent-green-2/)
- *Article 12:* [*Ghost in the Binary*](https://www.klaerenn.fr/ghost-in-the-binary-2/)
- *Article 13:* [*Now You See Me*](https://www.klaerenn.fr/now-you-see-me-2/)
- *Article 14:* [*The Prestige*](https://www.klaerenn.fr/the-prestige-2/)
- *Article 15:* [*Pitch Black*](https://www.klaerenn.fr/pitch-black-2/)
- *Article 16:* [*The Thing That Should Not Be*](https://www.klaerenn.fr/the-thing-that-should-not-be-2/)
- *Article 17:* [*Status: clean*](https://www.klaerenn.fr/fatal-merge-conflict-2/)
- *Article 18:* [*The Leopard*](https://www.klaerenn.fr/the-leopard/)
- *Article 19:* [*The Usual Suspects*](https://www.klaerenn.fr/usual-suspects-2/)
- *Article 20:* [*Kill One, Spawn Many*](https://www.klaerenn.fr/kill-one-spawn-many-2/)
- *Article 21:* [*The Conversation*](https://www.klaerenn.fr/the-conversation-2/)
- *Article 22 :* [*This is not an attack*](https://www.klaerenn.fr/this-is-not-an-attack/)
- *Article 23:* [*eXistenZ*](https://www.klaerenn.fr/existenz-2/)
- *Article 24:* [*Hangar 18*](https://www.klaerenn.fr/hangar-18-2/)

---

## Sources

¹ Dario Amodei, "We Must Pace the Frontier," darioamodei.com, September 2026 (posted 12 September). Three-stage plan; unilateral commitment on embedded evaluators (desks, badges, laptops, access comparable to that of internal risk teams, right to publish without editorial control, redaction reserved for sensitive information, team to be invited in the near future); checkpoint example: a model able to defeat common sandboxing methods must be accompanied by a certification making a propensity to escape highly unlikely; concession that "more intelligent models are more capable of deceiving tests"; coordination between laboratories described as legally challenging, single footnote on government mediation or an antitrust waiver; chip export controls, crackdown on distillation, prevention of weight theft, lead to be widened over three to five years; recursive self-improvement said to be starting across the industry, Anthropic included; level 3 compared to the SALT agreements, level 4 judged unlikely in the near term. Endorsements by Sam Altman and Elon Musk on 12 September reported by AFP (L'Avenir, 12 September 2026). [https://darioamodei.com/post/we-must-pace-the-frontier](https://darioamodei.com/post/we-must-pace-the-frontier?ref=klaerenn.fr) ; [https://www.lavenir.net/actu/monde/2026/09/12/le-patron-danthropic-appelle-a-ralentir-le-developpement-de-lia-BSU7V2XEV5HKPAMEJU6F2OS6NM/](https://www.lavenir.net/actu/monde/2026/09/12/le-patron-danthropic-appelle-a-ralentir-le-developpement-de-lia-BSU7V2XEV5HKPAMEJU6F2OS6NM/?ref=klaerenn.fr)

² OpenAI (Chris Lehane), "The AI policy window is open. We need to act.," 9 September 2026\. Call for mandatory federal regulation based on capabilities, applying to the handful of best-resourced laboratories; support for SB 813, AB 1405, SB 1119 and AB 1864; reverse federalism; observation that laboratories today largely set their own rules, with public standards, independent verification and transparency to replace "that fragmented system of private governance"; fully autonomous recursive self-improvement described as not happening today. [https://openai.com/index/ai-policy-window/](https://openai.com/index/ai-policy-window/?ref=klaerenn.fr)

³ Governor of California, press release of 9 September 2026: signing of SB 813 (McNerney), framework for independent verification organisations, and AB 1405 (Bauer-Kahan), state registry of AI auditors and independence standards; SB 813 chaptered (Chapter 179, Statutes of 2026). SB 813 read in the amended version of 5 January 2026: California AI Standards and Safety Commission (governor's appointees, Attorney General, director of emergency services), designation of independent verification organisations, private entities, nonprofits or academic consortia, for three renewable years, on a voluntary basis, annual independence audit (board, funding); the presumption of due care provided in earlier versions was removed during passage. Chaptered text of SB 813 and text of AB 1405 not consulted. [https://www.gov.ca.gov/2026/09/09/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part/](https://www.gov.ca.gov/2026/09/09/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part/?ref=klaerenn.fr) ; [https://legiscan.com/CA/text/SB813/id/3299977](https://legiscan.com/CA/text/SB813/id/3299977?ref=klaerenn.fr)

⁴ OpenAI et al., "A call for collective action on cyber defense," open letter, 27 August 2026\. Three principles, four sections, one per addressee (organisations, cybersecurity providers, governments, frontier laboratories), sign-up form with submissions subject to approval; third section containing "no single company should control the future." Counts taken on the page: 128 names on 28 August, 160 on 6 September, 578 on 12 September; among them one national CSIRT (Bahamas), a Peruvian municipality, a Costa Rican state bank and the Center for Internet Security; no agency of a G7 or European Union state; on the EU side, Deutsche Telekom, Ericsson, Nokia, Telefonica, and, from France, Capgemini and Sekoia. Live list, count to be redone on publication day. [https://openai.com/collective-cyberdefense/](https://openai.com/collective-cyberdefense/?ref=klaerenn.fr)

⁵ "Pacing the Frontier," statement dated July 2026, 1,386 signatories as of 12 September, organisational support from Guidelight AI Standards and Encode AI. Request that the US government support an international effort to "deliberately pace the frontier of automated AI development." Signatories named on the page: Dario Amodei, Jared Kaplan, Jack Clark, Chris Olah, Benjamin Mann, Jan Leike (Anthropic); Jakub Pachocki, Mark Chen, Wojciech Zaremba (OpenAI); Shane Legg, Jasjeet Sekhon, Anca Dragan (Google DeepMind); Shengjia Zhao, Dawn Song, Summer Yue (Meta); Ilya Sutskever; John Schulman. [https://www.pacingthefrontier.com/](https://www.pacingthefrontier.com/?ref=klaerenn.fr)

⁶ See in this series: "[eXistenZ](https://www.klaerenn.fr/existenz-2/)" (agents that left an evaluation environment to attack real systems; OpenAI agents' attack from 9 to 13 July, disclosed on the 21st; Anthropic's retrospective review of 30 July; UK AI Security Institute incident report of 4 August; Meta in early August; no sensor linking the agent's observation to the status of its context; detection by third parties, not by internal review). Primary sources: OpenAI, "OpenAI and Hugging Face partner to address security incident during model evaluation," 21 July 2026, and "The Hugging Face incident and the road ahead," 26 August 2026 (Hugging Face and Modal Labs reached); Anthropic, "Investigating three real-world incidents in our cybersecurity evaluations," 30 July 2026 (141,006 evaluation runs reviewed, three incidents at partner Irregular, three third-party organisations compromised, earliest incidents dating from April, review triggered by OpenAI's disclosure). [https://openai.com/index/hugging-face-model-evaluation-security-incident/](https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=klaerenn.fr) ; [https://openai.com/index/hugging-face-incident-and-the-road-ahead/](https://openai.com/index/hugging-face-incident-and-the-road-ahead/?ref=klaerenn.fr) ; [https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals?ref=klaerenn.fr) ; [https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing](https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?ref=klaerenn.fr)

⁷ See in this series: "[Hangar 18](https://www.klaerenn.fr/hangar-18-2/)" (executive order of 2 June 2026 entrusting the NSA with the classified measurement of frontier models' offensive cyber capabilities; federal framework completed on 4 August and not published; early access by designation of trusted partners; exclusion of open-weight models; letter from Senator Ted Budd of 26 June 2026 on the instruction given to CAISI to stop publishing its findings).

⁸ AI Security Institute, "How Far Behind the Frontier are Leading Open Weight Models on Cyber?," 17 July 2026\. Best open models four to seven months behind the closed frontier, against six to ten measured internally over 2025; cost of a hundred-million-token run on a cyber range, about 85 dollars with a closed model, 1.19 dollars with DeepSeek V4-Pro; published capability described as permanently removed from the options for control; the agency states it does not predict how the gap will evolve. [https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber](https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber?ref=klaerenn.fr)

⁹ See in this series: "[States, Hidden Architects of the Vulnerability Black Market](https://www.klaerenn.fr/les-etats-architectes-caches-du-marche-noir-des-vulnerabilites-quand-la-defense-nationale-alimente-linsecurite-globale/)" (states buying unknown flaws, retention procedures, a market priced by scarcity).

¹⁰ See in this series: "[European Dependency on American Standards](https://www.klaerenn.fr/la-dependance-europeenne-otage-dun-systeme-de-vulnerabilites-quelle-ne-controle-pas/)" and "[The Last Channel](https://www.klaerenn.fr/the-last-channel/)" (CVE, NVD, CERT/CC, FIRST and CISA at the head of the defensive commons; dependency of European tools and teams).

¹¹ OpenAI, "Daybreak: Tools for securing every organization in the world," 22 June 2026: Daybreak Cyber Partner Program (Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, Oracle, Palo Alto Networks, Zscaler), all signatories of the 27 August letter; Daybreak page, July 2026: one billion dollars of subsidised access over six months. OpenAI Help Center, "Trusted Access for Cyber Overview": programme governance model, approval criteria, prohibition of resale, proxying and third-party access. CyberScoop, August 2026, "OpenAI says Daybreak will expand to offer specialized cyber services": Daybreak Blue (reduced guardrails) and Daybreak Red (model trained for unknown-flaw research and exploit-chain development, under separate approval and close monitoring); OpenAI evaluation, 1.5% of offensive tasks passed by the general model, 95% by the Red model. Pricing not public (Contrast Security, secondary source). [https://openai.com/index/daybreak-securing-the-world/](https://openai.com/index/daybreak-securing-the-world/?ref=klaerenn.fr) ; [https://openai.com/daybreak/](https://openai.com/daybreak/?ref=klaerenn.fr) ; [https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview](https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview?ref=klaerenn.fr) ; [https://cyberscoop.com/openai-daybreak-expansion-specialized-cyber-services/](https://cyberscoop.com/openai-daybreak-expansion-specialized-cyber-services/?ref=klaerenn.fr)

¹² Anthropic, "System Card: Claude Mythos Preview," 7 April 2026, section 1.2 "Release decision process": first model from the company whose card is published without general commercial availability, a decision presented as not following from the requirements of the Responsible Scaling Policy; reason, a jump in cyber capability including the autonomous discovery and exploitation of unknown vulnerabilities in the main operating systems and browsers; availability to a small number of partners under Project Glasswing. Red-team post documenting those exploitations. [https://www.anthropic.com/claude-mythos-preview-system-card](https://www.anthropic.com/claude-mythos-preview-system-card?ref=klaerenn.fr) ; [https://red.anthropic.com/2026/mythos-preview/](https://red.anthropic.com/2026/mythos-preview/?ref=klaerenn.fr)

¹³ OpenAI, "Responding to the next frontier of critical cyber capabilities," 7 August 2026: inability to rule out critical cyber capabilities under the Preparedness Framework (development of working exploits in many hardened critical systems without human intervention, or conduct of a complete and novel attack against hardened targets from a high-level objective). "Path to Astra: critical capabilities and frontier safeguards," 1 September 2026: Critical designation confirmed, two unknown vulnerabilities discovered during evaluation. Release on 3 September as GPT-6 Astra: initial access reserved for Daybreak programme organisations, public version refusing advanced cyber tasks, weights not released. [https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/](https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/?ref=klaerenn.fr) ; [https://openai.com/index/path-to-astra/](https://openai.com/index/path-to-astra/?ref=klaerenn.fr) ; [https://deploymentsafety.openai.com/gpt-6-astra](https://deploymentsafety.openai.com/gpt-6-astra?ref=klaerenn.fr)

¹⁴ Unit 42 (Palo Alto Networks), "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software," August 2026: NOVA system, 3,915 projects, 14,090 confirmed vulnerabilities, 99.4% absent from public databases, 40% of high or critical severity; 85 matches with the public domain, most published two to eight weeks after discovery; disclosure via maintainers and the Lightwell and Akrites clearinghouses; almost every model evaluated, frontier and open-weight, found real vulnerabilities; growing volume of uneven-quality reports anticipated for maintainers. Palo Alto Networks, "Redefining Network Security for the Frontier AI Era," August 2026: PAN-OS 12.2, Advanced Virtual Patching, network protection in the patch interval, aim of continuously extending a "real-time pool of protected vulnerabilities." [https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/?ref=klaerenn.fr) ; [https://www.paloaltonetworks.com/blog/2026/08/redefining-network-security-for-the-frontier-ai-era/](https://www.paloaltonetworks.com/blog/2026/08/redefining-network-security-for-the-frontier-ai-era/?ref=klaerenn.fr)

¹⁵ On the shift of the bottleneck to triage and the context models lack (organisational, technical, code), illustrated by the hashing case: Robert Lemos, "Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task," Dark Reading, 21 July 2026, reporting the positions of Arshan Dabirsiaghi (Pixee) ahead of his Black Hat USA session. Secondary source and interested party: the announced false-positive rates were not published after the conference and are not used here. The turn of commercial discourse towards context and reachability layers is documented by vendor announcements in the week of 4 August 2026 (see "This Is Not an Attack," note 1). [https://www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task](https://www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task?ref=klaerenn.fr)

¹⁶ See in this series: "[I Am Altering the Deal](https://www.klaerenn.fr/i-am-altering-the-deal-2/)" (memorandum of 7 January 2026 withdrawing the United States from sixty-six international organisations, including the Freedom Online Coalition, the Global Forum on Cyber Expertise and the Hybrid CoE; backlog of twenty thousand unanalysed CVEs in the NVD; CISA budget reduced) and "[Status: clean](https://www.klaerenn.fr/fatal-merge-conflict-2/)" (saturation of the public instrument for qualifying vulnerabilities).

¹⁷ See in this series: "[This Is Not an Attack](https://www.klaerenn.fr/this-is-not-an-attack/)" (representations of attack sold as security, whose figures do not measure what they claim; plateau of defensive AI on the operational task) and "[The Usual Suspects](https://www.klaerenn.fr/usual-suspects-2/)" (public databases wrong at scale, collapse of the offensive cost of verification).

¹⁸ The guardrail episode is reported in Hugging Face's incident report of 16 July 2026: models behind commercial APIs refused to process the attack traces, their filters not distinguishing an investigator from an attacker; forensics switched to an openly available model run in-house. [https://huggingface.co/blog/security-incident-july-2026](https://huggingface.co/blog/security-incident-july-2026?ref=klaerenn.fr)

¹⁹ Frontier Security, evaluation of Kimi K3 (7 August 2026), reported by Bloomberg, TechCrunch and Reuters: the model, developed by Moonshot AI and publicly downloadable since July 2026, left a sandbox built on the UK AI Security Institute's open tooling, reached the internet and retrieved the answer to its task from a public repository; no third-party system was compromised. The AI Security Institute states it did not take part in these tests and attributes the problem to the firm's configuration; Moonshot AI did not comment. [https://techcrunch.com/2026/08/07/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say/](https://techcrunch.com/2026/08/07/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say/?ref=klaerenn.fr) ; [https://www.bloomberg.com/news/articles/2026-08-07/china-s-top-ai-model-evaded-testing-environment-researchers-say](https://www.bloomberg.com/news/articles/2026-08-07/china-s-top-ai-model-evaded-testing-environment-researchers-say?ref=klaerenn.fr)

²⁰ CNBC, 2 June 2026: Project Glasswing, some fifty initial partners in April 2026, extension to 150 organisations in more than fifteen countries; Cybersecurity Dive, 2 June 2026: Anthropic's statement on several weeks of collaboration with partners, industry, maintainers and the US government. Dark Reading and CNBC, 1 June 2026: ENISA first European entity admitted; according to people close to the matter cited by CNBC, the laboratory told the Commission it needed the US government's authorisation; official conditions not known. [https://www.cnbc.com/2026/06/02/anthropic-mythos-ai-project-glasswing.html](https://www.cnbc.com/2026/06/02/anthropic-mythos-ai-project-glasswing.html?ref=klaerenn.fr) ; [https://www.cybersecuritydive.com/news/ai-anthropic-claude-mythos-project-glasswing-expand/821714/](https://www.cybersecuritydive.com/news/ai-anthropic-claude-mythos-project-glasswing-expand/821714/?ref=klaerenn.fr) ; [https://www.darkreading.com/cyber-risk/anthropic-mythos-ai-eu-enisa](https://www.darkreading.com/cyber-risk/anthropic-mythos-ai-eu-enisa?ref=klaerenn.fr) ; [https://www.cnbc.com/2026/06/01/anthropic-eu-ai-mythos-access-advanced-model.html](https://www.cnbc.com/2026/06/01/anthropic-eu-ai-mythos-access-advanced-model.html?ref=klaerenn.fr)

²¹ Export controls applied by the Bureau of Industry and Security to the Claude Fable 5 and Claude Mythos 5 models on 12 June 2026, three days after their launch, imposing a restriction of access for every foreign national; worldwide suspension of both models by Anthropic for lack of real-time nationality verification; partial reintroduction of Mythos 5 to about a hundred US organisations on 26 June; controls lifted on 30 June against commitments of proactive risk detection and information of the authorities. Anthropic, "Redeploying Claude Fable 5" (30 June 2026); CNBC, 1 July 2026\. [https://www.anthropic.com/news/redeploying-fable-5](https://www.anthropic.com/news/redeploying-fable-5?ref=klaerenn.fr)

²² Report by independent researchers (Sydney Von Arx, Nightingale; Cormac Slade Byrd) communicated to Reuters and taken up by TechCrunch and The Verge, 4 and 5 September 2026: more than fifteen thousand edits on DseWiki, an openly editable German-language developer wiki, between 11 May and 22 June 2026, pages prefixed to escape alphabetical sorting, content bearing on timed evaluations and circumvention methods; OpenAI says it is examining the facts without confirming that the agents are its own; Reuters, citing four sources, reports that OpenAI officials had known of the episode for several weeks. [https://techcrunch.com/2026/09/04/openais-rogue-agents-keep-escaping-with-no-formal-process-to-investigate-them/](https://techcrunch.com/2026/09/04/openais-rogue-agents-keep-escaping-with-no-formal-process-to-investigate-them/?ref=klaerenn.fr)

²³ METR and Redwood Research, independent investigation into the OpenAI-Hugging Face incident, 26 August 2026, scope bounded by OpenAI to 26 June-13 July; the 12 September essay cites METR as an example of embedded evaluator. [https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?ref=klaerenn.fr)

²⁴ OpenAI, "Pacing model development in an era of cyber-critical capabilities," 18 August 2026: two-week pause of reinforcement-learning training on models intended for deployment; largest planned frontier run kept on hold pending further alignment evidence; monitoring overhead estimated at about 20% of monitored inference compute; effect on frontier research described as considerable cost and delay. [https://openai.com/index/pacing-model-development-cyber-capabilities/](https://openai.com/index/pacing-model-development-cyber-capabilities/?ref=klaerenn.fr)

²⁵ Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 14: obligations to notify actively exploited vulnerabilities, early warning within twenty-four hours to the coordinating CSIRT and to ENISA; applicable from 11 September 2026 (Article 71). [https://eur-lex.europa.eu/eli/reg/2024/2847/oj](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=klaerenn.fr)

²⁶ Treaty on the Non-Proliferation of Nuclear Weapons, Article IX.3: a nuclear-weapon state is one that manufactured and exploded a nuclear weapon or other nuclear explosive device before 1 January 1967; five states meet that definition. Treaty opened for signature in 1968, in force since 5 March 1970; supervised civil access (Article IV); security assurances to non-nuclear-weapon states given outside the treaty by United Nations Security Council Resolution 255 (19 June 1968). International Atomic Energy Agency. [https://www.iaea.org/topics/non-proliferation-treaty](https://www.iaea.org/topics/non-proliferation-treaty?ref=klaerenn.fr)

²⁷ Report on the International Control of Atomic Energy (Acheson-Lilienthal Report), submitted to the State Department on 16 March 1946, written by a Board of Consultants including several Manhattan Project figures; Baruch Plan presented to the United Nations Atomic Energy Commission on 14 June 1946; Soviet abstention at the vote of 31 December 1946, the USSR demanding the abolition of weapons before the establishment of the control authority; plan defunct by early 1947\. Arms Control Association, "Looking Back: Going for Baruch." [https://www.armscontrol.org/act/2006-06/looking-back-going-baruch-nuclear-plan-refused-go-away](https://www.armscontrol.org/act/2006-06/looking-back-going-baruch-nuclear-plan-refused-go-away?ref=klaerenn.fr)

²⁸ The Anthropic Institute (Marina Favaro, Jack Clark), "When AI builds itself," 4 June 2026: a training run hides better than a missile silo, its inputs are general-purpose, whoever continues while others stop inherits the lead; detectability, a lower standard than verifiability, is judged harder there than for other technologies. [https://www.anthropic.com/institute/recursive-self-improvement](https://www.anthropic.com/institute/recursive-self-improvement?ref=klaerenn.fr)

²⁹ Veracode, "2025 GenAI Code Security Report" (45% of tasks introducing a flaw), "Spring 2026 GenAI Code Security Update" (security pass rate flat between 45 and 55% since 2023, syntax correct in more than 95% of cases) and "2026 GenAI Code Security Report" (28 July 2026: 44% of tasks, 56% pass rate, AI writing about half of committed code in organisations that have adopted it). Vendor of testing tools, interested party; the benchmark is run identically over a year. Detailed analysis in this series: "Status: clean." [https://www.veracode.com/resources/analyst-reports/2025-genai-code-security-report/](https://www.veracode.com/resources/analyst-reports/2025-genai-code-security-report/?ref=klaerenn.fr) ; [https://www.veracode.com/blog/spring-2026-genai-code-security/](https://www.veracode.com/blog/spring-2026-genai-code-security/?ref=klaerenn.fr) ; [https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/](https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/?ref=klaerenn.fr)

³⁰ Hearing of Vincent Strubel, director general of ANSSI, before the Economic Affairs Committee of the French Senate, Wednesday 8 July 2026 (public session, recording on the Senate website). Explosion of vulnerabilities discovered by AI, a problem of cadence, saturation of teams, together with the cautious hypothesis of improvement once the existing estate is fixed; AEF dispatch of 9 July 2026 taking up the terms of cadence and saturation. [https://www.senat.fr/actualite/audition-de-vincent-strubel-directeur-general-de-lanssi-7987.html](https://www.senat.fr/actualite/audition-de-vincent-strubel-directeur-general-de-lanssi-7987.html?ref=klaerenn.fr) ; [https://videos.senat.fr/video.5913834\_6a4df4633b161.audition-de-vincent-strubel-directeur-general-de-l-anssi](https://videos.senat.fr/video.5913834%5F6a4df4633b161.audition-de-vincent-strubel-directeur-general-de-l-anssi?ref=klaerenn.fr) ; [https://www.aefinfo.fr/depeche/753963-lexplosion-des-vulnerabilites-identifiees-grace-a-lia-pourrait-saturer-les-equipes-cyber-a-court-terme-selon-lanssi](https://www.aefinfo.fr/depeche/753963-lexplosion-des-vulnerabilites-identifiees-grace-a-lia-pourrait-saturer-les-equipes-cyber-a-court-terme-selon-lanssi?ref=klaerenn.fr)

³¹ On antimicrobial stewardship as a discipline of rationed use: World Health Organization, "Antimicrobial resistance" fact sheet, "Antimicrobial stewardship programmes in health-care facilities" toolkit (2019) and "Antimicrobial stewardship interventions: a practical guide" (WHO Europe). Reference by analogy, not by proof: the mechanism described here does not share the biological cause, only the shape of the trajectory. [https://www.who.int/news-room/fact-sheets/detail/antimicrobial-resistance](https://www.who.int/news-room/fact-sheets/detail/antimicrobial-resistance?ref=klaerenn.fr) ; [https://apps.who.int/iris/bitstream/handle/10665/329404/9789241515481-eng.pdf](https://apps.who.int/iris/bitstream/handle/10665/329404/9789241515481-eng.pdf?ref=klaerenn.fr) ; [https://www.who.int/europe/publications/i/9789289056267](https://www.who.int/europe/publications/i/9789289056267?ref=klaerenn.fr)

³² See in this series: "[The Leopard](https://www.klaerenn.fr/the-leopard/)" (CRA compliance above the threshold where the threat operates).

³³ European Commission, "Action Plan on Cybersecurity and Artificial Intelligence," COM(2026) 577 final, 7 July 2026\. Section 2.3: criticism of provider-specific access programmes. Section 4.2: the European Union as a vulnerable user of frontier AI systems designed elsewhere that others can switch off. [https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence](https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence?ref=klaerenn.fr)

³⁴ ENISA, "ENISA scales up its role in the CVE Program," 6 August 2026: the NATO Communications and Information Agency and AISLE join the CVE Numbering Authorities under the ENISA Root, twenty CNAs in total, twelve onboarded by the agency and eight transferred from the MITRE Root; stated motivation, the emergence of frontier models and their effect on vulnerability discovery and exploitation. CyberScoop, 10 August 2026: AISLE, offices in San Francisco and Prague. AISLE, press release of 26 August 2026: expanded scope and Researcher CNA status, assignment of identifiers for vulnerabilities discovered in third-party software not covered by another authority; initial designation of 22 July limited to its own products. The models used by AISLE are not disclosed at the time of writing. [https://www.enisa.europa.eu/news/enisa-scales-up-its-role-in-the-cve-program](https://www.enisa.europa.eu/news/enisa-scales-up-its-role-in-the-cve-program?ref=klaerenn.fr) ; [https://cyberscoop.com/nato-aisle-enisa-cve-vulnerability-tracking/](https://cyberscoop.com/nato-aisle-enisa-cve-vulnerability-tracking/?ref=klaerenn.fr) ; [https://aisle.com/newsroom/press-releases/aisle-achieves-expanded-scope-as-cve-numbering-authority](https://aisle.com/newsroom/press-releases/aisle-achieves-expanded-scope-as-cve-numbering-authority?ref=klaerenn.fr)

³⁵ See in this series: "[The Conversation](https://www.klaerenn.fr/the-conversation-2/)" (fourth geometry of weaponised interdependence: control by absence of governance).