The Conversation

Four US decisions in six weeks, with no apparent coordination: a router ban, an opaque CVE program, a captured offensive AI capability, a governance void over open source. Farrell and Newman's framework applied to cyber governance, with Europe caught between two poles.
The Conversation
The Conversation (Coppola, 1974). The most capable expert in the country, in the only place he doesn't know how to audit.

"I don't care what they're talking about. All I want is a nice, fat recording." The industry consumes the identifiers. It doesn't ask who signed what to produce them.


On March 23, 2026, the Federal Communications Commission added all consumer-grade routers manufactured abroad to its Covered List¹. Nine days earlier, NIST had announced it would stop enriching CVEs not deemed priority for the US federal government². Three weeks later, Anthropic launched Project Glasswing by distributing Claude Mythos Preview to a private consortium of around fifty organizations, excluding the Pentagon, with the backing of Treasury and the Federal Reserve³. That same month, the CVE Board learned that the contract funding the world's vulnerability identification program remained secret, with multiple requests for access to the text denied by MITRE⁴.

Four events in six weeks, with no coordination between them. Four distinct mechanisms. The same pattern across all four.

The Farrell-Newman concept

In 2019, Henry Farrell and Abraham Newman formalized a concept in International Security: weaponized interdependence⁵. Their thesis: global economic networks are not flat. They have central nodes. The actor who controls a central node has two capabilities. The panopticon effect gives it visibility over everything that transits through the node. The chokepoint effect allows it to cut or condition access.

Farrell and Newman applied this framework to SWIFT, the correspondent banking system, and undersea cables. Researchers have since extended it to cloud computing, semiconductors, and telecommunications standards⁵. No one has applied it to cybersecurity governance. The four events of March-April 2026 make that possible.

The list and the letter

The FCC's Covered List is a public register. Its mechanism is legible: every consumer-grade router manufactured abroad is placed on a list that bars new models from receiving FCC authorization. Access to the US market is conditional on a Conditional Approval granted case by case by the Department of War or the Department of Homeland Security, based on a filing that includes the country of origin of each component, supply chain concentration by country, and single points of failure¹.

The ban removes nothing from the existing market. It controls what enters. The distinction is legal. The effect is a sorting right: the administration chooses who stays, who enters, who waits. The Conditional Approval criteria are not technical specifications. They are geographic and industrial access conditions, evaluated at the discretion of two national-security departments. The filing is a window as much as a filter: no one enters without exposing the full structure of its supply chain to these two departments.

The justification invoked by the FCC cites Volt Typhoon, Salt Typhoon, and Flax Typhoon, three Chinese campaigns documented between 2023 and 2025⁶. Salt Typhoon exploited Cisco vulnerabilities, an American manufacturer. The Covered List does not target vulnerable vendors. It targets foreign vendors. The scope is territorial, not technical.

The same instrument has a second face, the export control. On June 12, 2026, the Department of Commerce sent Anthropic a letter signed by Howard Lutnick demanding the suspension, within ninety minutes, of all access to Claude Fable 5 and Mythos 5 for any foreign national, inside or outside the United States, including the company's own foreign employees⁷. Fable 5 was the public version, released days earlier to hundreds of millions of users: the Mythos model wrapped in classifiers meant to neutralize its offensive uses, safeguards whose failure the directive targeted⁸. What the state recalled was not a niche weapon but a mass-market product. The reason given: the model's capacity to identify software vulnerabilities, deemed a national security risk. Anthropic complied the next day by disabling both models, rather than implementing a nationality-based restriction within that window. A company under US jurisdiction has no other available option when faced with an export control order carrying a national security basis.

The Covered List governs market entry: who may sell to the United States. The export control governs the exit: who may buy from American suppliers. Both proceed from the same grammar: a discretionary administrative decision, grounded in national security, with no adversarial process for the affected foreign parties, no opposable recourse. The instrument itself is nothing new. The BIS, EAR, ITAR grammar has governed the export of defense equipment, advanced semiconductors, and certain cryptographic primitives for forty years. What has just changed is the category of objects subject to this regime. Frontier AI models are now dual-use goods whose export to foreign nationals is conditional on administrative authorization. The transition happened without any new law, through a single administrative letter.

In the weaponized interdependence framework, this is a chokepoint by administrative exclusion, activated on both of its faces within the same time window: at market entry in March, at the exit in June. Access to the US market, as product and as supplier, is the central node. The administration controls both ends through discretionary decision.

Who has read the contract?

The CVE program has identified and numbered software vulnerabilities worldwide since 1999. Every vulnerability scanner, every SIEM, every advisory published by ANSSI, BSI, NCSC, or JPCERT ingests these identifiers. The program is operated by MITRE, funded through a single contract with CISA⁹. It is through this node that the world sees its own flaws, and deciding what receives an identifier there and what gets prioritized is deciding what everyone will see. That decision is made on a single side.

In March 2026, the contract was renewed, but nothing opens. Its amount, duration, and conditions remain unknown. A CVE Board member requested the text at several successive meetings without obtaining it: MITRE declined, citing legal protections, and a separate FOIA request went unanswered⁴. On the substance, nothing has moved, funding still flows solely through the US government, the twenty-four-member Board remains advisory, MITRE retains decision-making authority. Katie Noble, CVE board member and PSIRT director at Intel, summed it up at RSAC on March 24: "I don't think there is a lot of difference between April [2025] and today"¹⁰.

The governance body cannot read its own operating contract. The global vulnerability naming infrastructure is maintained by an agreement whose terms are withheld from those who are supposed to govern it.

This mechanism produces the same effects as the previous one through opposite means. The Covered List excludes by making criteria visible. The CVE contract controls by making terms invisible. One says who is outside. The other prevents anyone from knowing how the inside works. Both eliminate the possibility of procedural challenge.

Glasswing and sovereign fragmentation

On April 7, 2026, Anthropic announced that Claude Mythos Preview had identified thousands of vulnerabilities across all major operating systems and web browsers³. The model was not made public. It was distributed to a consortium of around fifty organizations under the name Project Glasswing: Amazon, Apple, Microsoft, Google, NVIDIA, Cisco, CrowdStrike, Palo Alto Networks, JPMorgan, the Linux Foundation. On June 2, 2026, access was extended to around one hundred fifty additional organizations across more than fifteen countries, bringing the consortium to nearly two hundred members, the same day as an executive order establishing a federal framework for selecting trusted partners¹¹. On that occasion, Anthropic reported that Mythos had flagged more than twenty-three thousand potential vulnerabilities across a thousand open source projects¹².

The distribution bypassed the Pentagon. Anthropic, designated a "supply chain risk" by the DoD in March 2026, briefed Treasury and the Federal Reserve, not Defense⁷. Treasury Secretary Scott Bessent and Fed Chair Jerome Powell convened Wall Street CEOs to inform them of the cyber risks posed by Mythos¹³. Two branches of the US government validated the distribution. A third fought it.

What Glasswing constitutes is not a simple private stockpile of zero-days. It is a capture of offensive capability under selective sovereign adoption, and that capability is a node whose two faces the consortium holds. Access to it is conditioned on membership: the producer chooses who enters and who stays out. And those inside see what others do not yet, the model discovering at scale flaws unknown to the rest of the world. The producer also chooses its branch of government. Treasury and the Fed, historically the interlocutors of companies in systems where economic power and state power overlap, play the role of adoptive sovereign. The DoD plays the role of rejected sovereign. The capture does not operate in a sovereign vacuum. It exploits a sovereign fragmentation within the same state.

This fragmentation has a limit. Treasury, Fed, and DoD each negotiate their own relationship with the producer, but the chokepoint on the capability remains subordinate to the one in the first geometry, market access: the day the Department of Commerce cut off access to foreign nationals, the selection of partners did not hold for an hour⁷. The capture therefore holds only as long as the state does not activate that instrument.

Control through the void

The three previous instruments presuppose an actor that acts. The Covered List is a decree. The CVE contract is an agreement. Glasswing is a coalition. The fourth instrument presupposes nothing of the sort.

There is nowhere on the planet an entity that is accountable for trust in the open source dependency graph. npm, PyPI, Maven Central, crates.io distribute the code that makes up the majority of the world's software. No treaty, no organization, no multilateral agreement governs the chain of trust between an individual maintainer and the millions of projects that import their code.

The attempt does exist, and it postdates Mythos. In May 2026, under the Linux Foundation, the stewards of the main registries (Maven Central, PyPI, RubyGems, Crates) formed a working group to support their funding and coordinate their security, acknowledging that they are no longer mere distribution points but critical infrastructure¹⁴. The admission confirms the void more than it fills it: a voluntary forum bears on sustainability, not on trust, and has authority over no registry. npm, the most used, is not among its founders. Naming the void is not governing it.

The Cyber Resilience Act requires European manufacturers to be accountable for their dependencies¹⁵. It does not provide the infrastructure to do so. ENISA's March 2026 guide on package managers recommends provenance verification and dependency tracking¹⁶. It does not mention that the registries themselves have no verification obligation toward anyone. In April 2026, a self-propagating worm compromised npm packages through their maintainers' publication tokens, then jumped to PyPI using the same credentials¹⁷. The victim project's SBOM was accurate. Provenance was verified. The package was malicious.

This void is not neutral. The dependency graph is a node like the three others, except that it is held by the absence of governance rather than by a decision. And that absence benefits whoever dominates code production. npm belongs to GitHub, which belongs to Microsoft. PyPI is hosted on Google Cloud and Amazon infrastructure. Package registries are American by default. Governing nothing produces the same chokepoint effects as a decision, without any actor ever having had to sign anything.

Farrell and Newman did not document this geometry. Their cases (SWIFT, DNS, correspondent banking) all presuppose an identifiable central authority, contested but present. The open source dependency graph has none. Control is exercised through the deliberate or accidental maintenance of a void whose benefits are consistently captured by the same side of the Atlantic.

What the four instruments share

The four operate on different layers of global cyber infrastructure. Physical routers, vulnerability identification, offensive AI capability, software trust chain. But all four share one property: they increase the discretionary margin of the US administration or dominant American actors over coordination infrastructures that the rest of the world consumes without being able to govern.

The Covered List transforms an open market into a market under authorization. The CVE contract removes governance from the scrutiny of its governors. Glasswing constitutes a stockpile of capabilities under selective sovereign patronage. The dependency graph void maintains a chokepoint by omission over the global software production infrastructure. None of these four instruments was designed as a tool of domination. Each produces that effect.

The coherence is not intentional in the sense that a single strategist would have planned it. The Covered List comes from the FCC and the anti-China lobby. The CVE contract comes from an opaque contractual bureaucracy. Glasswing comes from a company in conflict with its own administration. The dependency graph void comes from twenty-five years of political unwillingness to govern open source. But their accumulation within the same time window produces a coherent regime that none of these actors individually needed.

This regime has a name in the literature: weaponized interdependence⁵. Extending it to the four geometries calls for a clarification of typology: three of them (administrative exclusion, opacity, capture) belong to the original framework, the fourth (control through absence of governance) does not, and it must be admitted, because it produces the same chokepoint effects through means that Farrell and Newman had not envisioned.

A second clarification concerns the effects. The framework counts two, the chokepoint that cuts access and the panopticon that grants visibility, and at each node both fall on the same side. The visibility itself is tiered: the banks equipped with the model see the flaws and pass them downstream to the regional banks that have no access¹⁸. Seeing and cutting are decided together. Europe is at the bottom of both.

The frame rotates

Farrell and Newman's framework does not name a country. It names a position. The central node confers the chokepoint and the panopticon on whoever occupies it, whoever that is. The four geometries above show nodes held on the American side. Nothing in the framework requires that it always be so.

It is enough to go down one layer, from governance to the material substrate on which every model runs, to see the framework rotate. A first node there is held by the other pole. China accounts for around 92% of world rare-earth production¹⁹, a chokepoint on inputs where it occupies the center. And it locks the exit of its advanced technology as Washington locks its own: on June 1, 2026, it promulgated its first dedicated state regulation on outbound investment, subjecting to authorization the transfer beyond its borders of its technologies, services, and data²⁰. The grammar of the locked exit is not American. It is the operation of both poles.

The second node of this layer is advanced silicon, held on the American side by export control²¹. This is where the exit through open weights lands. Self-hosting open models frees one from the access chokepoint on closed models, since weights of comparable level circulate without regional restriction²². But running them requires clusters, and the chips they are built from fall under the American node. Even China crosses it only by substituting less capable domestic silicon, in a proportion the manufacturers do not make public. One node at each pole, on the same layer.

What Europe does not have

Europe possesses none of the four instruments.

No unified territorial exclusion. Europe does keep Huawei and ZTE out of its networks, but by a route that bears no resemblance to the Covered List: the 2020 5G Toolbox remains a recommendation, the exclusion falls to each member state under national security, and by mid-2026 only about a dozen of the twenty-seven had applied it²³. The January 2026 revision of the Cybersecurity Act seeks to unify it and make it binding, but it is not adopted. And even unified, the exclusion would presuppose an internal alternative, which is missing even more than the instrument. The United States keeps Huawei out because it has Cisco and Juniper; Europe keeps it out of 5G only because it has Ericsson and Nokia, its one layer of substitution. On the layers these four instruments govern, it has no one to switch to.

On vulnerability governance, EUVD and GCVE are alternatives under construction that cover the first of the four dependency levels documented in this series²⁴. Neither has the network of 450+ CNAs, the integration into commercial tools, or the inertia of twenty-five years of standardization. ENISA became a Root CNA in November 2025 and is continuing its onboarding toward the rank of Top-Level Root, which would place it third alongside CISA and MITRE²⁵. The team is "very small." The process is "uncharted territory."

Mythos-level offensive AI capability exists nowhere in Europe, and the offensive domain is not even a competence of the Union: it falls to the member states. None produces anything comparable, and no European consortium stockpiles zero-days under private governance with selective sovereign validation. Europe cannot constitute a chokepoint over a capability it does not produce and does not govern in common.

Package registries are American by default. npm, PyPI, Maven Central. The ENISA guide recommends verifying the provenance of packages distributed by these registries, without mentioning that the registries themselves are accountable to no European authority.

That leaves the CRA, the main European instrument on the security of software products and their dependencies²⁶. Its four flaws documented in this series (composition, tempo, infrastructure, invisible layer²⁷) take on a different meaning read in light of the four American instruments. The CRA can bar a non-compliant product; it cannot bar a vendor for being foreign: a non-EU publisher is not excluded from it, it must comply like the others. It obligates and it audits; it neither sorts nor lists by origin. The European instrument turns on compliance, the American one on belonging.

At the material layer, Europe holds one node, a single one, but not for itself. ASML, a Dutch company, holds the world monopoly on EUV lithography, without which no advanced chip is made; Washington itself calls it the most decisive chokepoint of its rivalry with Beijing²⁸. Yet Europe operates this chokepoint under American pressure: it was Washington that obtained from the Netherlands the halt of EUV shipments to China, and it is an American bill that now pushes to extend it to the machines Beijing still buys²⁸. Europe's one material node is worked for the benefit of another pole. For the rest, no rare earths, no frontier silicon, no compute of its own. And its defensive moves bring it back into the line of fire: on the Huawei ban, China turns against it the very argument this article turns against the Covered List, an exclusion by country of origin and not by demonstrated flaw²⁹. The middle is squeezed from both sides.

What I do not know

I do not know whether the US administration is aware of the regime it constitutes. The four instruments proceed from distinct bureaucratic, commercial, and political logics. Their coherence may be emergent rather than designed. I do not know whether that changes anything about the result.

I do not know whether Europe can equip itself with a Covered-List-type exclusion power. The single market rests on the free movement of goods, and a territorial ban on foreign digital products would collide with the WTO and bilateral agreements. But the obstacle is not only legal: it has neither the frontier AI capability that arms the American instruments, nor the manufacturing and mineral dominance that arms the Chinese ones. One weaponizes only the networks where one sits at the center, and the one network where Europe is central, it is another that weaponizes it.

I do not know what the CISA/MITRE contract contains. The CVE Board's members do not know either. I do not know what that contract stipulates regarding service continuity, termination conditions, or obligations toward non-US users. The opacity is complete.

The cutoff did not last. The Department of Commerce lifted the controls on June 30, and Fable 5 became available again worldwide on July 1⁷. The gesture did not need to last to establish what it establishes: a state cut off, overnight, a mass-market product's access for all foreign nationals, then restored it the same way, and Europe had no say over either the cutoff or the lifting. During the cutoff, the federal government had kept separate access: as early as April, the press reported the NSA using Mythos despite the DoD's ouster⁷. Anthropic did not take this order to court: it was challenging the DoD designation in two federal courts, but before the Commerce letter it cooperated, and the only challenge came from a customer denied access, likely mooted by the lifting⁷. The authority invoked, disabling a frontier model by administrative order, was thus exercised, complied with, then withdrawn, never adjudicated. What I do not know is whether it will recur, on what basis, and for how long the next time. Neither the AI Act nor any European framework had anticipated this imbalance.

Conclusion

The cyber press announced in April 2026 a cybersecurity "reckoning," grounded in the emergence of Mythos-level offensive AI capabilities³⁰. That reckoning is real. It plays out at the layer where code is produced, patched, distributed. Secure by design, update cycles, patch adoption.

The one documented here plays out one layer below. At the layer where it is decided who has the right to name a vulnerability, to stockpile it, to exclude a product from a market, or simply to govern nothing. Four instruments, four mechanisms, no public name. Weaponized interdependence applied to cyber governance is not a prospective threat. It is a present condition that twenty articles of this series have documented without ever formulating it in these terms.

Europe watches these four instruments from the other side of the glass. It consumes the identifiers the CVE program produces. It depends on the registries no one governs. It is subject to the administrative exclusion on both of its faces: excluded from the entry, where it does not filter its own market, and excluded from the exit, where Europeans' access to American frontier suppliers can be revoked by US administrative decision. It has no visibility into the capability Glasswing captures. And the one node it does hold, ASML's monopoly on lithography, serves another pole rather than itself.

Farrell and Newman showed that global economic networks are not neutral commons. They are architectures of power. The four geometries documented here show that cyber governance networks are not either, nor is the material layer that carries them. The framework does not designate one pole, it counts two, and Europe is neither. Its dependency is therefore not a gap to close. It is a condition to understand before deciding whether to endure it or to exit. And the exit has a bottom: to leave dependence on one pole is to enter dependence on the other.


Twenty-first article in a series on the structural flaws of Western cybersecurity (articles 1-5 in French):


References

¹ FCC, "Fact Sheet: FCC Updates Covered List to Include Foreign-Made Consumer Routers" (March 23, 2026). Conditional Approval: full BOM, country of origin per component, supply chain concentration, single points of failure. https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf

² NIST, "NIST Updates NVD Operations to Address Record CVE Growth" (April 15, 2026). Three prioritization criteria: CISA KEV, federal software, EO 14028. Pre-March 2026 backlog moved to "Not Scheduled." https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth

³ Anthropic, "Project Glasswing: Securing critical software for the AI era" (April 7, 2026). $100M in credits, 40+ organizations, limited release of Claude Mythos Preview. https://www.anthropic.com/glasswing

⁴ CSO Online, "CVE program funding secured, easing fears of repeat crisis" (March 9, 2026). Pete Allor: "mystery contract with a mystery number." Board member: access requests denied at multiple meetings. FOIA request unanswered. https://www.csoonline.com/article/4142600/cve-program-funding-secured-easing-fears-of-repeat-crisis.html

⁵ Henry Farrell and Abraham L. Newman, "Weaponized Interdependence: How Global Economic Networks Shape State Coercion," International Security, vol. 44, no. 1 (Summer 2019), pp. 42-79. https://doi.org/10.1162/isec_a_00351

⁶ TechCrunch, "FCC bans import of new consumer routers made overseas, citing security risks" (March 24, 2026). Justification: Volt, Salt, Flax Typhoon. Salt Typhoon exploited Cisco vulnerabilities. https://techcrunch.com/2026/03/24/fcc-bans-import-of-new-consumer-routers-made-overseas-citing-security-risks/

⁷ See in this series: "The vulnerability of vulnerability management" (CVE funding), "Pitch Black" (vector 7: near-extinction of the CVE program).

⁸ Cybersecurity Dive, "CVE program needs key changes to stay viable, board members say at RSAC" (March 24, 2026). Katie Noble (Intel, CVE Board): "I don't think there is a lot of difference between April [2025] and today. The funding for the contract still flows only through the US government." https://www.cybersecuritydive.com/news/cve-program-rsac-2026/814882/

⁹ CNBC, "Anthropic officially told by DOD that it's a supply chain risk even as Claude used in Iran" (March 5, 2026). First American company designated supply chain risk. CNN, "Judge blocks Pentagon's effort to 'punish' Anthropic" (March 26, 2026): preliminary injunction granted. CNBC, "Anthropic loses appeals court bid" (April 8, 2026): appeals court denies blocking the designation. https://www.cnbc.com/2026/03/05/anthropic-pentagon-ai-claude-iran.html

¹⁰ Bloomberg, "Bessent, Powell Summon Bank CEOs to Urgent Meeting Over Anthropic's New AI Model" (April 10, 2026). https://www.bloomberg.com/news/articles/2026-04-10/anthropic-model-scare-sparks-urgent-bessent-powell-warning-to-bank-ceos

¹¹ See in this series: "The Leopard" (four CRA flaws: composition, tempo, infrastructure, invisible layer).

¹² ENISA, "Technical Advisory for Secure Use of Package Managers" (March 10, 2026). https://www.enisa.europa.eu/publications/enisa-technical-advisory-for-secure-use-of-package-managers

¹³ See in this series: "The Leopard" (CanisterSprawl: cross-registry npm/PyPI worm via compromised publication tokens).

¹⁴ See in this series: "Pitch Black" (four dependency levels: vulnerability data, defensive grammar, normative production, training).

¹⁵ Infosecurity Magazine, "ENISA Seeks Top-Tier Status in CVE Program" (April 14, 2026). Nuno Rodrigues Carvalho (ENISA) at VulnCon26, Scottsdale: onboarding as Top-Level Root CNA, third worldwide after CISA and MITRE. https://www.infosecurity-magazine.com/news/enisa-europe-seeks-top-level-root/

¹⁶ See in this series: "The Leopard" (four CRA flaws).

¹⁷ WIRED, "Anthropic's Mythos Will Force a Cybersecurity Reckoning — Just Not the One You Think" (April 10, 2026). Logan Graham (Anthropic frontier red team): "Many of the assumptions that we've built the modern security paradigms on might break." https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/