IC Technology & Surveillance — 2026-05-11

Pentagon Cyber Policy Chief Says Frontier AI Can Find and Fix Vulnerabilities in Minutes, Not Weeks

Defense One reported on May 9 that Emil Michael, undersecretary of defense for research and engineering, told reporters at the Pentagon that the GenAI.mil platform has compressed two-week tasks to three hours since its December launch. Michael also said the Pentagon is in a testing and evaluation period with Anthropic's Mythos model for vulnerability discovery, despite Anthropic holding a government national-security risk designation that the company has challenged in federal court. Jackson Reed, founder of AI startup Barding Defense, told Defense One that the same agentic tools will enable criminal groups to shift from ransomware toward sustained network espionage, mimicking Russian and Chinese state-backed groups. Reed said Anthropic's Opus 4.6 can find and fix code vulnerabilities but misses lateral movement.

Analysis
The Pentagon's decision to evaluate Mythos despite Anthropic's active national-security risk designation, per a single Defense One report, signals operational urgency overriding procurement orthodoxy when no substitute meets capability requirements. The defensive dividend is narrower than those productivity figures imply: Opus 4.6 compresses the known-vulnerability cycle but leaves lateral movement undetected, and that gap is precisely what separates opportunistic ransomware from strategic espionage. Reed's gap analysis carries the commercial interest of a startup marketing to the same military customers, which qualifies its weight. Criminal groups exploiting the same cost-compression dynamics will likely adopt sustained network-espionage tradecraft at scale by mid-2027, driven by agentic AI's commoditization of reconnaissance and Russia's established criminal-state nexus.
1 sources
  1. Pentagon leaders love agentic AI but its giving cyber criminals nation-state-like powers - Defense One

View in full brief →

UNCLASSIFIED // OPEN SOURCE