When AI finds vulnerabilities better than humans (the turning point of 2026)A threshold was crossed in 2026: the best frontier models became capable of discovering and exploiting software vulnerabilities at the level of the very best human experts, on an unprecedented scale. Anthropic's Mythos model thus uncovered thousands of unknown vulnerabilities ("zero-days") across all the major operating systems and browsers, some of which had gone unnoticed for decades (a 27-year-old flaw in OpenBSD, another 16-year-old one in the FFmpeg video component that no automated test had detected). This is a characteristic double-edged sword: the same capability that makes a model dangerous in the wrong hands makes it precious for patching vulnerabilities before they are exploited. Hence, in April 2026, the Glasswing project, a defensive coalition bringing together Anthropic and major players in tech and finance (Amazon, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, etc.) to put these capabilities in the service of security, including for maintainers of open source software; other labs are developing their own tools in parallel (for example Big Sleep and CodeMender at Google). The flip side appeared in June 2026: invoking export controls and national security, the U.S. government suspended, overnight, access to the Fable and Mythos models for any foreign national, out of fear that their cyber capabilities might be misused. The episode fueled a heated debate: for the government, it was a matter of national security; for Anthropic, the measure was disproportionate and rested on a minor workaround that other public models also exhibited; for some observers, a product presented as a near-"weapon" ends up being treated as such by the state. It is one of the first cases where an export control targets an AI model, and no longer only chips (Chapters 22 and 25). The restriction was short-lived: the U.S. Department of Commerce lifted these controls on 30 June 2026, and Anthropic redeployed Fable 5 worldwide as early as 1 July, with a reinforced safety classifier that now blocks the reported workaround technique in more than 99 percent of cases (Mythos 5, for its part, being restored for a set of U.S. organizations). Notably, the tests conducted during the crisis confirmed Anthropic's position: less capable models (including Opus 4.8, GPT-5.5, or Kimi K2.7) spotted the same vulnerabilities, so that the workaround exposed no cyber capability specific to Mythos. The episode nonetheless prompted Anthropic and its partners (Amazon, Microsoft, Google) to begin work on a common framework for measuring the severity of jailbreaks and on reinforced collaboration with the state on pre-deployment testing.