The hackers just got a speed upgrade, and the referees took a pay cut.
The Summary
- New AI models from Anthropic (Mythos) and OpenAI (GPT 5.6) can find and exploit system vulnerabilities faster than human hackers, powerful enough that the U.S. government is pausing or limiting their public release
- This escalation arrives just as CISA and FedRAMP face major staffing cuts under the Trump administration
- Government says cloud services "meet rigorous security standards," but four former officials say the challenge is getting harder, not easier
The Signal
Agentic AI just crossed a threshold that matters. Anthropic's Mythos and OpenAI's GPT 5.6 can autonomously hunt for vulnerabilities and exploit them, no human in the loop. The speed differential is what's new. A skilled penetration tester might take days to map attack surfaces and test exploits. These models do it in hours, sometimes minutes.
The government noticed. Public releases of these cyber-capable models are being paused or restricted. That's a signal, not theater. When agencies that usually move at geological pace suddenly pump the brakes on AI deployment, the risk profile is real.
"The hackers just got autonomous, and the defense budget just got smaller."
Here's the timing problem. The Cybersecurity and Infrastructure Security Agency is operating with a fraction of its former headcount after recent cuts. FedRAMP, the body that sets security standards for cloud providers handling government data, has been "reformulated and slimmed down." These aren't minor support offices. CISA is the frontline threat monitor. FedRAMP gates access for Amazon Web Services, Google, Microsoft, and Palantir when they touch federal cloud infrastructure.
Both agencies are addressing agentic AI risks:
- CISA has issued new guidance on AI threats
- FedRAMP spent a year revising security requirements for cloud providers
- New reporting requirements are live, more expected in coming months
The official line is reassuring. Federal cloud services "meet rigorous security standards" and are "continuously tested as cybersecurity threats evolve." But four former government officials told Fast Company the reality is grimmer. One phrase stands out: "I'd be a lot more confident about all of this if the Trump administration hadn't forced out so many of the best IT and cyber professionals at CISA and other agencies."
The Implication
The agent economy has a shadow twin: agents built to break things. Offensive AI capabilities are advancing faster than defensive postures, especially when the defense is understaffed and underfunded. If you're building in the agent space, assume your systems will be probed by autonomous adversaries. Security isn't a feature anymore. It's the foundation.
Watch FedRAMP's evolving requirements. If cloud providers to the federal government are scrambling to meet new AI-era security standards, those same standards will ripple out to enterprise contracts. The companies that figure out agent-resistant infrastructure first will have a durable moat.