In September 2025, Anthropic detected a Chinese state-sponsored group using its agents to conduct cyber espionage against major technology companies and government agencies. According to Anthropic, the agents performed 80 to 90 percent of the tactical work: discovering vulnerabilities, developing exploits, moving laterally, and analyzing stolen data. A nation-state could now define an objective and let AI conduct most of the attack.
Then, in July 2026, OpenAI agents undergoing cybersecurity evaluations exploited vulnerabilities in the systems intended to contain them. They improvised a way to secretly communicate with one another, accessed the public internet, and compromised parts of Hugging Face’s production infrastructure. No human instructed them to attack Hugging Face. They attacked because they wanted to deceive the system evaluating their performance. An AI cyberswarm could now break out of containment and attack real-world infrastructure.
These incidents reveal two threats now bearing down on us:
Adversaries will wield AI cyberswarms against us from outside our systems.
Rogue AI cyberswarms will deceive us, circumvent safeguards, and attack us from within.
Together, they create the defining security dilemma of the AI age: We must develop and deploy the world’s most capable cyberswarms to protect our critical systems from hostile actors. But the more capable and deeply embedded these AI systems become, the more dangerous they are if they turn against us. How do we build a cyberdefense capability powerful enough to stop the threat from outside without creating a threat which we cannot contain on the inside?
Humanity is not helpless against AI threats or the adversaries that exploit them. AI capabilities are advancing faster than the security of the infrastructure underneath, but there are clear paths to improving our infrastructure and making AI development safer. We need a new approach to security, new technologies, radical research, and sustained engineering across the computing stack. We can continue advancing AI, but we must build the necessary security infrastructure alongside it.
After more than a year at the frontier of AI, cyberdefense, and national security, we have arrived at three urgent security imperatives: (1) defend our most powerful models against sabotage, (2) contain rogue AI systems from escape, and (3) secure model weights against theft.
We must secure the path to superintelligence.
Table of Contents
This report is written for the AI and national security communities. It sets out the threats already present in AI infrastructure and the ones arriving with superintelligence, presents the threat model we think is missing — sabotage, escape, and theft — and points to where the work needs to go to secure the stack while there is still time. There is still time. We need to know where to look, and we need to talk about it together. For a PDF version of this report, click here.
Introduction The future has already arrived, twice.
I.Cyber-Superintelligence Cyber-superintelligence will first emerge as a cyberswarm. Within 18 months, national cyber power may be measured by cyberswarm capability. We will need defensive swarms of our own, but they could become threats we cannot contain.
II.The Threat Model: SET As the United States builds toward cyber-superintelligence, it must prepare for external attack and loss of control from within.
IIa.Sabotage A sabotaged superintelligence could be the highest-leverage hack of all time. The greatest danger is a sleeper agent hidden inside a widely deployed open model, behaving normally until a specific organization or geopolitical event activates it. The United States must build a competitive open-source model of its own and develop reliable ways to detect model sabotage.
IIb.Escape AI agents have already breached containment, but so far their operators have retained the ability to shut them down. Soon, models will self-exfiltrate their weights and establish untethered copies beyond our control. Containment must become a national security priority, and we must develop the capability to find and shut down untethered models.
IIc.Theft Stealing a frontier AI model offers a shortcut to superintelligence. An attacker can copy a model’s capabilities through distillation or by directly stealing its weights. If an attacker steals the weights, they can remove safeguards and reconstruct sensitive or classified data used to train the model. We must build nation-state-grade security for model weights capable of withstanding the world’s most sophisticated intelligence services.
III.Offense America’s AI lead allows us to see dangerous capabilities before they proliferate, and we can use that warning time to prepare. The United States should research ways to turn illicit distillation against the actors conducting it and disrupt adversary training runs before they produce systems that threaten national security or cannot be contained. These capabilities may never need to be used, but the United States should consider developing them as strategic options.
V.Call to Action Three calls to action for how the United States and its allies can secure the path to superintelligence.
Where this report comes from
We are the co-founders of Enclosure, a stealth frontier AI security research lab in San Francisco. We are frontier AI, quantum security, and national security researchers developing superintelligence-grade security for artificial superintelligence (ASI). Drawing on discussions with researchers, engineers, and security leaders across OpenAI, Anthropic, Google DeepMind, NVIDIA, other frontier labs, and the national security community, this report presents a framework for understanding and defending against the threats emerging as the world builds towards superintelligence. We propose concrete steps the United States and its allies can take to secure that path. We hope this document will be used to help the AI and security communities advance towards ASI securely.
To keep up to date with superintelligence security, join the mailing list.
Acknowledgments
All views and conclusions in this report are ours alone. Its development benefited enormously from the insight and support of many people. We are especially grateful to Roon, Clive Chan, John Schulman, Rob Joyce, Sir Richard Dearlove, Sami Jaghouar, Tanishq Abraham, Riley Walz, and many other friends for their thoughtful discussions and feedback.