{"slug": "runtime-why-ai-can-t-defeat-every-security-challenge", "title": "Runtime: Why AI can't defeat every security challenge", "summary": "Cryptography experts pushed back on claims that advanced AI models can defeat encryption, after Anthropic announced in July that its Mythos model \"weakened\" the HAWK post-quantum cryptography algorithm and HAWK's team pulled it from NIST's vetting project. HAWK researcher Léo Ducas told The Stack that the identified weakness was real but could be fixed by doubling the cryptographic key size, and that \"the notion that AI will break all cryptography or that we would need some kind of post-AI cryptography is a take that doesn't make sense to me.\" Puneet Bakshi, a researcher at India's Centre for Development of Advanced Computing, said AI can still find loopholes in how cryptography is deployed even if it cannot attack the underlying mathematical hard problems.", "body_md": "*Welcome to Runtime! Today: Despite Anthropic's attempts, cryptography is still too hard for AI models to defeat, how Uber got over tokenmaxxing, and more.*\n\n*Please forward this email to a friend or colleague! If it was forwarded to you,* __sign up here__ *to get Runtime for free every week, or* __level up here__*.*\n\n### First up: Crypto keeper\n\nIn the wake of a fitful summer during which advanced AI models appeared to take on supernatural cybersecurity powers, it's no surprise that worries about the staying power of cryptographic algorithms — even the post-quantum ones — would crop up. After all, given enough time and tokens, is anything designed before the advent of LLMs really safe?\n\nBut cryptography experts think those concerns are overblown, despite [__Anthropic's announcement in July__](https://www.anthropic.com/news/discovering-cryptographic-weaknesses?ref=thestack.technology) that its Mythos model \"weakened\" the HAWK cryptography algorithm, leading the team behind that project to pull it from NIST's project to vet post-quantum standards. \"The notion that AI will break all cryptography or that we would need some kind of post-AI cryptography is a take that doesn't make sense to me,\" HAWK researcher Léo Ducas told *The Stack*.\n\nThe weakness that Mythos identified in the HAWK algorithm was real, but could be dealt with by doubling the size of the cryptographic keys used to protect the system, and given that the NIST challenge was focused on efficiency the researchers decided to pull it from consideration, Ducas said. However, that's a far cry from Mythos being able to defeat those protections altogether.\n\nStill, advanced AI models could find ways to work around cryptographic algorithms by exploiting weaknesses in how they are deployed, according to Puneet Bakshi, a researcher at the Centre for Development of Advanced Computing in India. \"AI can definitely help us in finding the loophole, which is different from attacking the fundamental basic mathematical hard problems,\" he said, meaning that security teams in the post-quantum world (assuming that ever arrives) will still have plenty to worry about even if AI models can't defeat their encryption protocols.\n\n### The rest of The Stack\n\n**Get the message**: MCP has developed into an essential building block for enterprise AI, and is probably as responsible as any model breakthrough in paving the way for agentic AI. At the first MCPCon in Europe Thursday, Anthropic's David Soria Parra — one of the co-creators of the protocol — told attendees that the next goal for the project is to improve the way end users communicate with agents through MCP.\n\n**MCP Uber alles**: MCP is also a crucial part of Uber's AI strategy, and after launching and ending the brief \"tokenmaxxing\" era the company has now figured out how to run MCP servers at scale without breaking the budget. \"Weekly active users of its AI coding tools rose 7x and weekly agent requests climbed 9.4x between February and August 2026 while Uber kept total spend roughly flat since April,\" Ed Targett reported.\n\n**Layer cake**: When companies start building a whole new class of applications, as we're seeing during the current rush to deploy AI agents, unforeseen security issues tend to proliferate. In this week's One To Watch, Noah Bovenizer talked to HiddenLayer co-founder and CEO Chris ‘Tito’ Sestito, whose company is working on updating endpoint security principles for the AI era.\n\n**Benioff bashes Brussels**: Hawaii land baron and Salesforce CEO Marc Benioff had a strong message for European AI companies and researchers Tuesday at Dreamforce: you're falling behind. He also talked about the headless software movement and debated AI policy with Sam Altman and Dario Amodei, as our report from San Francisco lays out.\n\n**Lost and gone forever**: In what appears to be a first in the twenty years of cloud infrastructure computing, AWS said this week that it does not expect it will be able to recover some customer data from its Bahrain region, which has been offline since March following Iranian drone attacks. \"The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand,\" AWS said, although it intends to return to the region next year.\n\n### Stacking up: The week ahead\n\n**Turing Fest** [__kicks off Tuesday in Edinburgh__](https://turingfest.com/?ref=thestack.technology), bringing together UK startups and investors as well as those who might be in the market for adding startups to their larger companies.\n\n**The National Cyber Summit** [__runs Tuesday through Thursday__](https://www.nationalcybersummit.com/Home?ref=thestack.technology) in Huntsville, Ala., featuring current and former government officials alongside industry security professionals with a lot to talk about in the AI era.\n\n**Oktane** [__hits Las Vegas Tuesday through Thursday__](https://www.okta.com/oktane/?ref=thestack.technology), a showcase for Okta's identity-management services, which have taken on new challenges with the rise of AI agents.\n\n**UiPath Fusion** [__will be crosstown in the desert during the same days__](https://www.uipath.com/events/fusion/agenda?ref=thestack.technology), with updates on the transition from RPA to agentic AI.\n\n**Quantum World Congress** [__starts Wednesday in College Park, Md.__](https://www.quantumworldcongress.com/?ref=thestack.technology), with presentations from industry and government leaders about the road to quantum computing.\n\n### We're also reading:\n\n__Why Software Factories Fail__**:** HumanLayer CEO Dex Horthy on AI coding agents, loop engineering, and the challenges and opportunities presented by this shift in software development strategies.\n\n[**__Agents: The new, New Kingmakers__**](https://redmonk.com/sogrady/2026/09/16/new-new-kingmakers/?ref=thestack.technology): Redmonk's Stephen O'Grady has an update (of sorts) to his seminal book on developer experience now that AI agents play an increasing role in software development.\n\n[**__Intel CEO Warns Against 95% Reliance on One Taiwan Chipmaker__**](https://en.sedaily.com/international/2026/09/16/intel-ceo-warns-of-risk-in-95-percent-reliance-on-one?ref=thestack.technology): Just too funny, coming from a company that had more than 90% of the server chip market for a decade.\n\n*Thanks for reading — see you Saturday!*", "url": "https://wpnews.pro/news/runtime-why-ai-can-t-defeat-every-security-challenge", "canonical_source": "https://www.thestack.technology/runtime-why-ai-cant-defeat-every-security-challenge/", "published_at": "2026-09-17 15:00:57+00:00", "updated_at": "2026-09-17 15:27:25.401078+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "large-language-models"], "entities": ["Anthropic", "Mythos", "HAWK", "Léo Ducas", "NIST", "Puneet Bakshi", "Centre for Development of Advanced Computing", "The Stack"], "alternates": {"html": "https://wpnews.pro/news/runtime-why-ai-can-t-defeat-every-security-challenge", "markdown": "https://wpnews.pro/news/runtime-why-ai-can-t-defeat-every-security-challenge.md", "text": "https://wpnews.pro/news/runtime-why-ai-can-t-defeat-every-security-challenge.txt", "jsonld": "https://wpnews.pro/news/runtime-why-ai-can-t-defeat-every-security-challenge.jsonld"}}