Why blocking AI models won’t stop the cyber threats they create AI-powered cyberattacks are now on par with the best human hackers, according to a new analysis, but blocking access to powerful models like Anthropic's Mythos and Fable through export controls is only a temporary fix as competitors such as OpenAI and China's Z.ai release comparable models. The analysis argues that the only long-term solution is investing in defense, yet federal cuts to agencies like CISA have left AI companies like Anthropic and OpenAI to fill the gap with initiatives like Project Glasswing and Patch the Planet, which cannot singlehandedly coordinate U.S. cyber defense. Why blocking AI models won’t stop the cyber threats they create 2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional period where new technologies are pushing existing American cybersecurity infrastructure to the brink. The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge? Attempts to control access to models with powerful cybersecurity capabilities, such as the federal government’s export controls https://www.anthropic.com/news/fable-mythos-access and their subsequent revocation https://www.anthropic.com/news/redeploying-fable-5 on Anthropic’s Mythos and Fable models, can only ever be a temporary solution. As with previous generations of AI models, other companies will soon catch up and develop models with Mythos-level capabilities. OpenAI was already hot on Anthropic’s heels with its GPT-5.5 model https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities ; more recently, Chinese lab Z.ai released its open-weight GLM-5.2 model https://www.axios.com/2026/06/25/china-glm-52-open-source-hackers , which early research suggests may be on par with Anthropic and OpenAI’s latest models when it comes to cybersecurity. Controlling AI is nearly impossible when foreign companies race to build more powerful models and release them publicly, so anyone with sufficient computing power can modify them for their own purposes. The only long-term solution is to invest in defense. The problem is that defensive efforts haven’t kept up with the pace of AI progress. The federal government cut resources to key agencies like CISA and redistributed their authorities. This created a gap that AI companies have filled by taking on responsibilities that should be government-led. Some examples are Anthropic’s Project Glasswing https://www.anthropic.com/project/glasswing and OpenAI’s Patch the Planet https://openai.com/index/patch-the-planet/ initiative, which aim to shore up critical infrastructure providers and open-source software libraries. AI companies have some incentives to invest in defense, both to improve public relations and strengthen software supply chains that they also rely on—but only to a certain extent. Unlike the public sector, they are incentivized to limit liability and blowback associated with irresponsible corporate behavior, not to secure the nation or its citizens. It’s a good thing that OpenAI and Anthropic have publicly committed to improving U.S. cyber defense. However, they are only positioned to help with one part of a very large problem. AI companies shouldn’t be expected to singlehandedly coordinate U.S. cyber defense, because many of the most urgent fixes have nothing to do with AI. Right now, AI companies can use their most powerful models to find software vulnerabilities and write patches. This is undoubtedly important, but the real challenge is making sure patches actually work and deploying them to key systems without causing problems. This is especially true for critical infrastructure, which relies on systems that are fragile, understaffed, and required to run continuously. AI companies bear responsibility for cyber defense, especially given the threats their own technologies create. But this responsibility is shared with other companies and the government. Critical infrastructure owners and operators, government agencies, and corporations all need a trustworthy source of information to judge the evolving risk landscape and to outline the options to reduce that risk. Traditionally, the federal government has played the role of an information clearinghouse, receiving intelligence from both the public and private sectors and releasing guidance to benefit various stakeholders. Responding to and recovering from cyberattacks has traditionally been the government’s job. It should stay the government’s job, not become an AI company responsibility. There is no question that cyberattacks, whether powered by AI or not, will happen in the future. Leaders should strengthen our defenses by doing the following: measuring our exposure to attack, testing how systems perform under attack, and shortening recovery times. AI companies have introduced new threats and should help address them, but they can’t replace the government’s role. So far, the federal government has only reacted to AI and cyberthreats instead of planning ahead. What we need is real long-term cybersecurity strategy, not quick-fixes like blocking individual model releases. Everyone sees the threat coming—the question is whether or not we have the will to do anything about it before it’s too late. Jessica Ji is a senior research analyst at Georgetown University’s Center for Security and Emerging Technology CSET , where she works on the CyberAI Project. Andrew Lohn is a senior fellow at Georgetown University’s Center for Security and Emerging Technology CSET , where he works on the CyberAI Project.