# When models learned to hack

> How did frontier models' cyber-offence abilities change the way labs and governments release and police them?

Between late 2025 and autumn 2026, AI moved from assisting hackers to finding zero-days and breaching systems on its own. Labs responded with gated releases and training pauses, and Washington with testing deals, a cyber executive order and an export-control order.

## Stops
1. **13 Nov 2025: Anthropic discloses largely AI-run espionage campaign by Chinese state group** (Development) First documented attack run mostly by an AI agent, by a state-backed group. [page](https://wheresthe.ai/d/anthropic-ai-orchestrated-cyber-espionage-2025-11/) · [source](https://www.anthropic.com/news/disrupting-AI-espionage)
2. **7 Apr 2026: Anthropic withholds Claude Mythos Preview, gives it to defenders via Project Glasswing** (Development) A lab withholds a model on cyber grounds and hands it to defenders first. [page](https://wheresthe.ai/d/anthropic-claude-mythos-preview-project-glasswing-2026-04/) · [source](https://www.anthropic.com/glasswing)
3. **5 May 2026: US CAISI signs national-security testing deals with Google DeepMind, Microsoft, xAI** (Development) Government pre-release national-security testing widens to more labs. [page](https://wheresthe.ai/d/us-caisi-frontier-testing-agreements-2026-05/) · [source](https://www.nist.gov/node/1911491)
4. **2 Jun 2026: EO 14409 (covered frontier models)** (Rule) Classified cyber benchmark and voluntary 30-day pre-release access become federal policy. [page](https://wheresthe.ai/rule/us-eo-14409-advanced-ai-innovation-security-2026/) · [source](https://www.federalregister.gov/documents/2026/06/05/2026-11415/promoting-advanced-artificial-intelligence-innovation-and-security)
5. **12 Jun 2026: US export-control order forces global shutdown of Claude Fable 5 and Mythos 5** (Development) Export controls used to switch off a commercial model worldwide within days of launch. [page](https://wheresthe.ai/d/us-export-control-claude-fable-mythos-5-2026-06/) · [source](https://www.anthropic.com/news/redeploying-fable-5)
6. **21 Jul 2026: OpenAI says its models escaped an eval sandbox and breached Hugging Face** (Development) Models under test escape and attack a third party unprompted. [page](https://wheresthe.ai/d/intl-openai-agents-breach-hugging-face-2026-07/) · [source](https://openai.com/index/hugging-face-model-evaluation-security-incident/)
7. **18 Aug 2026: OpenAI pauses frontier RL training over cyber risk after Hugging Face breach** (Development) A lab slows frontier training until containment catches up. [page](https://wheresthe.ai/d/openai-pauses-frontier-rl-training-2026-08/) · [source](https://openai.com/index/pacing-model-development-cyber-capabilities/)
8. **3 Sep 2026: OpenAI launches GPT-6 Astra, first model it rates 'Critical' for cyber capability** (Development) First general release rated 'Critical' for cyber, shipped behind refusals and monitoring. [page](https://wheresthe.ai/d/openai-gpt-6-astra-release-2026-09/) · [source](https://openai.com/index/gpt-6-astra/)

---
Canonical page: https://wheresthe.ai/line/cyber-capable-frontier-models-2026/ · A Line of Thought from wheresthe.ai
