New export controls and gatekeeping by AI vendors are slowing defensive research, forcing experts to rely on local and open models.
Over several months, AI giants have been developing tested programs and strict guardrails to limit the use of their models by malicious actors. However, these limits are currently hindering the work of legitimate network defenders, as well as offensive cybersecurity professionals.
In June, the U.S. government imposed export restrictions on the widely anticipated Mythos and Fable models from Anthropic. Reports say the restrictions were aimed at preventing the use for creating and carrying out harmful cyberattacks, including attempts to bypass their security barriers.
Regardless of whether the incident was truly driven by fear of an ‘out-of-control release,’ the fact remains that Anthropic has repeatedly positioned Mythos as the so-called ‘cyber-endangerment object’ that is provided after thorough verification with strict constraints. (Subsequently, export restrictions on Fable 5 and Mythos 5 were lifted: Fable 5 returned to general access on July 1; Mythos 5 was restored only for selected American organizations under government scrutiny.)
Such access controls are not unique to Mythos. Anthropic and OpenAI offer cybersecurity researchers programs through which they can apply for verified access with fewer restrictions: OpenAI – Trusted Access for Cyber, Anthropic – Cyber Verification Program.
Impact on the research community and justified limitations
Such access regimes are widely criticized by researchers whose work involves discovering unknown vulnerabilities and finding ways to exploit them before criminals do.
I’m not entirely comfortable with these giant companies making arbitrary decisions about what is safe in the field of security, and what isn’t.
– Mark Dowd
The mentioned expert from a well-known group of security solutions noted that his work might influence how security is perceived and the development of appropriate approaches, but he is not alone in this understanding. Various offensive cybersecurity specialists spoke about how they use AI tools and how they operate with their limitations.
Requesting the use of the model with the aim of attempting to exploit a flaw is a key step in confirming that it is a real vulnerability worth fixing. If the barrier refuses to respond, defenders become less effective.
– Chris Enley
He added that the same tool can be both offensive and defensive – and their roles cannot be fully separated. Likewise, it is compared to a hammer: you cannot build a house without a hammer, but the tool can be used as a weapon.
It’s like a hammer, he continued. You can’t build a house without a hammer.
– Chris Enley
To bypass such blocks, some specialists turn to open models without strict restrictions and run them locally. Paolo Stagno from CrowdFense noted that AI companies “practically place customers in the role of children who need to be supervised” through their verification programs and restrictions.
AI companies effectively place customers as children who need to be supervised.
– Paolo Stagno
Such approaches have led some researchers to use frontier models solely for reverse-engineering analysis to avoid data leakage risks into cloud services while probing vulnerabilities. Those who work with such models emphasize that denial of access or restrictions reduce the effectiveness of their work.
I still want to own discovering the vulnerability and using it as a weapon myself, and that won’t change, even if all restrictions were lifted tomorrow.
– Giuseppe Cali
Other industry participants argue that restrictions push toward using open local models or Chinese open-source solutions such as GLM, which can be downloaded and run without checks or restrictions.
Practically, it means a lot of time is spent negotiating with the model rather than focusing on the core security program.
– Chris Thompson
Chris Thompson also noted that when using frontier models the quality of results can be inconsistent, even within the more ‘soft’ offerings from Anthropic and OpenAI. This pushes researchers to seek a balance between obtaining useful information and avoiding unpredictable model outputs.
Rather than analyzing the vulnerability and justifying its exploitability, the researcher looks for why they obtain incoherent results or why the models overly sanitize the output.
– Chris Thompson
As a result, the research community increasingly turns to Chinese open models or local versions without strict checks, which experts say may reduce oversight of tool usage in the United States and increase data leakage risks.
A massive storm is coming: defenders may lose the race in artificial intelligence due to restrictions and access controls.
– Chris Thompson
In the long run, the research community calls frontier labs to open their programs, provide responsible access, and hold those who misuse tools accountable. Otherwise, defenders may concede the edge in fighting new threats that are rapidly emerging in today’s digital environment.
In conclusion, they emphasize that a balance is needed between open safety verification and responsible use of high-tech tools. Preserving the ability of research power with minimal necessary restrictions is a critical condition for maintaining cybersecurity at a high level in the face of increasing attack tempo.
