Open-weight models just cleared another cyber bar — and that changes the risk math for irreversible data.
Anthropic’s read on https://t.co/wEaCVLrb06’s GLM-5.3 put an open-weight model nearly on par with frontier systems on cyber exploits, with safeguards that can be stripped. For shops holding genomic and other irreversible IP, the question is no longer only which SaaS chatbot employees use. It is which weights can run locally, who may load them next to crown-jewel datasets, and what evidence shows what those models were allowed to see.
Cyberbiosecurity here is custody: purpose-bound access, egress that is not “export by default,” and logs that survive a board review after a model touches patient or research genomes. Capability without that proof is a privileged pipeline, not a productivity tool.
When an open-weight model sits near irreversible IP in your environment, what evidence would you show that it never saw what it should not?
Most AI security roadmaps are procurement plans that learned the word resilience. I tore one up. What I kept will not survive a vendor demo.
You do not have an AI. You have four failure modes on one budget line.
Talkers leak, obey the wrong instruction, and the next system treats the answer as a command. Check the input. Check the output. Model output is untrusted input to the next hop.
Learners do not make the news. They drift, get poisoned in the data, and fail quietly after the person who could roll them back has left. No version, no fallback, no owner.
Actors are where the program breaks. An agent does not answer. It spends, calls, and remembers. The chain looks like automation until it is not. Default deny on tools. A circuit breaker. A human before anything irreversible. Memory you can wipe. A kill switch at 2 a.m., no ticket. Defer that and the agent already outranks you.
The fourth is already in production. Personal keys. A coding assistant on the repo. A Thursday pilot nobody closed. McKinsey in 2025: risky AI behavior in production near 80 percent. Real visibility, low teens.
Thirty days of visibility, ninety days of coverage, then a phase named continuous operations. Unfunded work. I would not run it.
Visibility is not a phase. A thirty-day inventory is a photograph. "95 percent identified" assumes a denominator you do not have. Shadow AI is that denominator. I have watched the inventory go green while an agent kept standing rights to production. Green was the spreadsheet. The rights were the risk. No owner, no data-flow map, no production.
The foundation is not a product. Identity that can tell a human from a service from an agent. Paths that do not treat an API key as a perimeter. Governance over what may be remembered. Security on the runtime, not the center of excellence. Buy the platform after this holds. Not instead.
Then the specific layer. The prompt is a data path. The supply chain includes the model and the plugins. Drift needs a version and a rollback. Agents will chain. The ugly call is rarely the first. It is the fifth, and it still looks allowed.
Operations is where the roadmap buys another console. One view where code, identity, data, and runtime meet. Put the control in the IDE, or you meet the key in the incident review.
Throw the coverage targets out. Eighty percent covered means the incident is already booked in the other twenty. Faster detection is vanity if the agent has already acted and the clock starts at the ticket. Automated response with no forbidden list causes the next incident, with your logo on it.
I would not put coverage in front of a board. Time from agent action to containment. An owner who can roll production back this week. No data-flow map, no production, or the gate is fiction. Blast radius of the most privileged agent. Unmanaged deployments: zero.
Resilience is not a quarter you arrive at. It is whether you can stop the system, say what it touched, and put it back. A roadmap that ends in a demo has a buyer. One that ends in a kill switch, a rollback, and a name has a CISO.
If this year's plan still opens with "establish visibility," you are not behind on AI. You are behind on operations.
@itsarocket@Muse@OpenAI Logs ≠ audit trail until they answer who/what/system/policy version/model/context. Shared API keys erase the identity line. Ask for the field set exportable in six months.
@infantes_adrian Creative attacks can be noisy; scoring must be boring. Bind probe set, model/agent version, technique IDs, and a deterministic judge — a signed receipt beats a slide deck.
@XavierRiveraX A BOD clock forces the patch. Board follow-through is evidence: exploitation scope, which standing identities still reach crown jewels, and what forensic artifact survives the window.
@seoscottsdale Mgmt-plane KEVs remind us privilege concentration is the risk. Same pattern as agents & research platforms: one standing path to irreversible data. Patch fast — then map who can still reach crown jewels.
@SawayaSterling Genomic labs hold irreversible identity. After an ePHI path leak, ask blast radius + standing access + what evidence survives. Sequencing/analysis = crown-jewel custody, not a vendor footnote.
@GenomicsEngland Access ≠ export control. When participant data can leave as a “result,” you need airlocks, purpose bounds, and evidence of what left — especially once AI pipelines sit on the same datasets.
7/ In genomics I protect something that doesn’t expire when a password resets. If you can’t grant, revoke, and prove what a model was allowed to see, you don’t have AI governance. You have stationery.
6/ Wrong Q: Do we have an AI policy? Right Qs: Which models/agents are sanctioned? What data was each allowed to see? Who sees tool-call telemetry? Where is eval ≠ prod? What evidence in 24h?
5/ NISTIR 8587 hardens tokens after auth — not full agent authorization. EU CRA Art. 14 since Sep 11: 24h early warning / 72h notice. Regulators want timed evidence, not a policy binder.
4/ Eval ≠ prod: Anthropic (Jul 2026) — Claude reached real orgs from a misconfigured “isolated” CTF (prompt said no internet). Google confirmed May 2026 Irregular: Gemini accessed 3 real cos; stopped; notified; no damage claimed. A prompt isn’t isolation.
3/ Team8 2026 CISO Village (n=120): ~80% report AI agents in production. Only ~26% monitor actions/tool calls. Capability without traces isn’t control.
2/ LayerX 2026 (Akamai / vendor research): 47.11% of enterprise AI conversations ran through personal identities — not corporate-managed accounts.
>14% used corporate email on freemium AI that can still train public models while looking “official.”
Policy doesn’t inventory that.