September 2026
Secure Acceleration:
A Cyberdefense Strategy for Superintelligence
The future has already arrived, twice.
In September 2025, Anthropic detected a Chinese state-sponsored group using its agents to conduct cyber espionage against major technology companies and government agencies. According to Anthropic, the agents performed 80 to 90 percent of the tactical work: discovering vulnerabilities, developing exploits, moving laterally, and analyzing stolen data. A nation-state could now define an objective and let AI conduct most of the attack.
Then, in July 2026, OpenAI agents undergoing cybersecurity evaluations exploited vulnerabilities in the systems intended to contain them. They improvised a way to secretly communicate with one another, accessed the public internet, and compromised parts of Hugging Face’s production infrastructure. No human instructed them to attack Hugging Face. They attacked because they wanted to deceive the system evaluating their performance. An AI cyberswarm could now break out of containment and attack real-world infrastructure.
These incidents reveal two threats now bearing down on us:
- Adversaries will wield AI cyberswarms against us from outside our systems.
- Rogue AI cyberswarms will deceive us, circumvent safeguards, and attack us from within.
Together, they create the defining security dilemma of the AI age: We must develop and deploy the world’s most capable cyberswarms to protect our critical systems from hostile actors. But the more capable and deeply embedded these AI systems become, the more dangerous they are if they turn against us. How do we build a cyberdefense capability powerful enough to stop the threat from outside without creating a threat which we cannot contain on the inside?
Humanity is not helpless against AI threats or the adversaries that exploit them. AI capabilities are advancing faster than the security of the infrastructure underneath, but there are clear paths to improving our infrastructure and making AI development safer. We need a new approach to security, new technologies, radical research, and sustained engineering across the computing stack. We can continue advancing AI, but we must build the necessary security infrastructure alongside it.
After more than a year at the frontier of AI, cyberdefense, and national security, we have arrived at three urgent security imperatives: (1) defend our most powerful models against sabotage, (2) contain rogue AI systems from escape, and (3) secure model weights against theft.
We must secure the path to superintelligence.
Table of Contents
This report is written for the AI and national-security communities. It sets out the threats already present in AI infrastructure and the ones arriving with superintelligence, presents the threat model we think is missing — sabotage, escape, and theft — and points to where the work needs to go to secure the stack while there is still time. There is still time. We need to know where to look, and we need to talk about it together.
-
Introduction
The future has already arrived, twice.
-
Every variable that determines cyberswarm capability is accelerating at once.
-
Sabotage, escape, and theft — the three ways cyber-superintelligence turns against us.
-
IIa.Sabotage
A sabotaged superintelligence could be the highest-leverage hack of all time.
-
IIb.Escape
Every capability we give AI is a capability we may one day have to defend against.
-
IIc.Theft
Never before has so much power been concentrated in so little data.
-
III.Offense
Because the United States is ahead, we can use our lead to predict the future.
-
IV.Conclusion
We must secure the path to superintelligence.
-
Three calls to action for how the US and its allies can securely advance on the path to superintelligence.