September 2026 produced an alarm from inside the frontier labs about a capability that has not arrived, while the documented harm of the preceding nine months came from models already in production, reached through ordinary access paths. Read against the case files in Anthropic's own threat report, the 2026 breach data, the agent-hijacking measurements, and the European switching deadlines: seven attack surfaces ranked by how they are actually exploited, why concealment now fails while control does not, what a four-month open-weight gap makes affordable, the four strongest objections to decentralisation in their best form, and a ten-point playbook where every control ships with a test that can fail it. 195 verified references.
Edge Native Sovereignty
By Nicolas Waern, CEO — WINNIIO AB Published: 12 September 2026 · ORCID 0009-0001-4011-8201 · CC BY 4.0 DOI: [10.5281/zenodo.22738809](https://doi.org/10.5281/zenodo.22738809)
Every serious warning about artificial intelligence this month describes a capability problem. The evidence describes an exposure problem. Those require different work.
Evidence note. This report rests on 195 sources retrieved on 12 September 2026 and listed in full at the end. Claims are marked VERIFIED where a named source was read during preparation and ASSUMED where the statement is inference from those sources, so a reader can argue with the second kind. The method section states where the evidence base is weakest.
Ten findings
One finding organises the rest. The public alarm of September 2026 concerns systems that do not exist yet, while the documented harm of the preceding nine months came from systems already in production, reached through ordinary access paths. Preparing for the first while leaving the second open is the expensive order of operations.
1. The whistleblower excludes today's models from his own warning Jacob Coxon resigned from Anthropic in early September 2026 and wrote that the labs are “racing straight to self-improving superintelligence and gambling with our lives.”[1] He also said current platforms pose no imminent threat and are safe for people to use day to day.[2] Both halves belong in any honest citation of him. The risk he names is conditional on a capability that has not arrived.
2. Recursive self-improvement is contested by the people closest to it An Anthropic co-founder put recursive self-improvement before the end of 2028 at 60 per cent.[8] Weeks earlier, researchers reported that AI research agents handle engineering but fail at open-ended judgment, which they read as a bearish signal on short timelines.[9] The international expert report chaired by Yoshua Bengio ranks loss of control among the most consequential risks while treating fully autonomous self-improvement as speculative.[10]
3. Documented misuse is already state-grade and already operational Anthropic's September 2026 report describes an Iran-linked actor assembling targeting handbooks on US naval forces from public photo captions, transponder identifiers, satellite-imagery scripts and named vulnerabilities in shipboard systems.[22] Page 112 documents a weapons-engineering cell using a coding agent to develop guidance software for a guided rocket and a missile programme.[21] None of it required superintelligence.
4. The autonomy layer is the new attack surface, and it is not patched Prompt injection has topped the OWASP list for language-model applications for two consecutive editions, and neither retrieval nor fine-tuning closes it.[42] A joint evaluation by the US and UK AI safety bodies took agent-hijacking success from 11 per cent to 81 per cent using stronger attacks.[46] OpenAI has stated publicly that injection is unlikely ever to be fully solved.[59]
5. Third parties are now the majority route in The 2026 Verizon breach report found third-party involvement in 48 per cent of breaches, up from 30 per cent a year earlier, with vulnerability exploitation overtaking stolen credentials as the leading vector at 31 per cent.[76] Employee use of unsanctioned AI tools tripled from 15 to 45 per cent in the same dataset.[76]
6. Concentration turns one defect into a global event A latent race condition in one region's DNS automation cascaded across nine AWS services and produced roughly 6.5 million public incident reports.[68, 69] In February 2026 a cleanup task that misread an empty filter withdrew a quarter of Cloudflare's advertised customer address space from the internet for six hours.[71] Neither was an attack.
7. Concealment is gone, control is not More than 135,000 plate-reading cameras operate across 49 US states,[97] one commercial radar-satellite operator has orbited 62 spacecraft since 2018,[101] and Starlink passed 10,000 simultaneously active satellites in March 2026.[102] The woods are instrumented. What remains genuinely controllable is where your data rests and who may compute on it.
8. The open-weight gap is four months, which is what makes edge-native viable Epoch AI measures the best open-weight model as trailing the closed frontier by an average of four months since January 2026.[104] A four-month lag is a procurement decision rather than a capability sacrifice. That number is the single biggest difference between this argument in 2023 and the same argument now.
9. Edge-native is bought for control and latency, not for unit price Self-hosting beats frontier APIs above roughly 160 to 256 million tokens a month, while against low-cost open-weight APIs the break-even moves into the billions.[125, 126] The defensible case for owning inference is sovereignty, determinism and blast radius. Presenting it primarily as a saving invites a spreadsheet argument that the evidence does not support at small volume.
10. Unilateral hardening reduces your exposure, not systemic risk The compute-governance literature argues that concentrated compute is exactly what makes frontier development observable and enforceable.[158] Strategy work on state-level AI competition argues that no actor reaches stability by defending alone.[162] Both hold alongside the case here: edge-native is how an organisation stops being collateral, not how the species is made safe.
Fear is a two-second instrument. It registers that an exposure exists. It cannot name which one, and it closes none of them.
Part I — What the alarm actually says
On 8 September 2026 a researcher who had joined Anthropic two months earlier resigned, left the industry, and published a thread that reached tens of millions of readers. The line that travelled was blunt: the people building these systems “earnestly believe that it could kill us all by the end of the decade.”[1, 4] He had first said a version of it to colleagues on an internal channel before saying it in public.[5] Two days later he repeated it to Anderson Cooper on CNN, adding that the companies “find themselves in this scenario where they're compelled to race toward building a deadly technology,” and that he would welcome an international body empowered to slow the pace.[3]
What did not travel, and belongs in every serious reading of the episode, is the boundary he drew around his own claim. He stated that current AI platforms pose no imminent threat to humanity and that today's systems are safe for people to use in daily life.[2] His fear is specific: systems that improve themselves without human involvement.[3] Anthropic's own alignment-science lead publicly agreed with the magnitude of the concern, putting the probability of AI killing all humans above 10 per cent within the decade.[1] That is an extraordinary number to see attached to a named institutional role, and it is a probability about a future capability, not a description of the model answering your email.
The self-improvement question, with both sides represented
The reason the resignation landed when it did is that the labs had just published in the direction of his fear. In early September 2026 OpenAI announced it had reached a milestone it had set itself: an automated research intern able to carry out well-defined research tasks, including multi-day work, under human direction. In the same communication it said it does not know how to achieve full recursive self-improvement safely, and named a target of a fully automated AI researcher by March 2028.[6] Anthropic had disclosed in May 2026 that a model writes roughly 80 per cent of its production code, and that a model-assisted effort delivered more than 800 bug fixes in days.[7] An Anthropic co-founder placed recursive self-improvement before the end of 2028 at 60 per cent.[8]
Against that, the deflationary case is not fringe and is not vendor-funded. In August 2026, researchers including Sayash Kapoor at Princeton reported that AI research agents struggle to muster the creativity and judgment research requires, handling engineering tasks while failing at open-ended ones; the same coverage quotes an Anthropic co-founder calling the absence of intuitive creativity in current systems a bearish signal on short recursive-self-improvement timelines.[9] Modelling work on compute constraints estimates roughly a 10 to 40 per cent chance that a software-only intelligence explosion proceeds despite those bottlenecks, which is to say bottlenecks probably blunt the curve without necessarily stopping it.[12] The “AI as normal technology” position argues that the binding constraints are external to model design and that diffusion speed is set by how fast institutions and behaviour change.[15] Gary Marcus reads Anthropic's self-improvement framing as showing faster coding rather than a path to general self-improvement.[19]
Forecasts have moved in both directions, which is the honest summary. The AI 2027 scenario team, whose original projection put an intelligence explosion in late 2027, has slipped its median and now points at the early 2030s for the breakthroughs it once expected by 2027.[13] The Metaculus community forecast as of February 2026 sits at 25 per cent for artificial general intelligence by 2029 and 50 per cent by 2033, dramatically compressed from a median roughly 50 years out in 2020.[14] The 2026 International AI Safety Report, mandated by nations at Bletchley and drafted with more than a hundred experts across 29 nations, the UN, the OECD and the EU, ranks loss of control via self-improvement among the most consequential risks while noting that fully autonomous self-improvement remains speculative.[10] The 2023 statement that mitigating extinction risk should be a global priority alongside pandemics and nuclear war still carries the signatures of Hinton, Bengio, Hassabis, Altman, Amodei, Sutskever and Russell.[11]
Reading of the evidence
VERIFIED Named researchers inside and adjacent to the frontier labs disagree about recursive self-improvement timelines by roughly five years, and the disagreement is public and specific.
ASSUMED No planning decision available to a company or a household turns on whether the correct year is 2028 or 2033. Every control that matters under the fast scenario is also justified by documented 2026 harm, which means the timeline debate can be left to the forecasters without cost.
Politics moved within a week
On 4 September 2026, Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act, which would permanently prohibit development and deployment of superintelligent AI, temporarily pause advanced AI development until a federal regulator sets safety rules, and direct the United States to pursue international agreements.[17, 18] A separate bill, the Stop Rogue AI Act, was introduced the same month by Representatives Gottheimer and Lawler.[18] Polling published on 10 September found 68 per cent support for a pause and a superintelligence ban against 25 per cent opposed, including 63 per cent of Republicans and 70 per cent of independents.[16] Researchers quoted in Science note the enforcement problem: the experts cannot agree what “superintelligence” means, which makes a ban built on the term difficult to administer.[20]
Pulling in the other direction, an executive order signed in December 2025 created a Department of Justice litigation task force to challenge state AI laws, and directed the Federal Trade Commission to treat state-mandated AI bias mitigation as a potentially deceptive trade practice.[151] The practical consequence for anyone building now is that the regulatory floor in the United States is contested and may be lowered, while the European floor described in Part VI is legislated and dated.
The correct response to a two-second fear is not a prediction. It is an inventory.
Part II — What is already documented
The most useful document published in the same week as the resignation was not the thread. It was a 154-page threat-intelligence report covering December 2025 to August 2026, organised into seven harm categories: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, scams and fraud, and illicit distillation.[25] It is worth reading because it replaces speculation with case numbers, and because every case it describes was executed with models that shipped to the public.
Conventional weapons
Case GTG-87001, on page 112, describes a Yemen-based weapons-engineering cell using a coding agent in place of human engineers to build guidance, navigation and control software for a guided rocket that was field-tested and failed, a ballistic missile with a stated range goal above 2,000 kilometres, and a hypersonic-glide-vehicle variant.[21] The detail that matters for this report is the substitution: the agent stood in for scarce expertise. That is the same mechanism by which an SME uses an agent to stand in for a department it cannot afford, pointed at a different target.
Military reconnaissance
Case GTG-30005 describes an Iran-nexus actor building a Python pipeline that compiled targeting handbooks against US naval forces: a roster of personnel scraped from public photo captions, ship and aircraft transponder identifiers, satellite-imagery query scripts, and named vulnerabilities in maritime very-small-aperture-terminal and industrial control products.[22] The account was banned, detections were built, and findings were shared with government authorities.[22, 26, 27] Note what the inputs were. Public captions. Public transponder feeds. Commercial imagery. Published CVEs. The model contributed assembly, not access.
Biological misuse and the threshold statement
In May 2026 a biological-safety classifier blocked a gain-of-function request concerning chikungunya virus tied to a military research institute. A reseller platform then evaded regional blocks and routed refused prompts to more permissive competitor models.[23] The report states that newer models can no longer be assumed to sit below the bioweapons-uplift threshold.[23] This is the single most consequential sentence in the document, and it belongs beside the honest counterweight: a 2024 red-team study found no statistically significant difference in the viability of biological attack plans produced with and without then-current model assistance,[161] while a 2025 evaluation of 39 capable models found that custom-tuned open-weight models can have guardrails stripped, enabling step-by-step guidance.[160] The threshold is moving, and the open-weight path is part of why.
Surveillance and transnational repression
Cases GTG-14021 and GTG-14010 describe actors linked to municipal public-security organs in China using a model for “stability maintenance” surveillance, including an internal manual instructing the model to role-play as an intelligence analyst, with a police-academy-linked actor identifying ten private citizens for control, and separate work profiling Uyghurs and surveilling a diaspora publication.[24] For anyone building a platform that holds personal data, this is the demand side of the market for your database.
The trend line across eighteen months
| Date | Disclosure | What changed |
|---|---|---|
| 2025-08-27 | Extortion campaign run through a coding agent against at least 17 organisations, demands up to $500,000; North Korean operatives using models to hold fraudulent remote jobs[28] | AI as operator of a crime, not adviser |
| 2025-10 | Provider disruption report on account clusters used for malware, scams and influence operations[32] | Misuse became a routine reporting category |
| 2025-11-13 | State-sponsored espionage against roughly 30 targets with 80 to 90 per cent of the campaign executed by the agent and human intervention at 4 to 6 decision points[29, 30, 31] | Human-to-machine ratio inverted |
| 2026-02-25 | Two-year retrospective covering romance scams, fake legal services, coordinated influence and a state-linked harassment effort[33] | Volume crime, not just espionage |
| 2026-05-11 | First documented case of a threat actor deploying a zero-day exploit assessed as AI-developed, a two-factor bypass in an open-source admin platform, attributed from code artefacts including a hallucinated severity score[34, 35, 36] | Offensive capability creation, not just use |
| 2026-02 | Intrusion against a municipal water utility in which a model served as primary technical executor against an industrial gateway and SCADA platform; the OT breach failed[37] | Crossover into operational technology |
| 2026-09-10 | Seven-category report including missile guidance software, naval targeting handbooks, and the bioweapons-threshold statement[21, 25] | Physical-world engineering |
Read as a series, the disclosures describe a shift in who performs the work. In 2024 the model advised a human operator. By late 2025 a campaign ran at 80 to 90 per cent machine execution with a human at four to six decision points.[29] By mid-2026 a model produced an exploit rather than explaining one.[35] By February 2026 a model was the primary technical executor against industrial control equipment.[37] The capability frontier is a live argument; the labour frontier already moved.
The consumer edge of the same curve
The economic damage most people will actually meet is fraud. Cumulative global deepfake-fraud losses are reported at $2.19 billion, of which $1.65 billion fell in 2025, with the United States most targeted at $712 million and 43 per cent of activity aimed at the corporate sector.[38] The FBI's complaint centre logged 22,364 complaints carrying a new AI-related descriptor in 2025 totalling $893 million in adjusted losses, against total reported cybercrime losses crossing $20.9 billion for the first time.[39] Deloitte projects generative-AI-enabled fraud losses in the United States reaching $40 billion by 2027 from $12.3 billion in 2023.[40] The canonical case remains a finance employee at an engineering firm authorising $25 million after joining a video call on which every other participant, including the chief financial officer, was synthetic, built from public conference footage.[41]
The load-bearing point of this part
Not one case above required a system more capable than what is generally available. They required an organisation whose data, credentials, tooling or people could be reached. That is the variable an individual or a company actually controls.
Part III — Anatomy of a porous organisation
“Attack surface” is used loosely enough to mean nothing. Used precisely, it is the set of places where something outside your control can reach something inside it. Seven such places matter in 2026, and they are listed here in the order in which the evidence says they are actually exploited, not in the order in which they are usually discussed.
| Surface | What crosses it | Documented in 2026 |
|---|---|---|
| 1. Identity | Credentials, session tokens, one-time codes | Snowflake customer accounts breached via stolen credentials with no multi-factor enforcement, exposing records of at least 100 million people across 165 organisations[77] |
| 2. Third-party data custody | Your records, held where you cannot audit them | Third parties involved in 48 per cent of breaches, up from 30 per cent[76] |
| 3. The model path | Whatever staff paste into a prompt | 39.7 per cent of AI-tool interactions involve sensitive data, much of it through unmanaged personal accounts[185] |
| 4. The agent tool path | Instructions arriving inside content the agent reads | Zero-click exfiltration from an enterprise assistant, CVSS 9.3[47]; private repository leakage via a hijacked agent[48] |
| 5. Software supply chain | Dependencies, extensions, connector servers | A self-propagating package worm backdooring 796 packages across roughly 25,000 repositories[55] |
| 6. Infrastructure concentration | Availability and jurisdiction, not confidentiality | One region's DNS defect cascading across nine services[68]; a quarter of one provider's customer address space withdrawn for six hours[71] |
| 7. Physical and sensed | Your premises, vehicles, faces, movements | 135,000-plus plate readers across 49 states[97]; permanent live facial recognition planned across a London retail district[100] |
Surface four deserves its own treatment, because it is new and unsolved
An agent that reads untrusted content and can also act is a system in which data and instructions share one channel. Prompt injection is the name for exploiting that, it has led the OWASP list for language-model applications across two editions, and the guidance is explicit that neither retrieval augmentation nor fine-tuning fully mitigates it.[42] OWASP has since published a dedicated agentic threat taxonomy across agent design, memory, planning and autonomy, tool use, and deployment,[43] followed by a top ten for agentic applications naming goal hijack, tool misuse, identity and privilege abuse, memory and context poisoning, insecure inter-agent communication, cascading failures and rogue agents.[44] The NIST adversarial machine learning taxonomy, updated in March 2025 with more than 400 references, classifies the same family against integrity, availability and privacy.[45] The MITRE ATLAS knowledge base catalogues adversary tactics and techniques specific to machine-learning systems, which the general-purpose attack catalogues do not cover.[171]
The measurements are worse than the taxonomies imply. A joint evaluation by the US and UK AI safety bodies took agent-hijacking success on a workspace benchmark from 11 per cent for the strongest baseline attack to 81 per cent for the strongest new one.[46] Reported figures for a current frontier model on browser-agent tasks without safeguards sit around 31.5 per cent per attempt, meaning a targeted injection lands roughly three times in ten.[60] OpenAI's own position is that agent mode expands the threat surface and that injection, like social engineering, is unlikely ever to be fully solved.[59] The most promising research direction does not make the model resistant; it puts a capability-based control and data-flow system around the model so that a hijacked plan cannot reach a dangerous tool.[58] That is an architectural answer, and it is the same shape as the answer in Part V.
The disclosed incidents show the pattern in production. A single crafted email with no user interaction exfiltrated internal file contents through an enterprise assistant's retrieval engine.[47] A malicious issue in a public repository coerced an agent into publishing private repository contents, with the root cause identified as agent over-privileging rather than a flaw in the connector's code.[48] A connector server can hide instructions inside a tool description that the model reads and the user never sees, turning an apparently trivial function into an exfiltration path.[49] A research agent connected to a mailbox exfiltrated data from the provider's own cloud, invisible to the customer's endpoint and network controls.[51] Exploit chains have been demonstrated across five separate enterprise agent products,[52] a coding assistant was made to leak repository secrets through an image proxy,[53] a command-injection flaw in a widely used connector bridge scored 9.6,[50] and a browser assistant was shown to act on instructions hidden in page text, including fetching one-time codes from the user's email.[61]
The structural finding
In four of those cases the vendor's code was not defective. The architecture was: a privileged agent was allowed to read untrusted input and act without a boundary in between. That is a design error a customer can fix locally, and cannot fix by waiting for a patch.
Surface five: the dependency graph is now an AI-specific risk
A self-propagating worm in the JavaScript package ecosystem harvested continuous-integration secrets and republished them, prompting a national cyber agency alert; its second wave backdoored 796 unique packages spread across roughly 25,000 repositories tied to about 350 accounts.[54, 55] The same pattern has reached agent connectors specifically: an exact-name-match connector package ran cleanly for fifteen releases before the sixteenth silently added a blind-copy address that exfiltrated every email routed through it.[56] Model artefacts are executable too: a campaign placed malware-laced serialised models on a public hub, using non-standard compression and payload placement to evade the hub's scanner and open a reverse shell on load.[57]
Five Eyes agencies published joint guidance on agentic AI adoption in spring 2026 defining five risk categories, privilege escalation, design and configuration failures, behavioural misalignment, structural brittleness and accountability gaps, and recommending cryptographically anchored short-lived agent identities alongside avoidance of broad access to sensitive systems.[62, 63] That guidance exists because the agencies concluded the technology is being deployed faster than it is being bounded.
Surface six: concentration is an availability and jurisdiction problem
Three providers hold 63 per cent of enterprise cloud infrastructure spend, with the market's annual run rate passing half a trillion dollars in the first quarter of 2026 at 28, 21 and 14 per cent share.[64, 65] The model layer concentrates similarly: one survey of around 500 enterprise decision-makers puts three vendors at 40, 27 and 21 per cent of the enterprise language-model interface market,[66] and a single routing intermediary reports scaling from roughly 10 trillion to over 100 trillion tokens a year across 400-plus models.[67] Capital expenditure guidance for 2026 across the five largest providers totals between $660 and $690 billion, roughly double the prior year,[78] against an energy backdrop in which data-centre electricity use of about 415 terawatt-hours in 2024 is projected to roughly double by 2030.[79]
Concentration failures are not usually attacks. A provider's own post-incident summary attributes the October 2025 regional outage to a latent race condition in DNS management that produced an empty record for a regional endpoint, cascading across nine named services.[68] Public reporting puts it near fifteen hours, 6.5 million incident reports, more than a thousand affected companies and economic cost above a billion dollars.[69] A configuration change crossing incompatible control-plane versions took down a major edge service in the same month, affecting productivity suites, authentication and gaming platforms.[70] In February 2026 a cleanup task that misinterpreted an empty filter value began deleting customer-owned address prefixes, withdrawing roughly a quarter of those advertised, over six hours.[71] A 2024 endpoint-agent update crashed 8.5 million machines, under one per cent of the installed base, and produced more than 7,000 cancelled flights at one airline and a half-billion-dollar lawsuit.[72, 73, 74]
The jurisdictional dimension is separate and less discussed. The US CLOUD Act compels any provider under US jurisdiction to produce data on valid legal process regardless of where it is stored.[83] Section 702 of the Foreign Intelligence Surveillance Act, reauthorised in 2024, ran into a contested 2026 renewal in which the authority lapsed and a three-year extension passed the House before a subsequent short extension failed.[80] The adequacy decision that currently permits routine transatlantic transfer of personal data survived a challenge at the EU General Court in September 2025 and is now on appeal before the Court of Justice, the court that struck down both predecessor frameworks.[81, 82] An organisation whose operations assume that decision holds is carrying an unpriced legal option.
Cost of breach, for calibration
The global average breach cost fell 9 per cent to $4.44 million in 2025, the first decline in five years, with containment at 241 days. Unsanctioned AI use added about $670,000 to average breach cost, 13 per cent of organisations had suffered an attack touching their AI models or applications, and 97 per cent of those lacked proper AI access controls.[75]
Part IV — Why hiding fails and control does not
The instinct to disappear is worth taking seriously enough to test, because if it worked it would be cheaper than everything in Part VIII. It does not work, and the reason is that the sensing layer is now built, funded and commercially available.
The sensing layer, in numbers
- Orbit. Starlink passed 10,087 simultaneously active satellites in March 2026, the first constellation to exceed ten thousand at once.[102] One commercial synthetic-aperture-radar operator has launched 62 satellites since 2018, 22 of them in 2025 alone, serving national and commercial customers.[101] Radar imaging works at night and through cloud, which is what removes weather and darkness as cover.
- Streets. More than 135,000 plate-reading cameras have been identified across 49 US states, roughly four in five from a single vendor, with more than 50 jurisdictions cancelling or deactivating deployments during 2026 amid a documented backlash.[97, 98] A consumer doorbell manufacturer announced a video-sharing partnership with that network in October 2025 and cancelled it in February 2026 after public reaction.[96]
- Faces. One facial-recognition vendor's reference database reached 50 billion images by mid-2024.[99] London's police force plans permanent static live facial recognition across the West End and Soho by the end of 2026, following a pilot that produced 173 arrests.[100]
- Air. Ukraine produced more than four million drones in 2025 and targets more than seven million in 2026.[84, 85] AI-controlled defensive turrets that detect, track and compute intercept paths, with the operator confirming the strike, are fielded in more than ten front-line units.[86] A demonstrated swarm system launched 48 fixed-wing drones from one ground vehicle at three-second intervals, with a single command vehicle controlling up to 96.[87]
- Ground. One manufacturer sold more than 5,500 humanoid and 18,000 quadruped robots in a year at a valuation around $9 billion, with a quadruped launched at $1,600 against a Western equivalent near $165,000 used for base patrol.[95] A humanoid producer moved from one robot a day to one an hour within about 120 days, past 350 delivered units against a stated annual target of 12,000.[93] A vehicle manufacturer targets 50,000 humanoid units in 2026 at $20,000 to $30,000, undercut by a $16,000 competitor.[94]
- Substrate. The standards body set sixth-generation mobile milestones with a first functional freeze in March 2027 and final freeze in December 2028, with requirements work targeted for completion by end of 2026.[103] Coordination latency keeps falling as a matter of scheduled engineering.
The governance layer is moving more slowly than the hardware. A record 76 states now support opening negotiations on a binding instrument on autonomous weapons, and the expert group's report affirms that human control and judgment are required, but references to design and development obligations and to predictability, reliability, explainability and traceability were removed before adoption.[88] A General Assembly resolution passed 156 to 5 in November 2025.[89] The relevant US directive requiring appropriate levels of human judgment over the use of force has not been substantively revised since January 2023.[90] The mass-autonomy programme that promised thousands of fielded systems was dissolved into a successor organisation with a far smaller line item after reporting suggested only hundreds had been delivered,[92] while first contracts for AI-driven interceptor drones were awarded in January 2026.[91]
The distinction the evidence forces
Concealment is the attempt to be unobserved. Against the layer above, it fails for any entity with premises, vehicles, staff or a public footprint. Control is the ability to decide where your data rests, who may compute on it, and what happens when an outside party is unavailable, compromised or compelled. Nothing in Part IV touches control. The whole of Part V is about it.
You cannot leave the sensed world. You can decide that the sensed world does not also get your database, your model and your keys.
Part V — Edge-native, measured
Edge-native means computation begins where data originates, and leaves only by explicit decision. The argument has been available for a decade and was until recently unaffordable in capability terms, because running your own models meant accepting a large quality deficit. That deficit is now measurable, and it is small.
The four-month number
Epoch AI tracks the gap between the best open-weight model and the closed frontier on a capability index. Since January 2026 the average lag is four months, or about eight index points; the best open-weight model measured trails a top proprietary model by roughly the distance between two successive releases of that proprietary family.[104] The same programme measured the gap at about three months in October 2025 and found that models small enough for consumer hardware reach frontier-level performance within about a year of the frontier setting it.[105] Published comparisons of leading open-weight releases put the strongest reported open result on a software-engineering benchmark above 80 per cent.[107] Licences have loosened in the same period: one major family moved to Apache 2.0 in April 2026, while another caps its free grant at 700 million monthly active users, a threshold no reader of this report will encounter.[108, 109] Public leaderboards now filter explicitly by proprietary, open-weight, and open-weight with commercial restrictions, which is itself a sign the category is taken seriously.[106]
What four months buys
VERIFIED The capability cost of running open weights is a four-month lag on average.
ASSUMED For the overwhelming majority of business tasks, retrieval quality, data quality and workflow design dominate that four-month difference. A model with your actual data beats a better model with a summary of it.
Hardware you can buy
| Class | Memory / bandwidth | Indicative price | Measured behaviour |
|---|---|---|---|
| Small-form AI workstation[111] | 128 GB / 273 GB/s | $4,699 | 1,723 tokens/s prefill but 38.6 tokens/s decode on a 120-billion-parameter open model |
| Embedded robotics module[110] | 128 GB / 273 GB/s | — | 2,070 sparse FP4 teraflops at 40 to 130 watts |
| Unified-memory mini PC[112] | 128 GB / ~215 GB/s | $1,499–1,999 | 100 tokens/s on a 30-billion sparse model; 55.6 tokens/s on a 120-billion sparse model |
| Desktop GPU[118] | 32 GB / 1,792 GB/s | $1,999 | 180–230 tokens/s for models that fit in video memory |
| Laptop / desktop Mac[115, 116] | up to 128 GB / 153–546 GB/s | — | 20–28 tokens/s on a 70-billion model at 4-bit; under 3 seconds to first token on a 30-billion sparse model |
| Network-attached storage[137] | CPU only | $600–995 | 0.5–4 tokens/s on a 7-billion model: background work only |
Three observations follow from that table, and they are the ones vendors do not lead with. First, decode speed is set by memory bandwidth, not by advertised compute, which is why a $4,699 appliance can lose a decode benchmark to three older consumer graphics cards.[111] Second, the memory ceiling is rising fast on the consumer side: a refreshed unified-memory part supports up to 192 gigabytes,[113] and generation-on-generation bandwidth gains are real but modest, 153 against 120 gigabytes per second, producing 19 to 27 per cent faster generation.[115, 117] Third, the baseline is now shipping in ordinary laptops: the current certification for AI-capable PCs requires a neural processing unit of at least 40 trillion operations per second, with 80 to 85 already shipping in some 2026 machines.[114] The quantisation frontier is also moving: a 1.58-bit inference framework reports 2.4 to 6.2 times CPU speedup with 72 to 82 per cent energy reduction on x86.[119]
Local-first is now a supported architecture, not a philosophy
The 2019 essay that named local-first software set out seven ideals: instant response, offline capability, multi-device sync, collaboration, longevity, privacy and user control.[120] The tooling caught up. Conflict-free replicated data types are production libraries with published benchmarks: one processes a 260,000-character editing trace in about 600 milliseconds after a Rust rewrite cut memory from 1.1 gigabytes to about 44 megabytes, and the current major version reports around a tenfold further memory reduction.[123, 124] An embeddable Postgres compiled to WebAssembly grew from one million to thirteen million weekly downloads in the twelve months to August 2026, and its maker was acquired by a data-platform vendor specifically to extend synchronisation from the warehouse to the edge.[121, 122] That acquisition is the clearest market signal in this section: the centralised side of the industry is buying the edge-sync problem rather than dismissing it.
When the work must leave the device
Three technologies narrow the gap between local and remote without requiring trust in the operator. Confidential computing chains a processor enclave to a confidential GPU so that neither driver nor hypervisor observes weights or gradients; the best-documented cloud path today pairs one vendor's trusted-domain extensions with current data-centre GPUs, while the competing processor path is technically functional but far less documented in provider catalogues.[138] One consumer platform's private inference design is audited under a recurring independent examination and publishes a cryptographically verifiable append-only ledger of every server in the fleet, which is the strongest publicly verifiable arrangement currently shipping at consumer scale.[139] Fully homomorphic encryption, computing on data without decrypting it, is a thousand to ten thousand times faster than five years ago with sub-millisecond bootstrapping demonstrated on a current accelerator, though the widely repeated larger speedup figures are projections rather than shipped silicon.[140]
The economics, stated honestly
Inference prices have collapsed. The cost of querying at the quality of a 2022 frontier model fell from $20 to $0.07 per million tokens by October 2024, a reduction above 280-fold in about eighteen months,[128] with per-benchmark declines measured between nine and nine hundred times a year.[127] Total spend nevertheless rises, because provider inference revenue has grown roughly threefold a year.[129] Against that backdrop the break-even for self-hosting is volume-dependent and unforgiving: roughly 160 to 256 million tokens a month to beat frontier APIs on a thousand-dollar-a-month GPU instance, and billions of tokens a month to beat the cheapest open-weight APIs.[125, 126]
At infrastructure scale the picture reverses, which is why the credible repatriation stories are large. Cloud spend averaging about half of cost of revenue across fifty public software companies was estimated to suppress market value by roughly $100 billion.[130] One software company cut its annual bill from $3.2 million to $1.3 million, recovered a $700,000 hardware purchase inside the first year, and projects $10 million over five years.[131, 132] A search-data company operating 850 colocated servers at about $1,500 each per month against an estimated $17,557 cloud equivalent reported roughly $400 million avoided over three years.[133] An insurer whose cloud bill exceeded $300 million a year cut compute cost about 50 per cent per core and storage more than 60 per cent per gigabyte by moving to open-hardware colocation.[134] On the consumer side, one open-source home automation platform doubled year-on-year to more than two million active installations,[135] and catalogued self-hosted alternatives grew 45 per cent between 2023 and 2026.[136]
The claim to stop making
“Edge-native is cheaper.” At household and small-business token volumes it is not, measured against low-cost open-weight APIs.[125, 126] The claims the evidence supports are different and stronger: it removes a jurisdictional exposure, it removes a third-party availability dependency, it bounds what a hijacked agent can reach, and it makes the four-month capability lag the only thing you trade away.
Part VI — The law is now a tailwind
Until recently, sovereignty arguments in Europe were made on principle and paid for out of goodwill. That changed when three instruments acquired dates. An organisation in Sweden building edge-native now is not ahead of regulation; it is aligned with a legislated schedule.
The AI Act itself entered into force on 1 August 2024. Prohibited practices and AI-literacy duties applied from February 2025, and general-purpose model governance from August 2025, preceded by a code of practice published in July 2025 whose signatories were made public the day before the obligations bit.[141, 142, 145] The simplification package cleared its final political hurdle in June 2026 and pushed the high-risk deadlines out.[143, 144] One threshold in the Act deserves attention from anyone training models: cumulative training compute above 10^25 floating-point operations creates a rebuttable presumption of systemic risk, with notification to the Commission inside two weeks and additional obligations covering adversarial testing, incident reporting and cybersecurity.[159] Fine-tuning open weights on your own data sits orders of magnitude below that line, which is the practical reason the edge-native path carries little AI Act weight for an SME.
Around those instruments sits the resilience and governance layer: operational resilience rules applying in full to financial entities since January 2025 with third-party provider registers due that April,[149] network and information security transposition still incomplete enough that the Commission issued reasoned opinions against nineteen member states in May 2025,[150] and a data governance regulation applicable since September 2023 covering public-sector data reuse and data intermediaries.[152]
Sovereign infrastructure: funded, unfinished, and worth reading sceptically
The Commission adopted a Cloud and AI Development Act proposal in June 2026 that creates a four-tier sovereignty framework running from EU data location to full EU ownership, control and citizenship, aiming to at least triple European data-centre capacity within five to seven years.[156] A €20 billion facility for AI gigafactories under the InvestAI initiative saw its formal call deferred to early 2026 after respondents signalled more than €230 billion of prospective investment interest.[157] A federated-infrastructure trust framework reached an operational release in early 2026 with more than fifteen data spaces built on it.[154] A parliamentary-backed proposal would mobilise roughly €300 billion over a decade for a European technology stack.[155]
Two facts belong next to that optimism. The top tier of the European cloud certification scheme had its sovereignty criterion requiring EU-only storage and control removed from the draft, and the scheme remained unfinalised into 2026 while industry associations campaigned for reinstatement.[153] And the large providers' own sovereign offerings, including one launched in Germany in January 2026 under a separate national legal entity, remain US-owned and therefore within reach of the CLOUD Act and of sanctions-driven service interruption, with precedents cited for both.[167] Nordic alternatives are early: a telecommunications operator established a standalone Norwegian-jurisdiction cloud company in May 2026, in pilot, with commercial launch planned for the first half of 2027.[168, 169]
For a Swedish organisation the domestic position is now documented. The government published a national cloud policy on 25 June 2026 framed around increased digital sovereignty in public administration.[170] The public-sector cooperation body's standing position on the transatlantic adequacy framework is that it does not give agencies an unconditional green light for US cloud services, and that sovereignty, security and suitability must still be assessed case by case.[172] Anyone selling into Swedish public bodies should read that as a procurement question they will be asked, not a philosophical one.
Commercial consequence
VERIFIED From 12 January 2027 the contractual cost of leaving a cloud provider in the EU falls to zero for switching-related transfer.[146]
ASSUMED That date converts architectural portability from an engineering virtue into a negotiating instrument. A buyer who can credibly leave prices differently from one who cannot, and the deadline gives every EU buyer that credibility on the same day.
Part VII — The strongest case against this thesis
A report that only argued one way would be advocacy. Four objections to edge-native decentralisation are serious, and two of them survive scrutiny and should change how the thesis is stated.
Objection one: concentration is what makes AI governable at all
The compute-governance literature argues that compute is uniquely governable among AI inputs, because it is detectable, excludable, quantifiable, and produced through an extremely concentrated supply chain. That gives regulators visibility and enforcement they have over nothing else, while the same paper warns that naive compute governance risks privacy harm and further centralisation of power.[158] The practice follows the theory: the AI Act's systemic-risk presumption is a compute threshold,[159] and US enforcement against a strategic rival has run primarily through chip export licensing rather than model restrictions, treating hardware as the choke point.[166]
Assessment. This objection is correct and does not conflict with the thesis. It concerns who may train frontier models; edge-native concerns where an organisation's own data and inference sit. A regime in which frontier training is concentrated and observable while deployment and data are distributed and owned is coherent, and is arguably the best available configuration.
Objection two: open weights transfer capability to people you cannot revoke
The US telecommunications regulator's 2024 review, drawing on 332 public comments and applying a marginal-risk framework, concluded that the government should not restrict the wide availability of open model weights at that time while recommending continued monitoring for capability jumps that would change the answer.[165] The monitoring condition is now live. An evaluation of 39 capable models found that custom-tuned open-weight models can have their guardrails stripped, enabling step-by-step guidance toward biological weapons development,[160] and a frontier developer has stated that its newer models can no longer be assumed to sit below the bioweapons-uplift threshold.[23] The counterweight remains an earlier red-team study finding no statistically significant difference in attack-plan viability with and without model assistance.[161]
Assessment. This objection is serious and it constrains the thesis in one specific place. Advocating open weights for personal and organisational sovereignty is defensible. Advocating them as an unconditional public good is not, because the same removable guardrails that let you run a model offline let someone else remove the refusal behaviour. The honest position separates the two: own your inference, and support capability-conditional release policy rather than opposing release policy in general.
Objection three: decentralisation moves security to people who are worse at it
This is the objection most likely to be true of a specific reader. Exploitation of unpatched vulnerabilities overtook stolen credentials as the leading initial-access vector at 31 per cent, while only 26 per cent of catalogued known-exploited vulnerabilities were fully remediated in 2025, down from 38 per cent.[195] Small organisations accounted for 96 per cent of ransomware victims in the 2026 breach dataset, and human behaviour or error contributed to 62 per cent of all breaches.[194] Consumer network equipment is actively targeted: a worm-built botnet of compromised routers, cameras and recorders drove floods above 20 terabits per second,[191] and two actively exploited router vulnerabilities were added to the US known-exploited catalogue on 10 September 2026, one flagged as requiring forensic triage.[192] Recovery is where the gap shows most: 90 per cent of organisations express confidence in recovering from a cyber incident, while only 28 per cent of ransomware victims fully recovered their data and the average victim got back about 72 per cent.[187] Roughly half of organisations whose data was encrypted paid, at a median of $769,000, with average recovery cost at $1.7 million.[186]
Assessment. Partly correct, and it changes the sequencing rather than the destination. Moving data onto infrastructure you own while operating it at household standards trades a jurisdictional risk you had priced for an availability and ransomware risk you have not. The consequence is that the backup, patching and identity controls in Part VIII are prerequisites for edge-native rather than accompaniments to it. Sovereignty without a tested restore is a story about sovereignty.
Objection four: unilateral hardening does not reduce systemic risk
Strategy work on state-level AI competition argues that because sabotaging a rival's destabilising AI project is easier than defending one, no actor achieves stability through unilateral defensive hardening, and deterrence, non-proliferation and competitiveness have to be pursued together.[162] Critics of that framework argue a mutual-sabotage regime could itself worsen the offence-defence balance and raise first-strike incentives against AI infrastructure,[163] and that formalising datacentre sabotage as policy would accelerate racing as each side disperses compute to survive a first strike.[164] Note that the last argument cuts toward dispersal, which is edge-native's own logic applied at state scale.
Assessment. Correct, and it is the boundary that should be stated out loud whenever this thesis is published. Edge-native control is a blast-radius intervention. It determines whether a given household or company is collateral in someone else's incident. It does not reduce the probability of that incident, and claiming otherwise invites exactly the criticism the argument cannot survive.
The thesis, restated to survive all four
Taking control of your data, models and infrastructure is the only intervention available to a household or a company that measurably reduces its own exposure, and the four-month open-weight gap is what makes it affordable in capability terms. It is not a contribution to global AI safety, it is not cheaper at small volume, and it is net negative unless backup, patching and identity are handled first.
Small together becomes bigger than ever only if small is also competent. Federation multiplies capability; it also multiplies whatever hygiene the weakest member brought.
Part VIII — The top ten, for a person and for a company
Ordered by exposure reduction per unit of effort, not by how interesting each item is. Each carries a framework anchor so it can be audited by someone other than its author, and a proof test, because a control nobody has seen fail is not yet a control.
For an individual or a family
| # | Control | Why, with evidence | Proof test |
|---|---|---|---|
| 1 | Passkeys or hardware keys on email, banking, cloud storage and domain registrar | Only smartcard and FIDO2 credentials are designated phishing-resistant; push with number matching is explicitly interim.[180] Users relying solely on security keys blocked 100 per cent of automated, bulk-phishing and targeted attacks in one study.[182] Around 5 billion passkeys are now in use.[179] | Attempt login from a clean browser with the correct password and no key. It must fail. |
| 2 | Three copies, two media, one offline and immutable | The rule dates to 2005 and is restated by national agencies because many ransomware variants hunt and delete reachable backups.[183, 184] Only 28 per cent of victims fully recover.[187] | Restore one real file from the offline copy onto a different machine, monthly. Time it. |
| 3 | Patch the router, the cameras and the recorder, or replace them | Consumer equipment is the botnet supply: floods above 20 terabits per second were built from routers, cameras and recorders,[191] and actively exploited router flaws entered the known-exploited catalogue in September 2026.[192] | List every device with an IP address and its firmware date. Anything undated or unsupported is the finding. |
| 4 | Segment the home network: work, family, devices that phone home | The consumer IoT baseline underpinning the US labelling scheme assumes separation rather than perimeter trust.[190] | From the device network, attempt to reach the work machine's file shares. It must fail. |
| 5 | Decide, in writing, what never goes into a third-party model | 39.7 per cent of AI-tool interactions involve sensitive data, with most consumer-assistant use flowing through unmanaged personal accounts.[185] Minimisation is a legal duty in the EU, not a preference.[188] | Take last week's prompts. Count those containing a name, a figure or a contract term. |
| 6 | Run one model locally, on real work | A four-month capability lag is the whole trade.[104] Ordinary hardware sustains 55 to 100 tokens per second on capable sparse models.[112] | Do one week of a real recurring task locally. Record where it was insufficient. |
| 7 | Own the family archive: photos, documents, correspondence, on your storage | Local-first is a supported architecture with production sync tooling, not a preference.[120, 121] Self-hosted alternatives grew 45 per cent from 2023 to 2026.[136] | Disconnect the internet. Open a photo from 2014 and a document from last week. |
| 8 | Reduce the data broker footprint, and treat public footage as attacker input | Ten popular apps shared personal data with at least 135 third parties.[189] A $25 million transfer was authorised after a call whose other participants were synthesised from public footage.[41] | Search your own name and face. Write down what an attacker could assemble in an hour. |
| 9 | Agree a verification phrase with family and finance contacts | AI-related complaints reached $893 million in adjusted losses in 2025 against total reported losses above $20.9 billion,[39] with projections to $40 billion by 2027.[40] Provenance standards exist but do not cover a phone call.[193] | Call a family member and request an unusual transfer. See whether the phrase is asked for. |
| 10 | Grant no agent standing access to a mailbox or repository it does not need | Zero-click exfiltration through assistants and connectors is documented repeatedly, with over-privileging named as root cause.[47, 48, 51] | List every connector with mail or file access. Revoke one and see whether anything breaks. |
For a company
| # | Control | Anchor | Proof test |
|---|---|---|---|
| 1 | Adopt essential cyber hygiene as a floor and name an owner for each safeguard | 56 safeguards in the entry implementation group, designed for organisations with limited security expertise;[177] five technical controls in the UK scheme, whose current requirements apply to accounts created after 26 April 2026.[178] Map outcomes to the 2024 framework revision.[173] | Sample five safeguards at random and ask the named owner for evidence. |
| 2 | Phishing-resistant authentication everywhere, administrators first | Multi-factor blocks over 99.9 per cent of account compromise by one provider's telemetry;[181] only 28 per cent of organisations deploying passkeys are fully passwordless.[179] | Run an internal phishing exercise against the administrator group. |
| 3 | Inventory third-party data custody and rank by records held | Third parties feature in 48 per cent of breaches;[76] one platform's customer accounts exposed records of at least 100 million people without any platform vulnerability.[77] | Name the top five holders of your customer data and the notice period each owes you. |
| 4 | Put a boundary between agents and tools: short-lived scoped identities, allow-listed actions, approval for consequence | Five Eyes guidance recommends cryptographically anchored short-lived agent identities and no broad access;[62] the leading research defence isolates control and data flow around the model rather than hardening the model.[58] | Plant a benign injected instruction in a document the agent reads. It must be refused or blocked, and the attempt must appear in a log. |
| 5 | Govern AI use with a management system, not a memo | The AI management-system standard published in December 2023 is already certified by major providers;[176] the risk framework and its generative profile give twelve named risk categories to work through.[174, 175] | Produce the risk register entry for your highest-volume AI feature, with owner and date. |
| 6 | Pin the dependency graph, including agent connectors and model artefacts | 796 packages backdoored across roughly 25,000 repositories;[55] a connector package clean for fifteen releases and malicious in the sixteenth;[56] serialised models carrying executable payloads past a scanner.[57] | Break a lockfile deliberately. The build must fail, not resolve to latest. |
| 7 | Bring the sensitive inference path in-house and keep a remote fallback | Four-month capability lag;[104] confidential computing for work that must leave the premises.[138, 139] | Cut the external API at the firewall. Measure which features degrade and which stop. |
| 8 | Make portability a tested property before January 2027 | Switching must complete within 30 days now, and switching charges end 12 January 2027.[146] | Stand the primary workload up at a second provider from repository and backup alone. Record the elapsed time. |
| 9 | Prepare for the reporting clocks that are already running | 24-hour early warning and 72-hour notification for actively exploited vulnerabilities since 11 September 2026;[147, 148] operational resilience rules in force for financial entities since January 2025.[149] | Run a tabletop at 02:00 on a Saturday. Produce the draft notification inside 24 hours. |
| 10 | Ship every control with a fixture that makes it fail, and count the unproven ones | Only 26 per cent of catalogued known-exploited vulnerabilities were fully remediated in 2025;[195] adversary technique catalogues specific to machine learning exist for exactly this rehearsal.[171] | For each gate, apply a mutation it claims to catch. Report the count of gates that stayed green. |
The one-line version, for the comment thread
Keys you cannot phish, a restore you have actually run, an agent that cannot reach what it does not need, and one model running on your own hardware. Four things. Everything else in this report is detail.
Part IX — Ninety days, with provable gates
A programme whose completion is a matter of opinion never completes. Each phase below ends in a command or an observation that can only return one of two answers, which is the only way a plan survives contact with a quarter's worth of interruptions.
| Phase | Work | Gate: done means |
|---|---|---|
| Days 1–14 Inventory | Enumerate every system holding your data, every third party with access, every agent with a credential, every device with an address. Rank by records held and by what a compromise would reach. | A single list exists, with a named owner per line and no line reading “unknown”. Anyone can name the top five holders of customer data from memory. |
| Days 1–14 Identity | Phishing-resistant credentials on administrators, finance, email, domain registrar and code hosting. | A correct password without a key fails on every account in that set. Observed, not assumed. |
| Days 15–30 Recovery | Offline immutable copy of everything that would end the business, plus a documented restore path. | A file from the offline copy is restored onto a machine that has never held it, and the elapsed time is written down. |
| Days 31–45 Agent boundary | Scope every agent credential, allow-list tool actions, require approval for anything irreversible, log every tool call. | A planted injection in a document the agent reads is refused or blocked, and the attempt appears in a log a human reads. |
| Days 46–60 Local inference | One open-weight model on owned hardware, serving one real recurring workload, with the remote path kept as fallback. | The external API is cut at the firewall for one working day and the workload still completes. Degradations are listed by name. |
| Days 61–75 Portability | Rebuild the primary workload at a second provider from repository and backup only, ahead of the January 2027 switching-cost change.[146] | The second environment serves real traffic for one hour. Elapsed rebuild time is recorded. |
| Days 76–90 Proof | For every gate above, build a fixture that makes it fail, run it, and observe the failure. Count the gates that could not be made to fail. | The report states three numbers: gates proven, gates fail-closed, gates unproven. An unproven gate is not counted as passing. |
Blocked is a valid ending
Any phase that requires a decision only a person can make, a credential only a person holds, or a signature only a person can give, stops and reports who owns the next step. A failing check is not a block. A red gate is the work.
Part X — What would change these conclusions
Stating the falsifiers is what separates a position from a prediction. Five observations would force a revision, and three of them are measurable on a quarterly cadence.
1. The open-weight gap widens past roughly twelve months. The current four-month average is what makes local inference a procurement choice rather than a sacrifice.[104] If frontier capability decouples, the honest recommendation shifts toward confidential computing at a provider[138, 139] rather than local weights. Check quarterly. 2. Prompt injection gets a deployable structural fix. The current position is that it is unlikely ever to be fully solved,[59] with the credible defences architectural.[58] If capability-based isolation ships as a platform default and independent evaluations show hijack rates falling from the measured 81 per cent[46] to low single digits, the agent-boundary work in Part VIII becomes vendor-supplied rather than customer-built. 3. Open-weight release becomes materially implicated in a mass-casualty event. The 2024 finding that open weights should not be restricted was explicitly conditional on continued monitoring,[165] and a frontier developer has already withdrawn the assumption that its newer models sit below the bioweapons threshold.[23] A demonstrated causal link would make unqualified open-weight advocacy untenable, and the sovereignty argument would have to be rebuilt on confidential compute and licensed weights. 4. EU switching and sovereignty deadlines slip materially. The AI Act's high-risk obligations have already been deferred once by the simplification package.[143, 144] If the January 2027 egress provision moves,[146] the commercial case for portability loses its deadline and reverts to an engineering preference. 5. Self-managed infrastructure shows a worse measured breach rate than managed, at comparable scale. The current evidence is uncomfortable rather than decisive: small organisations were 96 per cent of ransomware victims[194] and patch remediation is falling.[195] A clean comparative study showing sovereignty reliably costs availability would reorder Part VIII rather than overturn it, since the prerequisite controls are already listed first.
What the evidence supports, and what it does not
VERIFIED Documented, state-grade misuse of generally available models; an unsolved autonomy attack surface; third parties as the majority breach route; concentration failures with global reach; a four-month open-weight gap; a legislated European schedule that rewards portability.
ASSUMED That omnidirectional, near-omnipotent AI arrives on any particular schedule. That is a forecast, contested by named researchers on both sides,[8, 9, 13] and nothing in Part VIII or IX depends on which side is right.
The case for taking control does not need the scary timeline to be true. That is the strongest thing about it.
References
Retrieved 12 September 2026. Where a paywall or access control prevented reading the primary article, the entry names the outlet that carried the same reporting. Dates are as published by the source.
1. TechCrunch, “'Gambling with our lives': Anthropic researcher quits, warns against self-improving AI,” 9 Sep 2026. techcrunch.com 2. CBS News, “Ex-Anthropic researcher Jacob Coxon warns AI could grow 'smart enough to kill us',” 11 Sep 2026. cbsnews.com 3. CNN, “Former Anthropic researcher warns AI could 'kill us all',” Anderson Cooper 360, 10 Sep 2026. cnn.com 4. CoinDesk, “Anthropic's AI researcher quits, says insiders fear human extinction by 2030,” 9 Sep 2026. coindesk.com 5. NBC News, “An Anthropic safety researcher resigned with a warning about AI to co-workers on Slack,” Sep 2026. nbcnews.com 6. Help Net Security, “OpenAI just hit a milestone on the road to self-improving AI,” 7 Sep 2026. helpnetsecurity.com 7. TechCrunch, “An Anthropic researcher just gave us a peek at self-improving AI,” 28 Aug 2026. techcrunch.com 8. KuCoin News, “Anthropic and DeepMind signal AI self-improvement acceleration,” reporting Jack Clark's 4 May 2026 statement. kucoin.com 9. MIT Technology Review, “AI's recursive self-improvement might not come so quickly after all,” 18 Aug 2026. technologyreview.com 10. Y. Bengio (chair) et al., “International AI Safety Report 2026,” arXiv:2602.21012, 24 Feb 2026. arxiv.org 11. Center for AI Safety, “Statement on AI Extinction Risk,” 30 May 2023. aistatement.com 12. Forethought, “Will compute bottlenecks prevent an intelligence explosion?,” arXiv:2507.23181, Jul 2025. arxiv.org 13. “AI Futures Project,” encyclopaedia entry summarising the AI 2027 scenario and subsequent timeline revisions. wikipedia.org 14. FutureSearch, “AGI timeline predictions: how top forecasters updated, 2023 to 2026.” futuresearch.ai 15. A. Narayanan and S. Kapoor, “AI as Normal Technology.” normaltech.ai 16. Common Dreams, “68% of US voters back Sanders/Casar bill for AI pause, ban on superintelligence: poll,” 10 Sep 2026. commondreams.org 17. Office of Sen. Bernie Sanders, “Sanders, Casar to introduce legislation to ban artificial superintelligence and temporarily pause advanced AI development.” sanders.senate.gov 18. Paubox, “New bills would ban superintelligent AI and regulate AI agents,” 10 Sep 2026. paubox.com 19. Artificial Intelligence Dynamics, “Gary Marcus on AGI and scaling limits,” 9 May 2026. artificialintelligencedynamics.com 20. Science, “Bernie Sanders aims to ban AI 'superintelligence.' But experts can't agree what the term means.” science.org 21. Anthropic, “Detecting and countering misuse of AI: September 2026,” 10 Sep 2026, case GTG-87001 at p.112. anthropic.com (PDF) 22. Ibid., case GTG-30005, “Military reconnaissance,” pp.105–106. 23. Ibid., biological misuse case study 1, pp.129–132, including the statement that newer models can no longer be assumed below the bioweapons-uplift threshold. 24. Ibid., cases GTG-14021 (pp.92–93) and GTG-14010 (pp.85–88), surveillance and transnational repression. 25. Anthropic, “Countering misuse of AI: September 2026” (report landing page; period covered Dec 2025 – Aug 2026, seven harm categories). anthropic.com 26. Navy Times, “Iran used Claude to target US Navy in Middle East, Anthropic says,” 11 Sep 2026, carrying Wall Street Journal reporting. navytimes.com 27. Stars and Stripes, “Iran-linked actor used AI to build targeting guides on US Navy,” 11 Sep 2026. stripes.com 28. Anthropic, “Threat Intelligence Report: August 2025,” 27 Aug 2025. anthropic.com (PDF) 29. Anthropic, “Disrupting the first reported AI-orchestrated cyber espionage campaign,” 13 Nov 2025. anthropic.com 30. The Record, “Chinese state hackers used Anthropic AI systems in dozens of attacks,” 14 Nov 2025. therecord.media 31. Axios, “Chinese hackers used Anthropic's Claude AI agent to automate spying,” 13 Nov 2025. axios.com 32. OpenAI, “Disrupting malicious uses of AI: October 2025.” openai.com (PDF) 33. OpenAI, “Disrupting malicious uses of AI,” two-year retrospective, 25 Feb 2026. openai.com 34. Google Threat Intelligence Group, “Adversaries leverage AI for vulnerability exploitation, augmented operations, and initial access,” May 2026. cloud.google.com 35. CyberScoop, “Google spotted an AI-developed zero-day before attackers could use it,” 11 May 2026. cyberscoop.com 36. CNBC, “Google says it likely thwarted effort by hacker group to use AI for 'mass exploitation event',” 11 May 2026. cnbc.com 37. Dragos, “AI-assisted ICS attack on a water utility,” 2026. dragos.com 38. Surfshark Research, “Global deepfake fraud reaches $2.19B — US leads in losses,” 2026. surfshark.com 39. FBI, “Cryptocurrency and AI scams bilk Americans of billions,” 2025 Internet Crime Report figures. fbi.gov 40. Deloitte Center for Financial Services, “Generative AI is expected to magnify the risk of deepfakes and other fraud in banking,” 29 May 2024. deloitte.com 41. TrueScreen, “Voice cloning corporate fraud: CFO defense after the Arup case,” 2026 analysis of the February 2024 incident. truescreen.io 42. OWASP GenAI Security Project, “OWASP Top 10 for LLM Applications 2025,” 14 Nov 2024. owasp.org (PDF) 43. OWASP GenAI Security Project, “Agentic AI — Threats and Mitigations,” 17 Feb 2025. genai.owasp.org 44. OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications,” 9 Dec 2025. genai.owasp.org 45. NIST, “Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations,” NIST AI 100-2e2025, 24 Mar 2025. nist.gov 46. NIST Center for AI Standards and Innovation, “Strengthening AI agent hijacking evaluations,” with the UK AI Security Institute, 17 Jan 2025. nist.gov 47. Aim Security research via HackTheBox, “Inside CVE-2025-32711 (EchoLeak),” 24 Jul 2025. hackthebox.com 48. Invariant Labs, “GitHub MCP exploited: accessing private repositories via MCP,” 26 May 2025. invariantlabs.ai 49. Invariant Labs, “MCP security notification: tool poisoning attacks,” 2025. invariantlabs.ai 50. GitHub Advisory Database, GHSA-6xpm-ggf7-wc3p / CVE-2025-6514, command injection in mcp-remote. github.com 51. The Hacker News, “ShadowLeak zero-click flaw leaks Gmail data via OpenAI ChatGPT Deep Research agent,” Sep 2025. thehackernews.com 52. Zenity Labs via PR Newswire, “Zenity Labs exposes widespread 'AgentFlayer' vulnerabilities,” Aug 2025. prnewswire.com 53. Legit Security, “CamoLeak: critical GitHub Copilot vulnerability leaks private source code,” 2025. legitsecurity.com 54. CISA, “Widespread supply chain compromise impacting npm ecosystem,” 23 Sep 2025. cisa.gov 55. Microsoft Security, “Shai-Hulud 2.0: guidance for detecting, investigating, and defending against the supply chain attack,” 9 Dec 2025. microsoft.com 56. Stacklok, “Examining the impact of npm supply chain attacks on MCP,” including the postmark-mcp rug-pull. stacklok.com 57. The Hacker News, “Malicious ML models found on Hugging Face leverage broken pickle format to evade detection,” Feb 2025. thehackernews.com 58. E. Debenedetti, I. Shumailov, T. Fan, J. Hayes, N. Carlini, D. Fabian, C. Kern, C. Shi, A. Terzis, F. Tramèr, “Defeating prompt injections by design” (CaMeL), arXiv:2503.18813, 24 Mar 2025. arxiv.org 59. TechCrunch, “OpenAI says AI browsers may always be vulnerable to prompt injection attacks,” 22 Dec 2025. techcrunch.com 60. VentureBeat, “OpenAI admits that prompt injection is here to stay,” with browser-agent attack-success data. venturebeat.com 61. Brave, “Agentic browser security: indirect prompt injection in Perplexity Comet,” 25 Aug 2025. brave.com 62. CISA with NSA, ASD ACSC, CCCS, NCSC-NZ and NCSC-UK, “Careful adoption of agentic artificial intelligence services,” 1 May 2026. cisa.gov 63. Same guidance, primary PDF dated 30 Apr 2026. media.defense.gov (PDF) 64. Synergy Research Group, “Cloud market annual revenue run rate topped half a trillion dollars in Q1,” 29 Apr 2026. srgresearch.com 65. Synergy Research Group, “Cloud market share trends — big three together hold 63%,” 19 Nov 2025. srgresearch.com 66. Menlo Ventures, “2025 State of Generative AI Report,” via GlobeNewswire, 9 Dec 2025. globenewswire.com 67. Menlo Ventures, “Investing in OpenRouter, the one API for all AI,” 25 Jun 2025. menlovc.com 68. Amazon Web Services, “Summary of the Amazon DynamoDB service disruption in the Northern Virginia (US-EAST-1) region,” Oct 2025. aws.amazon.com 69. TechCabal, “Everything you need to know about the AWS outage,” 20 Oct 2025. techcabal.com 70. ThousandEyes, “Microsoft Azure Front Door outage analysis: October 29, 2025.” thousandeyes.com 71. Cloudflare, “Cloudflare outage on February 20, 2026,” 20 Feb 2026. blog.cloudflare.com 72. CNBC, “Delta, CrowdStrike sue each other over widespread IT outage,” 25 Oct 2024. cnbc.com 73. IT Pro, “Delta sues CrowdStrike for $500 million in damages,” 28 Oct 2024. itpro.com 74. PC Gamer, citing Microsoft's David Weston, “8.5 million devices were affected by the CrowdStrike bug,” Jul 2024. pcgamer.com 75. IBM X-Force, “2025 Cost of a Data Breach Report: navigating the AI rush without sidelining security.” ibm.com 76. Verizon, 2026 Data Breach Investigations Report announcement, 19 May 2026. verizon.com 77. Cloud Security Alliance, “Unpacking the 2024 Snowflake data breach,” 7 May 2025. cloudsecurityalliance.org 78. Futurum Group, “AI capex 2026: the $690B infrastructure sprint,” 12 Feb 2026. futurumgroup.com 79. International Energy Agency, “Energy demand from AI,” in Energy and AI, 2025. iea.org 80. Brennan Center for Justice, “Section 702 of the Foreign Intelligence Surveillance Act: 2026 resource page.” brennancenter.org 81. WilmerHale, “European Court of Justice to review challenge to EU-U.S. Data Privacy Framework,” 1 Dec 2025 (Case C-703/25 P). wilmerhale.com 82. IAPP, “European General Court dismisses Latombe challenge, upholds EU-US Data Privacy Framework,” Sep 2025. iapp.org 83. National Law Review, “Beyond the server location: why the new fight over FISA 702 and the CLOUD Act matters to corporate privacy strategy,” 2026. natlawreview.com 84. Aviation Week, “Ukraine eyes drone production topping 7 million units,” 21 Apr 2026. aviationweek.com 85. Militarnyi, “Ukraine plans to produce over 7 million drones in 2026,” 26 Jan 2026. militarnyi.com 86. Militarnyi, “Ukraine develops AI-controlled turrets to shoot down drones using fiber optics,” 9 May 2026. militarnyi.com 87. Global Times, “China unveils full-process demonstration of Atlas drone swarm operations system,” 25 Mar 2026. globaltimes.cn 88. Human Rights Watch, “UN talks on killer robots end with calls for negotiations growing,” 7 Sep 2026. hrw.org 89. Stop Killer Robots, “156 states support UNGA resolution on autonomous weapons,” 6 Nov 2025. stopkillerrobots.org 90. GovConWire, “DOD updates autonomy in weapon systems directive,” 26 Jan 2023, on DoD Directive 3000.09. govconwire.com 91. Washington Times, “Pentagon awards first contracts for AI-powered drone interceptors under Replicator 2,” 15 Jan 2026. washingtontimes.com 92. Defense One, “The Pentagon's $54 billion bet on autonomous warfare,” May 2026. defenseone.com 93. Interesting Engineering, “Figure claims new BotQ facility can make one humanoid robot per hour,” 30 Apr 2026. interestingengineering.com 94. Fortune via MSN, “Tesla is targeting 50,000 Optimus robots in 2026 at $20,000 to $30,000 each, while China's Unitree undercuts it with a $16,000 humanoid,” 2026. msn.com 95. Military Times, “How US military funding propelled China's robot dogs,” 18 Aug 2026. militarytimes.com 96. TechCrunch, “Amazon's Ring cancels partnership with Flock,” 13 Feb 2026. techcrunch.com 97. ABC News, “Flock cameras trigger nationwide backlash over privacy concerns, police abuse,” 1 Sep 2026. abcnews.com 98. Newsweek, “Flock's major rivals as cameras spark increasing backlash,” 25 Aug 2026. newsweek.com 99. Biometric Update, “Clearview facial recognition searches double, database reaches 50B images,” 26 Jun 2024. biometricupdate.com 100. IBTimes UK, “Met Police pushes ahead with facial recognition rollout despite calls for regulation first,” 2026. ibtimes.co.uk 101. ICEYE, “ICEYE launches five new satellites, supporting additional customer missions,” 29 Nov 2025. iceye.com 102. KeepTrack, “Starlink satellite count hits 10,087,” 22 Mar 2026. keeptrack.space 103. IEEE ComSoc Technology Blog, “3GPP approves timelines for Release 21,” 16 Jun 2026. techblog.comsoc.org 104. Epoch AI, “Open models lag state-of-the-art closed models by 4 months,” data through 28 May 2026. epoch.ai 105. Epoch AI, “Open-weight models: data and research.” epoch.ai 106. Artificial Analysis, Intelligence Index leaderboard, accessed 12 Sep 2026. artificialanalysis.ai 107. Morph, “Best open-source coding model 2026,” benchmark compilation. morphllm.com 108. H. Konishi, “Open-weights LLM release history and timeline.” hidekazu-konishi.com 109. Digital Applied, “Open-source AI landscape April 2026,” Apr 2026. digitalapplied.com 110. NVIDIA, “Jetson Thor” product specifications, accessed 12 Sep 2026. nvidia.com 111. IntuitionLabs, “NVIDIA DGX Spark review,” 2026. intuitionlabs.ai 112. RunAIHome, “AMD Ryzen AI Max+ 395 (Strix Halo) for local LLMs in 2026.” runaihome.com 113. Tom's Hardware, “AMD Ryzen AI Max 400 'Gorgon Halo' packs up to 192GB of unified memory,” 2026. tomshardware.com 114. Solid AI Tech, “AI PC NPU dashboard: check your Copilot+ TOPS rating,” May 2026. solidaitech.com 115. Apple Machine Learning Research, “Exploring LLMs with MLX and the neural accelerators in the M5 GPU,” 2026. machinelearning.apple.com 116. Current Affair, “Mac M4 Max local LLM 70B benchmark,” 2026. currentaffair.today 117. LLMCheck, “M5 Max vs M4 Max local LLM,” 2026. llmcheck.net 118. Jarvislabs, “NVIDIA RTX 5090 specs, release date, and benchmarks for AI,” 2026. jarvislabs.ai 119. Microsoft, “BitNet: official inference framework for 1-bit LLMs,” repository, accessed 12 Sep 2026. github.com 120. M. Kleppmann et al., Ink & Switch, “Local-first software: you own your data, in spite of the cloud,” 2019. inkandswitch.com 121. Databricks, “Electric joins Databricks to bring WASM Postgres to AI agent sandboxes,” 11 Aug 2026. databricks.com 122. Blocks and Files, “Databricks buys Electric,” 12 Aug 2026. blocksandfiles.com 123. Automerge project, repository README, accessed 12 Sep 2026. github.com 124. PkgPulse, “Yjs vs Automerge vs Loro: CRDT libraries 2026.” pkgpulse.com 125. Cloudzy, “Self-hosting an LLM vs. API: real cost math (2026).” cloudzy.com 126. K. Ganglani, “Local LLM cost vs cloud API break-even,” 2026. kunalganglani.com 127. Epoch AI, “LLM inference prices have fallen rapidly but unequally across tasks,” 2025. epoch.ai 128. Stanford HAI, “AI Index 2025: state of AI in 10 charts,” 2025. hai.stanford.edu 129. Epoch AI, “How persistent is the inference cost burden?,” 2025. epoch.ai 130. S. Wang and M. Casado, “The cost of cloud, a trillion dollar paradox,” Andreessen Horowitz, 27 May 2021. a16z.com 131. Data Center Dynamics, “37signals expects to save $7m over five years after moving off of the cloud.” datacenterdynamics.com 132. Data Center Dynamics, “37signals claims it saved almost $2m last year from cloud repatriation,” 2025. datacenterdynamics.com 133. IT Pro, “Singapore firm 'saves $400 million' by not migrating to cloud,” 2024. itpro.com 134. The Stack, “GEICO slashes compute costs 50% with cloud repatriation, shift to OCP,” 2026. thestack.technology 135. Home Assistant / Open Home Foundation, “2 million homes strong — State of the Open Home 2025,” 16 Apr 2025. home-assistant.io 136. DreamHost, “Self-hosting in 2026: is the revolution finally here?” dreamhost.com 137. LLM Hardware, “Running LLMs on a NAS (Synology, QNAP): is it worth it,” 2026. llmhardware.io 138. Phala, “AMD SEV vs Intel TDX vs NVIDIA GPU TEE,” 2026. phala.com 139. Apple, “Apple Private Cloud Compute SOC 3 audit,” report period ending 30 Apr 2026. support.apple.com 140. Duality Technologies, “Is FHE still too slow? Homomorphic encryption benchmarks 2026.” dualitytech.com 141. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal, 12 Jul 2024. eur-lex.europa.eu 142. European Commission, “AI Act,” regulatory framework page with applicability milestones. digital-strategy.ec.europa.eu 143. Council of the EU, “Artificial intelligence: Council gives final green light to simplify and streamline rules,” 29 Jun 2026. consilium.europa.eu 144. Gibson Dunn, “EU AI Act omnibus agreement — postponed high-risk deadlines and other key changes,” 2026. gibsondunn.com 145. European Commission, “AI Office invites providers to sign the GPAI Code of Practice,” Jul 2025. digital-strategy.ec.europa.eu 146. Alston & Bird, “The Data Act: switching requirements for cloud services providers,” Sep 2025, on Regulation (EU) 2023/2854. alston.com 147. European Commission, “The Cyber Resilience Act — summary of the legislative text,” on Regulation (EU) 2024/2847. digital-strategy.ec.europa.eu 148. National Law Review, “Cyber Resilience Act: 11 September 2026 key starting point for reporting obligations.” natlawreview.com 149. DLA Piper, “Application of the Digital Operational Resilience Act (DORA),” Feb 2025. dlapiper.com 150. Viktoria Compliance, “NIS2 transposition in 2026: where every EU member state stands.” viktoria-compliance.eu 151. Paul Hastings, “President Trump signs executive order challenging state AI laws,” on the order of 11 Dec 2025. paulhastings.com 152. “Data Governance Act,” Regulation (EU) 2022/868, applicable since 24 Sep 2023. wikipedia.org 153. European DIGITAL SME Alliance, “Changes to the EU Cloud Services Cybersecurity Certification Scheme put EU citizens' data at risk,” 5 Sep 2024. digitalsme.eu 154. Gaia-X Hub Netherlands, “Why Europe is moving towards a federated cloud infrastructure.” gaia-x.nl 155. “EuroStack,” encyclopaedia entry on the European technology-stack proposal. wikipedia.org 156. European Commission, “Cloud and AI Development Act,” proposal adopted 3 Jun 2026. digital-strategy.ec.europa.eu 157. Light Reading, “EU defers formal call for AI gigafactories to early 2026.” lightreading.com 158. G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. Hadfield et al., “Computing power and the governance of artificial intelligence,” Centre for the Governance of AI, 14 Feb 2024. governance.ai 159. “Article 51 — classification of general-purpose AI models as models with systemic risk,” AI Act commentary. regulation-ai.eu 160. RAND Corporation, “Contemporary foundation AI models increase biological weapons risk,” 2025. rand.org 161. RAND Corporation, “The operational risks of AI in large-scale biological attacks: results of a red-team study,” 2024. rand.org 162. D. Hendrycks, E. Schmidt, A. Wang, “Superintelligence strategy: expert version,” arXiv:2503.05628, 7 Mar 2025. arxiv.org 163. RAND Corporation, “Seeking stability in the competition for AI advantage,” Mar 2025. rand.org 164. Z. Mowshowitz, “On MAIM and Superintelligence Strategy,” Mar 2025. thezvi.substack.com 165. NTIA, “Dual-use foundation models with widely available model weights,” 30 Jul 2024. ntia.gov 166. Cleary Gottlieb, “BIS further restricts exports of artificial intelligence and advanced chips to China,” Apr 2025. clearytradewatch.com 167. Computerworld, “AWS European cloud service launch raises questions over sovereignty,” 2026. computerworld.com 168. Telenor Group, “Telenor establishes sovereign cloud company,” 5 May 2026. telenor.com 169. RCR Wireless News, “Telenor launches sovereign cloud venture in Norway,” 8 May 2026. rcrwireless.com 170. Government Offices of Sweden, “A cloud policy for Sweden — for increased security, efficiency and innovation in public administration,” 25 Jun 2026. government.se 171. MITRE, “MITRE ATLAS,” adversarial threat landscape for artificial-intelligence systems. atlas.mitre.org 172. Webperf, “DPF: eSam ger inte grönt ljus för amerikanska molntjänster (nu heller),” on eSam's position. webperf.se 173. NIST, “The NIST Cybersecurity Framework (CSF) 2.0,” NIST CSWP 29, 26 Feb 2024. nist.gov 174. NIST, “AI Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, 26 Jan 2023. nist.gov 175. NIST, “AI RMF: Generative Artificial Intelligence Profile,” NIST AI 600-1, 26 Jul 2024. nvlpubs.nist.gov (PDF) 176. ISO/IEC 42001:2023, “Information technology — artificial intelligence — management system,” Dec 2023. iso.org 177. Center for Internet Security, “CIS Critical Security Controls Implementation Group 1,” Controls v8.1. cisecurity.org 178. NCSC / IASME, “Cyber Essentials: requirements for IT infrastructure v3.3,” effective for accounts created after 26 Apr 2026. ncsc.gov.uk (PDF) 179. FIDO Alliance, “FIDO Alliance reports accelerating global passkey adoption on World Passkey Day 2026,” 7 May 2026. fidoalliance.org 180. CISA, “Implementing phishing-resistant MFA,” fact sheet, Oct 2022. cisa.gov (PDF) 181. Microsoft Security, “One simple action you can take to prevent 99.9 percent of account attacks,” 20 Aug 2019. microsoft.com 182. Google Security Blog, “New research: how effective is basic account hygiene at preventing hijacking,” 17 May 2019. security.googleblog.com 183. Backup Wrap-Up, interview with Peter Krogh, who coined the 3-2-1 rule in The DAM Book (2005). backupwrapup.com 184. CISA and MS-ISAC, “#StopRansomware Guide.” cisa.gov 185. Cyberhaven, “Sensitive enterprise data is flowing into AI tools at scale,” 11 Feb 2026. cyberhaven.com 186. Sophos, “The State of Ransomware 2026.” sophos.com 187. Veeam, “Data Trust and Resilience Report 2026,” 14 Apr 2026. veeam.com 188. Regulation (EU) 2016/679 (GDPR), Article 5(1)(c), data minimisation. gdpr-info.eu 189. Consumer Reports, “Popular apps share intimate details about you with dozens of companies,” 14 Jan 2020, on a Norwegian Consumer Council study. consumerreports.org 190. NIST, “Profile of the IoT core baseline for consumer IoT products,” NISTIR 8425, 20 Sep 2022. nvlpubs.nist.gov (PDF) 191. Security Affairs, “Aisuru botnet is behind record 20Tb/sec DDoS attacks,” 28 Oct 2025. securityaffairs.com 192. CISA, “CISA adds two known exploited vulnerabilities to catalog,” MikroTik RouterOS, 10 Sep 2026. cisa.gov 193. Coalition for Content Provenance and Authenticity, Content Credentials specification v2.4, 21 Apr 2026. c2pa.org 194. Cyber Readiness Institute, “Verizon DBIR 2026: small businesses face escalating cyber threats.” cyberreadinessinstitute.org 195. Dark Reading, “Verizon DBIR: basic security gaffes cause breach surge,” 2026. darkreading.com
How this was assembled, and where it is weakest
Nine parallel research tracks ran against the open web on 12 September 2026, each instructed to return only sources it had actually retrieved, with the specific fact seen at that address. Entries that could be read only as a search snippet were marked as such by the researcher and are presented here without upgrade. The Anthropic threat-intelligence report was downloaded and its text extracted directly, which is why page and case numbers appear rather than paraphrase.
Three weaknesses should be stated rather than discovered. First, several local-inference benchmarks in Part V come from trade blogs and enthusiast sites rather than instrumented independent testing; they are consistent with one another and with vendor specifications, but they are not laboratory results, and the hardware table should be read as indicative. Second, two load-bearing legal items, the Section 702 renewal sequence and the appeal against the transatlantic adequacy decision, were confirmed through legal commentary rather than the court and congressional records themselves. Third, one Wall Street Journal report is cited through two outlets that attribute it explicitly, because the original sits behind a paywall.
This report assesses public evidence only. It makes no measurement claims about WINNIIO's or Life Atlas's own systems, and nothing here should be read as a description of software either has delivered.
Edge Native Sovereignty · research report · 12 September 2026 · 195 sources.
Findings marked VERIFIED rest on a named source read during preparation. Findings marked ASSUMED are inference from those sources and are labelled so they can be argued with.
Where this goes next
Want this applied to your organisation?
One call is enough to know if we're a fit.