TL;DR: Anthropic’s Project Glasswing shows a model finding zero-day vulnerabilities autonomously across production systems, with benchmark success jumping from 2 to 181 exploit completions and 29 register-control wins, according to WitnessAI’s analysis of Anthropic’s findings. The security problem is no longer discovery scarcity but governance for machine-speed exploitation, where runtime controls, AI visibility, and agent oversight become decisive.
Editorial analysis by NHI Mgmt Group, based on content published by WitnessAI: “A Frontier Lab Just Paused Its Most Powerful Model. Here’s What That Means for Your Security Team.”.
Key questions
Q: What breaks when AI models can find and weaponise vulnerabilities autonomously?
A: What breaks is the assumption that exploit development is rare, slow, and reviewable by human teams before damage occurs.
Q: Why do machine-speed AI workflows increase governance risk?
A: Because governance controls that depend on human-paced review, manual detection, or after-the-fact certification cannot keep up when actions happen continuously.
Q: What are the signs that AI governance controls are not keeping pace with adoption?
A: Common warning signs include unclear ownership for AI use cases, inconsistent approval processes, limited visibility into where sensitive data enters models, and weak evidence for audits or assessments.
Practitioner guidance
- Inventory AI usage beyond approved web tools Map where employees, developers, and agents are using AI inside IDEs, native apps, coding assistants, and workflow systems.
- Define runtime policy boundaries for model actions Specify which codebases, systems, data sets, and tools an AI system may touch, and enforce those boundaries at execution time rather than in a policy document.
- Classify AI agents by tool authority and approval scope Document which agents can call tools, what they can access, and whether human approval is required before high-risk actions.
Bottom line: AI systems that can discover and chain vulnerabilities autonomously change the security problem from scarcity of exploits to scarcity of control.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Machine-speed exploit discovery collapses the old scarcity assumption: The security model that treated vulnerability discovery as expensive and rare no longer holds when a general-purpose model can find and chain flaws autonomously. That assumption was designed for human-paced adversaries and bounded tooling. It fails when the actor can explore code paths, reason about exploitability, and iterate faster than review cycles can react. The implication is that vulnerability governance must be built for machine-rate discovery, not human-rate research.
A question worth separating out:
Q: Should organisations prioritise discovery or runtime enforcement first for AI governance?
A: Discovery comes first because runtime enforcement cannot be meaningfully scoped without knowing where AI exists and what it can access. Once the inventory is live, teams can apply policy checks, output controls, and retention requirements to the highest-risk systems first.
👉 Read our full editorial: AI vulnerability discovery is outpacing enterprise security controls