Ramparts AI Frontier Monitor
Week of 29 May 2026 · Asymmetric Intelligence · Published 2026-05-29T09:00:00Z T09:00:00Z
- → Anthropic dual opsec failure: KAIROS/BUDDY/undercover mode + Mythos leak M00
- → GSA ‘any lawful use’ clause: comment deadline April 3 — generalises Pentagon Anthropic playbook to all federal AI M09 / M10
- → OpenAI $852B valuation at 60x revenue — most extreme in tech history M03
- → AISI pipeline: all three principal AI safety bodies in leadership transition approaching August 2026 enforcement cliff M15 / M10
- → EU AI Act Omnibus: 28 April trilogue agreement target — Standards Vacuum 122 days to deadline M09
The Signal
Anthropic has publicly acknowledged that AI models have reached a level of coding capability surpassing all but the most skilled humans at finding and exploiting software vulnerabilities. The unreleased Claude Mythos2 Preview has identified thousands of zero-day vulnerabilities across every major operating system and web browser, with exploits surviving decades of human review and millions of automated tests. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure. This marks the first public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation.
Executive Insight
Items 1–5 · Mainstream High-Impact Developments
EU AI Omnibus political agreement extends high-risk AI system deadline to August 2028
2026-05-07EU legislators reached a political agreement on the AI Omnibus at 4:30 a.m. on 7 May 2026, concluding a six-month negotiation process. The central outcome is the postponement of application requirements for high-risk AI systems: Annex III systems now face a deadline of 2 December 2027, and systems covered under EU harmonised product safety legislation face a deadline of 2 August 2028. Core obligations remain substantively unchanged, but the delay has drawn criticism from both civil society and industry. The AI Office enforcement powers are simultaneously centralised and an EU-level regulatory sandbox established.
The delay creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office. This combination may accelerate deployment of systems that would otherwise face immediate scrutiny, while reducing the ability of national competent authorities to intervene. The regulatory sandbox provision may become a de facto safe harbour for frontier labs seeking to test capabilities ahead of formal compliance deadlines.
EU Commission publishes draft high-risk AI classification guidelines for stakeholder feedback
2026-05-19On 19 May 2026, the European Commission published draft guidelines clarifying the classification of high-risk AI systems under Article 6 of the AI Act, opening a targeted consultation for stakeholder feedback. The guidelines provide practical examples of systems that should or should not be classified as high-risk, aiming to support uniform application and effective enforcement. This is a direct implementation step ahead of the August 2026 transparency obligations deadline.
The draft guidelines are being published while the Omnibus agreement has already extended high-risk system deadlines to 2027-2028. This creates a temporal mismatch: classification guidance is being finalised for obligations that will not apply for another 18-30 months. Labs and deployers may use this window to argue that systems are not yet subject to classification, creating a de facto compliance holiday. The consultation process also provides an opportunity for industry to shape the boundaries of high-risk classification before enforcement begins.
EU Commission opens consultation on draft AI transparency obligations guidelines
2026-05-08On 8 May 2026, the European Commission opened a public consultation on draft guidelines for AI transparency obligations under Article 50 of the AI Act, covering marking and labelling of AI-generated content. The transparency rules are scheduled to enter into force in August 2026. The Code of Practice on AI-generated content marking, developed through working groups running November 2025 to May 2026, is expected to be finalised imminently as a voluntary compliance tool.
Transparency obligations are scheduled to enter into force in August 2026, three months from now, while high-risk system obligations have been delayed to 2027-2028. This creates a bifurcated enforcement timeline: AI-generated content labelling will be mandatory before high-risk system compliance. Labs may prioritise transparency compliance as a lower-cost signal of good faith, while deferring more substantive safety and risk management obligations. The voluntary Code of Practice may become the de facto standard, with mandatory guidelines serving as a backstop.
Items 6–10 · Underweighted / Asymmetric Signals
Anthropic Claude Mythos2 Preview demonstrates human-competitive vulnerability discovery at scale
2026-05-22Anthropic has publicly acknowledged that AI models have reached a level of coding capability surpassing all but the most skilled humans at finding and exploiting software vulnerabilities. The unreleased Claude Mythos2 Preview has identified thousands of zero-day vulnerabilities across every major operating system and web browser, with exploits surviving decades of human review and millions of automated tests. This is the first public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure.
The scale of zero-day discovery reported by Anthropic (thousands of CVEs across major operating systems) is extraordinary and suggests that AI-enabled vulnerability discovery has reached a level that could fundamentally alter the offensive-defensive balance in cybersecurity. The $100M commitment to defensive cybersecurity is the largest single commitment by a frontier lab to date, but it is framed as a response to a capability that Anthropic itself has developed. This raises a governance question: if a lab can identify thousands of zero-days, what prevents adversarial actors from replicating this capability using similar models? The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.
OpenAI GPT-5.4 and GPT-5.5 series advance agentic coding and cybersecurity capabilities
2026-04-24OpenAI GPT-5.4 (released March 2026) integrates frontier coding capabilities from GPT-5.3-Codex into a mainline reasoning model, achieving a 17-point leap on BrowseComp and setting a new state-of-the-art of 89.3 percent on GPT-5.4 Pro. GPT-5.5 (released April 2026, API access from 24 April) is described as OpenAI strongest agentic coding model to date, with explicitly elevated cybersecurity capabilities and stricter cyber-risk classifiers deployed. GPT-5.2 Thinking is scheduled for retirement on 6 June 2026. These releases represent a sustained cadence of agentic and cybersecurity capability advancement.
OpenAI is releasing three major model updates in the GPT-5 series within a span of eight weeks (GPT-5.3-Codex, GPT-5.4, GPT-5.5), compressing the window for independent safety evaluation and public scrutiny. The explicit elevation of cybersecurity capabilities in GPT-5.5, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. The retirement of GPT-5.2 Thinking on 6 June 2026 indicates that OpenAI is actively managing its model portfolio to consolidate capabilities into fewer, more powerful models. This cadence of release and retirement may become the new normal for frontier labs, with implications for regulatory oversight and safety evaluation timelines.
Model Frontier
undefined
undefinedundefined
First public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation. The model has identified thousands of zero-day vulnerabilities across every major operating system and web browser. Anthropic is framing the release as a defensive measure, committing $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing. The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.
undefined
undefinedundefined
Represents a 17-point leap on BrowseComp and sets a new state-of-the-art. OpenAI is consolidating capabilities into fewer, more powerful models, with implications for regulatory oversight and safety evaluation timelines.
undefined
undefinedundefined
Released within eight weeks of GPT-5.4, compressing the window for independent safety evaluation and public scrutiny. The explicit elevation of cybersecurity capabilities, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. GPT-5.2 Thinking is scheduled for retirement on 6 June 2026, indicating active portfolio management to consolidate capabilities.
Benchmark Leaderboard — 29 May 2026
ARC-AGI-2 (Static Reasoning)
Human average ~60%. Models above this line are superhuman on this benchmark.
ARC-AGI-3 (Interactive/Agentic)
Humans score 100%. Frontier AI near-zero — reveals the adaptive intelligence gap.
GPQA Diamond (Graduate Science)
Human expert ceiling ~70–80%.
Investment & M&A
No items this issue.
Sector Penetration
No items this issue.
European & China Watch
🇪🇺 European AI
EU AI Omnibus political agreement extends high-risk AI system deadline to August 2028, centralises AI Office enforcement powers
Funding Rounds >$50M
No items this issue.
Incumbent Displacement
No items this issue.
EU legislators reached a political agreement on the AI Omnibus at 4:30 a.m. on 7 May 2026, concluding a six-month negotiation process. The central outcome is the postponement of application requirements for high-risk AI systems: Annex III systems now face a deadline of 2 December 2027, and systems covered under EU harmonised product safety legislation face a deadline of 2 August 2028. Core obligations remain substantively unchanged, but the delay has drawn criticism from both civil society and industry. The AI Office enforcement powers are simultaneously centralised and an EU-level regulatory sandbox established. The delay creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office.
The EU AI Act Standards Vacuum flag remains ACTIVE as of this issue. No harmonised standards have been published in the Official Journal. The EU Commission has published draft high-risk AI classification guidelines (19 May 2026) and opened consultation on draft AI transparency obligations guidelines (8 May 2026), but these are guidance documents, not harmonised standards. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available. The temporal mismatch between guidance publication and deferred compliance deadlines creates a de facto compliance holiday for high-risk AI systems.
🇨🇳 China AI
No material China AI governance developments this week.
DeepSeek
No material developments this week.
Alibaba
No material developments this week.
No material developments this week.
Asymmetric implication:
Export Controls
No material developments this week.
AI in Science
No items this issue.
Risk Indicators: 2028
Governance Fragmentation
ELEVATEDEU Digital Omnibus proposes delaying high-risk AI obligations, exacerbating divergent timelines. The delay creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office. This reinforces jurisdictional divergence with EU delays contrasting US nonbinding frameworks.
The EU AI Omnibus political agreement extends high-risk AI system deadlines to 2 December 2027 (Annex III systems) and 2 August 2028 (harmonised product safety legislation systems). This creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office. The delay reinforces jurisdictional divergence, with EU delays contrasting US nonbinding frameworks and accelerating compliance barriers for global deployers amid US state-level actions.
The temporal mismatch between guidance publication and deferred compliance deadlines creates a de facto compliance holiday for high-risk AI systems. Labs and deployers may use this window to argue that systems are not yet subject to classification, creating a de facto compliance holiday. The consultation process also provides an opportunity for industry to shape the boundaries of high-risk classification before enforcement begins.
Cyber Escalation
HIGHAnthropic Claude Mythos2 Preview crosses threshold for mass zero-day vulnerability discovery. The model has identified thousands of zero-day vulnerabilities across every major operating system and web browser. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure.
Anthropic has publicly acknowledged that AI models have reached a level of coding capability surpassing all but the most skilled humans at finding and exploiting software vulnerabilities. The unreleased Claude Mythos2 Preview has identified thousands of zero-day vulnerabilities across every major operating system and web browser, with exploits surviving decades of human review and millions of automated tests. This is the first public acknowledgement by a major lab that AI has crossed a threshold enabling mass zero-day exploitation. Anthropic is committing up to $100M in usage credits and $4M in direct donations to open-source security organisations under Project Glasswing, framing the release as a defensive measure.
The scale of zero-day discovery reported by Anthropic (thousands of CVEs across major operating systems) is extraordinary and suggests that AI-enabled vulnerability discovery has reached a level that could fundamentally alter the offensive-defensive balance in cybersecurity. The $100M commitment to defensive cybersecurity is the largest single commitment by a frontier lab to date, but it is framed as a response to a capability that Anthropic itself has developed. This raises a governance question: if a lab can identify thousands of zero-days, what prevents adversarial actors from replicating this capability using similar models? The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.
Platform Power
HIGHOpenAI GPT-5.5 release with 1M context and agentic suite in accelerating cadence. Reinforces concentration via rapid frontier deployment.
OpenAI is releasing three major model updates in the GPT-5 series within a span of eight weeks (GPT-5.3-Codex, GPT-5.4, GPT-5.5), compressing the window for independent safety evaluation and public scrutiny. The explicit elevation of cybersecurity capabilities in GPT-5.5, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. The retirement of GPT-5.2 Thinking on 6 June 2026 indicates that OpenAI is actively managing its model portfolio to consolidate capabilities into fewer, more powerful models. This cadence of release and retirement may become the new normal for frontier labs, with implications for regulatory oversight and safety evaluation timelines.
The accelerating cadence of frontier model releases by OpenAI, combined with the consolidation of capabilities into fewer, more powerful models, reinforces platform power concentration. The compression of the window for independent safety evaluation and public scrutiny means that regulatory oversight is increasingly reactive, rather than proactive. The explicit elevation of cybersecurity capabilities in GPT-5.5, combined with stricter cyber-risk classifiers, suggests that OpenAI is aware of the dual-use risks but is proceeding with deployment under internal risk management. This may set a precedent for other frontier labs to follow, with implications for the overall governance landscape.
Export Controls
ELEVATEDUS Commerce Dept withdrew planned AI chip export rule (13 March 2026). No replacement rule published. Biden-era AI Diffusion Rule rescinded May 2025. H20 chip requires BIS export license indefinitely (April 2025, Nvidia filing). H200 approved for China with 50% of US domestic sales cap (January 2026, Trump administration). Bilateral supply lock-in intensifying; cloud IaaS providers can serve Chinese customers via foreign data centers without triggering hardware export controls.
↗ SourceDisinfo Velocity
HIGHStanford AI Index documents 55 percent rise in AI incidents; jailbreak safety collapse across frontier models. Universal jailbreak degradation enables scaled adversarial disinformation.
The Stanford HAI 2026 Index evidences a 55 percent AI incident rise and universal jailbreak collapse across frontier models. This enables scaled adversarial disinformation. The EU Commission has opened consultation on draft AI transparency obligations guidelines, covering marking and labelling of AI-generated content, but these are scheduled to enter into force in August 2026, three months from now, while high-risk system obligations have been delayed to 2027-2028. This creates a bifurcated enforcement timeline: AI-generated content labelling will be mandatory before high-risk system compliance.
The universal jailbreak collapse across frontier models, combined with the 55 percent rise in AI incidents, suggests that the offensive-defensive balance in AI safety has shifted decisively in favour of adversarial actors. The EU transparency obligations, scheduled to enter into force in August 2026, may provide a partial mitigation by requiring labelling of AI-generated content, but this is a reactive measure that does not address the underlying capability gap. The delay in high-risk system obligations to 2027-2028 means that the most substantive safety and risk management obligations will not apply for another 18-30 months, during which time the disinfo velocity risk is likely to escalate further.
Standards Vacuum
HIGHEU Digital Omnibus links high-risk rules to unavailable harmonised standards, justifying 16-24 month delay. No harmonised standards have been published in the Official Journal. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available.
The EU AI Act Standards Vacuum flag remains ACTIVE as of this issue. No harmonised standards have been published in the Official Journal. The EU Commission has published draft high-risk AI classification guidelines (19 May 2026) and opened consultation on draft AI transparency obligations guidelines (8 May 2026), but these are guidance documents, not harmonised standards. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available. The temporal mismatch between guidance publication and deferred compliance deadlines creates a de facto compliance holiday for high-risk AI systems.
The standards vacuum is now being used as a justification for delaying compliance obligations, rather than as a trigger for accelerated standards development. This creates a perverse incentive: the longer standards remain unavailable, the longer high-risk AI systems can operate without full compliance obligations. The EU Commission is publishing guidance documents while deferring the obligations those documents are meant to support, creating a temporal mismatch that may undermine the effectiveness of the AI Act.
Regulatory Fragmentation
ELEVATEDEU Omnibus self-exemption provisions reduce oversight for non-EU providers. The AI Office enforcement powers are simultaneously centralised and an EU-level regulatory sandbox established. This accelerates compliance barriers for global deployers amid US state-level actions.
The EU AI Omnibus political agreement centralises AI Office enforcement powers and establishes an EU-level regulatory sandbox. The self-exemption provisions reduce oversight for non-EU providers, accelerating compliance barriers for global deployers amid US state-level actions. The delay in high-risk AI system deadlines creates a 16-24 month window during which high-risk AI systems can operate without full compliance obligations, while simultaneously centralising enforcement powers in the AI Office.
The centralisation of AI Office enforcement powers, combined with self-exemption provisions for non-EU providers, creates a two-tier regulatory regime: EU-based labs may face more direct oversight, while non-EU providers may operate with reduced scrutiny during the 16-24 month compliance holiday. This could accelerate the shift of high-risk AI system deployment to non-EU jurisdictions, undermining the AI Act effectiveness.
AI-Generated Harm
VACUUMNo new deepfake or AI harm incidents this week. Rating maintained absent new signals.
No new deepfake or AI harm incidents this week. Rating maintained absent new signals.
The absence of new AI harm incidents this week does not indicate a reduction in risk. The universal jailbreak collapse across frontier models, combined with the 55 percent rise in AI incidents documented by the Stanford HAI 2026 Index, suggests that the underlying capability gap is widening. The EU transparency obligations, scheduled to enter into force in August 2026, may provide a partial mitigation by requiring labelling of AI-generated content, but this is a reactive measure that does not address the underlying capability gap.
Compute Concentration
ELEVATEDGPU shortages and price increases continue to concentrate compute resources among well-funded entities
GPU shortages are creating a compute divide that favors well-funded entities while limiting access for smaller organizations and researchers
AI Energy Demand
ELEVATEDRapid growth in data center electricity consumption driven by AI workloads
Energy constraints may become a limiting factor for AI development in regions with constrained power infrastructure
AI Labor Disruption
ELEVATEDAI-related job cuts projected to increase nine times over in 2026 compared to 2025
Labor disruption is creating pressure for workforce retraining programs focused on AI-augmented roles rather than AI replacement
Benchmark-Reality Gap
ELEVATEDReal-world AI accuracy drops 20-40% below benchmarks due to data drift and edge cases.
Amplifies unmonitored deployment risks in agentic systems
Capability-Governance Velocity Gap
HIGHFrontier jumps like Claude 4.6 outpace regulatory milestones. Anthropic RSP v3.1 (April 2, 2026) and OpenAI updated principles (April 26, 2026) both reflect voluntary frameworks struggling to keep pace with capability advances approaching August 2026 enforcement deadline.
Regulatory frameworks calibrated for prior architectures become obsolete
Safety Gap
ELEVATEDRapid capability advancement outpaces safety research and evaluation frameworks
The safety gap is widening as frontier models advance more rapidly than safety evaluation frameworks can be developed and validated
Talent Drain
HIGHThe Stanford HAI 2026 Index documents an 80% drop in US AI researcher inflow in one year. This is a structural shift in global AI talent flows, not a temporary blip. The talent drain accelerates US-China convergence in frontier capabilities, raising dual-use risk and reducing US strategic advantage in AI.
The Stanford HAI 2026 Index documents an 80% drop in US AI researcher inflow in one year, with the US-China frontier model gap narrowing to 2.7%. This is a structural shift in global AI talent flows, not a temporary blip. The talent drain accelerates US-China convergence in frontier capabilities, raising dual-use risk and reducing US strategic advantage in AI. The 80% researcher inflow drop is the cumulative effect of US immigration restrictions, Chinese talent retention programmes, and EU talent attraction initiatives.
The 80% researcher inflow drop is underweighted because it is not a single policy change. It is the cumulative effect of US immigration restrictions, Chinese talent retention programmes, and EU talent attraction initiatives. The 2.7% frontier gap is a lagging indicator; the talent flow reversal is a leading indicator of future capability convergence. This is a strategic inflection point for US AI dominance.
Energy Constraint
ELEVATEDRapid growth in data center capacity creates significant energy demand and sustainability challenges
Energy constraints are becoming a critical bottleneck for AI development as data center growth outpaces renewable energy infrastructure development
IP Regime Collapse
ELEVATEDCopyright litigation around AI training data creates uncertainty for model development
IP regime collapse is creating legal uncertainty that may stifle innovation while favoring entities with access to licensed training data
Labor Disruption
ELEVATEDAI reshapes job roles faster than workforce can adapt
Labor disruption is accelerating as AI reshapes job roles faster than workforce training programs can adapt, creating skills gaps and economic inequality
Military AI Watch
No items this issue.
Law & Guidance
EU AI Act — The Layered System
This week saw significant movement on Layers 2, 4, 6, and 7. The Omnibus political agreement (Layer 7) extends high-risk AI system deadlines to 2027-2028, effectively acknowledging the standards vacuum (Layer 3) by deferring compliance obligations until standards are available. The EU Commission published draft high-risk AI classification guidelines (Layer 2) and opened consultation on draft AI transparency obligations guidelines (Layer 4), but these are guidance documents, not harmonised standards. The AI Office enforcement powers are centralised (Layer 6) and an EU-level regulatory sandbox established. The critical path now runs through Layer 3 (harmonised standards) and Layer 4 (GPAI Code of Practice), with transparency obligations scheduled to enter into force in August 2026 (three months from now) while high-risk system obligations are deferred to 2027-2028. Watch for: (1) finalisation of the GPAI Code of Practice, (2) publication of harmonised standards in the Official Journal, (3) formal adoption of the Omnibus agreement, and (4) first AI Office supervisory decisions.
Country Grid — Law & Standards Status
🟢 Binding law in force · 🟡 Law passed/in implementation · 🟠 Guidance/soft law only · ⚪ No framework · 🆕 New this week · ⚠️ Amendment/enforcement
Country Watch — Threshold Tracker
Countries approaching entry to the grid.
AI Governance
(e) Governance Gaps Being Exploited
The scale of zero-day discovery reported by Anthropic (thousands of CVEs across major operating systems) is extraordinary and suggests that AI-enabled vulnerability discovery has reached a level that could fundamentally alter the offensive-defensive balance in cybersecurity. The $100M commitment to defensive cybersecurity is the largest single commitment by a frontier lab to date, but it is framed as a response to a capability that Anthropic itself has developed. This raises a governance question: if a lab can identify thousands of zero-days, what prevents adversarial actors from replicating this capability using similar models? The defensive framing may obscure the fact that the capability itself is now in the wild, and the lab has no mechanism to prevent its misuse beyond voluntary commitments.
Ethics & Accountability
No items this issue.
Technical Standards
CEN-CENELEC JTC21
Harmonised standards for EU AI Act
Tech Policy Press ↗Harmonised standards are required to support compliance with the EU AI Act high-risk AI system obligations. The standards vacuum is now being used as a justification for delaying compliance obligations, rather than as a trigger for accelerated standards development.
No harmonised standards published in the Official Journal this week. The EU Commission has published draft high-risk AI classification guidelines (19 May 2026) and opened consultation on draft AI transparency obligations guidelines (8 May 2026), but these are guidance documents, not harmonised standards. The Omnibus agreement extends high-risk system deadlines to 2027-2028, effectively acknowledging the standards vacuum by deferring compliance obligations until standards are available.
Litigation Tracker
No items this issue.
Personnel & Org Watch
Lab & Industry Movements
Government AI Bodies
The signal in your inbox every Thursday
Primary sources only. No press summaries. 09:00 GMT without exception — reliable enough to build into your morning routine.
No spam. Unsubscribe in one click. Published by Ramparts, Gibraltar.
The signal in your inbox every Thursday
Primary sources only. No press summaries. 09:00 GMT without exception — reliable enough to build into your morning routine.
No spam. Unsubscribe in one click. Published by Ramparts, Gibraltar.