“The first ultraintelligent machine is the last invention that man need ever make, provided that the machine is docile enough to tell us how to keep it under control.” I. J. Good, Speculations Concerning the First Ultraintelligent Machine (1965)1
Sixty years on, Good’s footnote has become the operating assumption of three of the world’s most capitalised research labs. What was once a thought experiment for cyberneticists in Hawaii is, by 2026, a quarterly capex disclosure. The question is no longer whether such a machine will be built. The question is whether the race to build it will run faster than the institutions meant to govern it.
This is the shape of the competitive singularity: not one lab quietly tipping over a threshold, but several, in parallel, each unable to slow without forfeiting the field to the others. The fast-takeoff scenario that Bostrom described in Superintelligence (Oxford, 2014)2 and that Yudkowsky’s MIRI line of work has warned of for two decades has acquired a property neither writer fully anticipated. It is now multipolar. Three institutional cultures, three theories of safety, three risk tolerances, and a single shared cliff.
I. Anthropic’s Mythos
The lab that was founded to slow down has not slowed down. By April 2026 Anthropic had quietly handed an unreleased frontier model named Mythos3 to eleven launch partners and more than forty critical-infrastructure organisations under a programme it calls Project Glasswing4. The internal codename, according to The Logic, is Capybara5: a frontier tier intended to sit above the public Claude Opus line. The launch list included AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. The general public was not on it.
There is no general release. There is no version number on a marketing page. Mythos exists, today, only as a limited deployment to vetted enterprises, to forty-plus organisations the United States considers critical infrastructure, and to the federal standards body that has quietly become the West’s frontier-evaluation backstop. That body, the Center for AI Standards and Innovation (CAISI, the renamed U.S. AI Safety Institute inside NIST), has completed more than forty pre-deployment assessments of unreleased systems since its predecessor was stood up in 20246. A separate Anthropic collaboration, a Top-Secret-cleared partnership with the National Nuclear Security Administration and the Department of Energy national labs on nuclear-weapons safeguards, predates Mythos by two years7 and continues independently. Mythos itself reached the public not because Anthropic decided it was time, but because a misconfigured CMS database let Fortune scoop the story on 26 March 20268. The official announcement followed twelve days later.
And the cyber capabilities were sufficient that the White House began weighing an executive order requiring pre-release reviews of high-risk AI models9. As Scientific American put it, the worry is not science-fictional: a single private lab’s unreleased system has, by its mere existence, become the determining input to a public-policy timetable10. Let’s be clear about what that sentence describes. The democratic process is now reacting to artefacts it has not been shown, evaluated by a body it does not control, distributed under a programme name the public learned by accident.
This is what the competitive part of the competitive singularity actually looks like in 2026. Not theology. Not racing to the top. Not the romantic image of a foreign adversary stealing the weights. It is a single lab releasing a frontier capability inside a closed channel, the U.S. government accepting the role of pre-deployment evaluator, and the rest of civic society discovering the existence of the artefact only because a database was unsecured. Dario Amodei’s Machines of Loving Grace (October 2024)11 is the public-facing rationale for this posture: compressed decades of biomedical and economic progress are within reach, and the path runs through systems whose values must be earned, not assumed. Read that essay alongside the Mythos rollout and one structural fact emerges. The most safety-conscious frontier lab in the world cannot, by its own analysis of the strategic environment, slow down. It can only choose who sees the model first.
II. OpenAI’s Cyber Researcher
If Anthropic’s frame is institutional, OpenAI’s is operational. The release of an autonomous cyber researcher, a system that reads code, identifies vulnerabilities, proposes patches, and exploits where instructed, is the bluntest commercial expression to date of what Carlsmith12, in Is Power-Seeking AI an Existential Risk? (2022), called “agentic planning over open domains.”
The capability itself is not new in kind. Project Zero, ZeroFox, and the older lineage of fuzzing research have been pursuing pieces of it for years. What is new is the integration cost: a system that does what a senior offensive-security engineer does, at the marginal cost of inference tokens, available through an API.
This is not Skynet. It is something subtler and, in the short term, more consequential. It is the flattening of the offensive/defensive labour market in cybersecurity. A regional water utility, a small clinic, a municipal court: none of these have ever been able to afford a Mandiant retainer. They will not be able to afford one in 2027, either. But the attacker side of that equation is about to scale, and OpenAI’s product is the most visible signal of it. The question of how a democracy defends critical infrastructure against an unbounded supply of agentic adversaries is no longer a hypothetical. It is now the same conversation as whether your county clerk’s office can run a patch on a Tuesday.
III. DeepSeek’s Capital Cliff
The third leg is the one Western policy circles have spent the most ink misunderstanding. DeepSeek-V3 (December 2024)13 and DeepSeek-R1 (January 2025)14 did not merely close the capability gap with the U.S. frontier; they did so at, by their own published figures, roughly a twentieth of the training cost of the comparable American models. (Replicated independently by the Allen Institute and several European groups in early 2025.)
Read narrowly, this is a story about reinforcement learning from verifiable rewards and a clever mixture-of-experts architecture. Read broadly, it is a story about the collapse of the compute moat as a governance instrument. Western export controls, the CHIPS Act, and the Biden-era diffusion framework were all built on a thesis that frontier capability would remain capital-intensive enough that licensing GPUs would constitute meaningful policy leverage. DeepSeek’s contribution to the world was the demonstration that this thesis has a sell-by date, and that date has passed.
When the marginal cost of getting to within striking distance of the frontier falls by an order of magnitude, the strategic depth of the safety conversation falls with it. There is no longer a comfortable belief that “we have a few years to get this right because only three labs can afford to play.” The price of admission is dropping toward a number any well-funded sovereign actor (and many non-sovereign ones) can clear.
There is also a less-charitable reading worth taking seriously. Scott Galloway has put it directly:
“If I were advising Xi, I’d counsel him to go for the jugular by engaging in AI-dumping, a repeat of their aughts steel-dumping playbook. It’s already underway, and working. Eighty percent of a16z startups use open-source Chinese models. Same story at Airbnb. China is registering similar or better performance as the American LLM leaders, but with a fraction of the capex. Flooding the market with competitive, less-expensive AI models will put pressure on the margins and pricing power of the Mag 7, taking down a frighteningly concentrated S&P and likely sending the U.S., possibly the globe, into recession.”15
On this reading the twentieth-of-the-cost figure is not only a technical achievement to be admired. It is a strategic-dumping number, with specific evidence on the demand side: an a16z portfolio that has already switched, an Airbnb that has already switched, a Mag-7 margin profile that depends on the rest of the market not doing the same. The end-state Galloway has described over the past decade in steel, in solar panels, in lithium-ion batteries, and in drones is the same end-state his AI argument now names: capability moves to whoever is willing to subsidise it longest, and the strategic layer of the economy follows. If that is the actual game, the West’s response is not only a compute-export-control conversation. It is an industrial-policy one. And the AISIs have very little to say about it.
What This Adds Up To
A competitive singularity is not the same as a technical singularity. It does not require any one model to recursively self-improve in a server closet at 3 a.m. It requires only that three or more institutions, each rationally pursuing their position in the race, collectively push capabilities forward faster than alignment, deployment policy, and civic oversight can absorb. That is the world we are now living in.
Three reinforcing forces:
- Anthropic’s Mythos demonstrates that the most safety-conscious frontier lab is already distributing pre-release capabilities through a closed partner channel, with the U.S. federal standards body operating as evaluator-of-record rather than as a public slow-lane.
- OpenAI’s agents demonstrate that the gap between demo and deployed labour market is now measured in months, not years.
- DeepSeek’s economics establish that the compute-based governance frame the West has spent eight years building is structurally undersized.
None of these are catastrophes individually. Each lab is, by its own account, behaving rationally given the others. The danger is the joint trajectory: a fast takeoff that nobody chose, that no single party can stop, and that no current institution is scaled to govern.
A Civic Argument
This blog has, for years now, argued that the persistence of human institutions (journalism, the Electronic Frontier Foundation, open-source communities) is not nostalgia. It is structural. The reason is precisely the one Habermas gave for the public sphere16: collective sense-making is the operation by which a society stays steerable. When the rate of change in our technical substrate outruns the rate at which we can publicly metabolise that change, steerability fails. We end up, as Levitsky and Ziblatt warned in How Democracies Die (2018)17, with consequential decisions made by people we did not elect, against criteria we did not get to debate, on a timeline we did not consent to.
The right answer is not to ban the labs. It is not even, in any near-term policy-feasible sense, to pause them. The FLI open letter of March 2023 settled that question on the ground, regardless of how it reads on paper. The right answer is to build the civic instruments that can keep pace: international evaluation bodies with teeth (the U.K. AISI, the U.S. AISI now CAISI, and the EU AI Office are starting points, not endpoints); mandatory pre-deployment red-teaming on a treaty footing rather than a voluntary one; public compute and public alignment research at a scale comparable to what private labs deploy; and the slower, harder work of educating a citizenry that can tell the difference between a moral question and a benchmark number.
The fast takeoff is no longer one lab’s worry. It is three labs’ default. The cliff is shared. The question for the rest of us (the journalists, the lawyers, the open-source maintainers, the city-council members reading this from somewhere far from San Francisco) is whether we are still the kind of public that can decide, collectively, whether to step back from it.
History, on this point, is not encouraging. But history was not the public-sphere argument’s strongest defence in 1962, either, and the argument held anyway. It can hold again.
Notes
I. J. Good, Speculations Concerning the First Ultraintelligent Machine, Advances in Computers vol. 6 (1965). ↩︎
Nick Bostrom, Superintelligence: Paths, Dangers, Strategies (Oxford University Press, 2014). ↩︎
Anthropic, Claude Mythos Preview, red.anthropic.com, 7 April 2026 (official preview announcement). ↩︎
Anthropic, Project Glasswing, anthropic.com (programme description and partner list). ↩︎
Murad Hemmadi, Why Anthropic is putting an unreleased AI in front of more than 40 organizations, The Logic, April 2026 (identifies the internal codename Capybara and the cyber-capability briefing pattern). ↩︎
Matt Kapko, NIST relaunches AI testing arm as Center for AI Standards and Innovation, Cybersecurity Dive, 2026 (CAISI is the renamed U.S. AI Safety Institute and runs pre-deployment evaluations of frontier systems including unreleased ones). ↩︎
Anthropic, Developing nuclear safeguards for AI through public-private partnership, anthropic.com, April 2024 (the NNSA / DOE-national-labs collaboration on classified nuclear-weapons-relevant evaluations). ↩︎
David Meyer, Anthropic exclusive event exposes details of unreleased model via unsecured data store, Fortune, 26 March 2026. ↩︎
Lucian Constantin, Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models, CSO Online, May 2026. ↩︎
Lauren Leffer, What is Mythos, and why are experts worried about Anthropic’s AI model?, Scientific American, April 2026. ↩︎
Dario Amodei, Machines of Loving Grace: How AI Could Transform the World for the Better, October 2024. ↩︎
Joseph Carlsmith, Is Power-Seeking AI an Existential Risk?, 2022. ↩︎
DeepSeek-AI, DeepSeek-V3 Technical Report, arXiv:2412.19437, December 2024. ↩︎
DeepSeek-AI, DeepSeek-R1: Incentivising Reasoning Capability in LLMs via Reinforcement Learning, arXiv:2501.12948, January 2025. ↩︎
Scott Galloway, 2026 Predictions, No Mercy / No Malice. The same predatory-pricing pattern has been applied by Galloway in his Prof G coverage of solar, lithium-ion batteries, telecommunications equipment (Huawei), and drones over the past decade. ↩︎
Jürgen Habermas, The Structural Transformation of the Public Sphere (Polity, 1989; orig. 1962). ↩︎
Steven Levitsky & Daniel Ziblatt, How Democracies Die (Crown, 2018). ↩︎