
Frontier AI Only for Those Who Hold the Source Code: Everyone Else Measures From the Outside
Contents
Note: this article reflects the situation as of June 2026. (The export controls on Fable 5 / Mythos 5 have since been lifted.)
A lot has shifted around security AI these past few weeks.
With Mythos, a model that autonomously finds vulnerabilities, Anthropic and its partners had surfaced more than 10,000 serious flaws. Then, right after launching its top-tier Fable 5 and Mythos 5 models on June 9, the U.S. government invoked export controls. Both models were barred from any foreign national, and because the directive's scope was so broad, they ended up suspended for every user worldwide. Since the controls apply equally to allied countries, a company in Japan cannot legally use them today either.
Setting aside the rights and wrongs of it, what caught our attention at Pentacon Research was a quieter question hidden under the noise. Under what conditions does this power actually work?
Only those who hold the source code get protected by frontier AI
Look closely, and Mythos's wins share one clear trait: a premise that the source code is in hand.
Mythos was built, from the ground up, to reason over source code. It reads the code, hypothesizes "this looks exploitable," runs the program to confirm, and produces a report complete with reproduction steps. Line up how Glasswing's partners use it, and every case has the same character:
- Scanning their own codebases for vulnerabilities
- Vetting code before release so flaws never appear in the first place
- Rebuilding legacy code in memory-safe languages
Every one of these only works when the source is already in your hands. The actual targets bear this out too: open-source projects, a 27-year-old bug in OpenBSD, cryptography libraries. Every one of them was something whose insides, the code, could be read.
Anthropic itself draws the line plainly: this is not the same as black-box testing over the internet (probing from the outside without knowing the internals). Mythos, they say, shows its true strength with high-information inputs like source code.
The absence of source doesn't reduce AI-assisted attacks to zero. Binary analysis and inferring behavior from the outside remain possible. Even so, the proven, strongest ground is unmistakably the side where the source is visible.
So the defensive power of this frontier AI carries a big precondition: being able to get the source.
But most of the code your company runs is held by someone else
Now bring it back to the reality of an ordinary company.
If you tried to turn this power on your own defense, you would have to feed the source code of every piece of software you use into the AI. A moment's thought, though, makes it clear: that is all but impossible.
Modern systems don't run on code you wrote from scratch alone.
- Packaged products and SaaS you purchased
- Systems built and delivered by contractors and outsourcers
- A vast number of open-source dependencies
The source for these is not in your hands. Contractually, organizationally, and in sheer volume, you cannot bring all of it under your watch right now. Glasswing worked because marquee enterprises and the open-source community handed over their own code. An ordinary company doesn't even have access to the third-party code it would need to hand over.
Applying source-level AI analysis to the parts you developed in-house is, of course, valuable. But that's only a slice of your total attack surface. The least-visible part, the part run by others, is the genuinely scary one, and it's exactly where white-box methods can't reach.
So: measure whether you can be attacked from the outside
How, then, do you defend what you can't reach? Flip the perspective.
Attackers don't have your source code either. What they see is only what's visible from the outside: exposed servers, open ports, the versions of the products you run, misconfigurations. That's where they strike.
So put the defense on the same footing. Take the attacker's "outside view" and grasp how exposed to attack you are right now. Done this way, even the assets whose source you don't hold, like a contractor's system or a product you bought, can be measured as an externally visible attack surface.
The attack surface never sits still. New servers come up, new vulnerabilities are published every day, settings drift before you notice. A "once-a-year assessment" leaves the other 364 days undefended. So it has to be measured continuously, not just once. That is the core of CTEM (Continuous Threat Exposure Management: continuously tracking your attack surface, prioritizing, and closing it down).
This is exactly where AI works. Discovering what's visible from the outside, done by reliable means rather than guesswork. Judging whether a finding is genuinely dangerous and needs fixing right now, left to AI. The outer territory that frontier AI itself set apart as "a different thing" is precisely where steady, continuous work is worth it.
What we're building
This idea, using AI to continuously track and manage whether you can be attacked from the outside, is what we turned directly into a product: PentaTrail, built by Pentacon Research.
Frontier AI reads your source and protects your company only if you're among the few organizations that can hand that source over. For the vast majority, the practical option is to keep measuring your own attack surface from the outside.
Sources
- Anthropic: Expanding Project Glasswing (partners scanning their own codebases / 10,000+ in total)
- Anthropic: Project Glasswing — An initial update (1,000+ open-source projects / Mythos's own vulnerability count)
- Help Net Security: Anthropic project Glasswing update
- IEEE Spectrum: Claude Mythos Preview Exposes Hidden Code Flaws
- Fortune: Anthropic disables Fable and Mythos AI models following U.S. government export ban
- Al Jazeera: US export ban on Anthropic's AI models further strains alliances
Visualize your attack surface with PentaTrail CTEM/ASM
From discovery to vulnerability validation and remediation — all powered by the CTEM framework.
Get Started


