Two offensive AI models shipped this week. The interesting one is not from a frontier lab.
Two things happened in security this week, and most of the coverage folded them into one story about AI getting dangerous. They are two different bets, and only one of them is really about capability.
OpenAI shipped GPT-6 Astra and declared it the first model to cross the "Critical" cybersecurity threshold in its own Preparedness Framework. It scored 100% on ExploitBench, up from 78.5% for the model before it, and in internal testing it found two previously unknown vulnerabilities and chained them without a human directing each step. The public version refuses to write proof-of-concept exploits. The real offensive capability sits behind a vetted-defender programme.
Days earlier, CrowdStrike opened its Fal.Con keynote with SafeMind: two purpose-built cybersecurity models developed with NVIDIA, one offensive and one defensive, trained on fifteen years of the company's own incident-response fieldwork and sensor telemetry. The offensive model probes a digital twin of the customer's environment for attack paths. The defensive model remediates what it finds. The loop repeats until there are no paths left.
The first is a capability announcement with a policy wrapper around it. The second is a deployment architecture. After a couple of hundred production systems, I know which shape survives contact with a customer.
To be fair to the frontier release, it gives us something valuable: a number. We now know, from a lab willing to publish it, roughly where autonomous exploit discovery actually sits. That is more disclosure than most labs offer. It also tells you almost nothing about whether you can use it.
Because the question a security team asks is not "can this model find a zero-day." It is "will legal let me stream production telemetry to an API in another jurisdiction so it can try." I have never seen that answered yes on the first pass.
The closest work I have done to this is drone threat detection for defence and police users, running at 94% precision on hardware someone carries into a field. Nobody on that programme ever asked me whether a larger model would score a few points higher. The question was whether the thing would run at all, in a place with no uplink and no permission to send a single frame anywhere. That one constraint settled the architecture before any model was chosen.
Security telemetry is the same class of problem, only harder. It is the most sensitive data an enterprise holds, it is enormous, and it is exactly the data an attacker would want a copy of. The idea that it would flow out to a general-purpose frontier API for analysis was never going to clear a review board. So the winning shape was always going to be a narrower model, trained on domain data, running close to the environment it defends.
Which is why I think the digital twin is the real product in that announcement, not the two models. A simulated copy of your environment is the one place an offensive model is allowed to be genuinely aggressive, because nothing it breaks is real. That is not a model capability. That is an engineering decision about where you let the dangerous thing run. Frontier labs solve the same problem with lawyers and access tiers. A simulator solves it with topology.
Two cautions, because I would rather be useful than enthusiastic.
The performance figures in that launch are vendor figures: higher detection, faster remediation, dramatically lower cost, all measured against a baseline the vendor selected, with no independent audit published. Treat them as a hypothesis, not a result. And a twin is only as good as its fidelity. If your simulated environment does not include the forgotten jump host with a hardcoded credential on it, the offensive model will never find the path that an actual intruder will use first. Every red-team system I have worked with fails in the gap between the map and the territory.
The other caution is one I keep repeating and will keep repeating. Neither of these is open. No published sizes, no downloadable weights, standalone access through a programme with no public documentation. A model that runs inside your environment is not the same thing as a model under your control. It is someone else's model on a shorter cable, and when the licence terms change you will discover the difference.
Still, the direction is right, and it is the direction I have been arguing for since the days when running anything locally meant quantising until the output was gibberish. Domain data beats general capability for narrow work. Proximity to the data beats raw intelligence when the data cannot move.
Capability was the scarce resource for about three years. It is not the scarce resource now. Permission to sit next to the data is. Build for that, not for the leaderboard.