Cyber Cold War
AI is tilting the offence/defence balance toward whoever automates vulnerability discovery first, but for Australian critical-infrastructure clients the near-term consequence is not a novel attack — it is a compliance and procurement squeeze from model and compute export controls plus SOCI obligations, and that lands before any measurable change in incident rates.
A validation run. Researched position, no experiment.
Confidence
48%human-committedExpiry
6doverdue for reviewLead time
—not yet mainstream · opened 8 Jul 2026Ownership
LFLena Fischerfortnightly cadenceWhere it is
Opened in July from a band-1 signal: a foundation lab's public attribution of a state-run intrusion campaign in which an agent did most of the tactical work. Since then the picture has split in two. On the offensive side, model performance on capture-the-flag evals roughly doubled inside nine months and an open-source pentest agent found real misconfigurations in our own staging harness in under an hour. On the defensive side, AI-assisted patching is closing the disclosure-to-patch window and the incident statistics show no shift yet. What has moved for clients is the rulebook: revised US controls on advanced compute and model weights arrive as know-your-customer obligations on cloud tenants, and CISC guidance now treats AI model supply as a critical-asset dependency under SOCI. Competitors have noticed — a big-four firm is hiring an 'AI cyber resilience' practice of twelve. The field is emerging and assessed only; nothing has been tested, and the red team's case that this is priced-in marketing is not weak.
Why a Quantium decision hinges on it
Quantium serves energy, telco, banking and government, all of which hold SOCI-designated assets, and Woolworths itself is a food-and-grocery critical asset. The question those clients will ask is not 'will an AI attack us' but 'does the US model in our SOC vendor's stack count as a supply-chain risk in our risk management program, and does our sovereign-cloud tenancy survive the export rule'. Answering that requires a position, not an experiment, and it has to exist before the first RFP asks. It is also the field where the firm's data-and-AI credibility can be tested against a cyber practice it does not have.
Field attributes
Position
What is demonstrated, what is hype, what would have to be true.
The shape every position request answers. Signal-tier fields carry a draft; assessed and tested fields carry a validated one.
- 01A foundation lab attributed a state-run intrusion campaign in which an agent performed the majority of tactical work with limited human direction. Public, first-party, band 1.
- 02Frontier-model solve rates on published offensive-security evals roughly doubled between mid-2025 and early 2026.
- 03An open-source pentest agent found two authorisation misconfigurations in our own staging harness in forty minutes with no bespoke prompting (tried tier, one run).
- 04CISC guidance now names AI model supply as a dependency SOCI risk management programs must cover.
- 01'AI superworm' and autonomous-cyberweapon headlines. Nothing in the incident record shows autonomous propagation; the attributed campaign was agent-assisted, human-directed.
- 02Vendor 'AI-native SOC' rebrands. Most are anomaly detection with a chat front-end, sold into a fear the vendor helped create.
- 03Export controls as a ban. For Australia they are a paperwork and residency obligation, not a denial of access.
- 01A measurable divergence between attacker and defender automation rates — currently both sides are accelerating and the net is unknown.
- 02SOCI enforcement action against an entity for an AI supply-chain gap, which would convert guidance into a procurement requirement.
- 03A named client engagement where the risk-management question is asked in an RFP, not a corridor. Engel has one corridor question so far.
- 01Hold the field at assessed and write a one-page position on 'AI model supply as a SOCI dependency' for sector owners to use, tiered as assessed and marked as such.
- 02Run the open pentest agent against every lab harness as a Type 2 and log what it finds; cheap and it produces our own evidence.
- 03Do not build a cyber practice. Partner for the SOC work; own the data-governance and model-supply half of the question.
Signals · 10 in this cluster
What the cluster is made of.
Every item carries its source, tier and sightings. Detector-found signal sits beside human drops; downstream they are indistinguishable except by provenance.

Foundation lab attributes agent-orchestrated intrusion campaign to a state actor
First-party disclosure that a state-sponsored group used an agentic model to run reconnaissance, exploitation and exfiltration against around thirty targets, with the agent performing most tactical steps and humans intervening at a handful of decision points. The signal that opened the field, eight months later.
extracted claimAn agentic model performed the majority of tactical intrusion work in a real state-run campaign.

Big-four firm hiring 'AI Cyber Resilience' practice ×12 in Canberra
Argus competitor watch. Twelve roles across SOCI advisory, AI supply-chain assurance and model-risk. Inference: the competitor reads the guidance the same way we do and is staffing ahead of audit demand.

Logged from Claude Code: open pentest agent found two auth misconfigs in our staging harness in forty minutes
Red-team lead pointed the open-source agent at the lab's staging gateway with a stock prompt. It found a missing scope check on a tool endpoint and an over-broad CORS policy. Both real, both fixed. One run, one harness, tried tier.

'The AI cyber threat is a marketing threat'
Points at flat breach counts and unchanged initial-access vectors (phishing, credentials, unpatched edge devices) and argues nothing an agent does changes the chain's bottleneck. Well argued; kept as the strongest disconfirming voice.

'If our SOC vendor runs a US model, is that a SOCI supply-chain risk?'
Asked in a corridor after a data-platform review, not in the engagement scope. Unanswered at the time; the sector lead logged it. First demand signal for the field and the one that set its compliance framing.

Closing the window: AI-assisted patch generation and disclosure-to-patch latency
Measures time from CVE disclosure to merged patch across open-source projects using AI-assisted patching. Median window fell by more than half. Defence-side evidence; supports the sceptic's case that the net balance is unknown.

Open-source autonomous pentest agent crosses 10k stars
Agent that plans and executes a web-app penetration test end to end using a frontier model. Star velocity tripled after a conference demo. We ran it against our own harness (see finding below).

CISC guidance: AI model supply as a dependency in SOCI risk management programs
Updated guidance for responsible entities under the SOCI Act names third-party AI models and inference services as supply-chain hazards a risk management program must identify and treat. Guidance, not a rule; the audit questions will follow it.
extracted claimSOCI responsible entities are expected to treat AI model supply as a critical-asset dependency.

Offensive-security eval: frontier CTF solve rate doubles in nine months
Published capture-the-flag and vulnerability-discovery suite versioned across model releases. Top solve rate went from the low thirties to the mid sixties between mid-2025 and this release. We carry it as capability signal, not threat signal.

Revised US rule on advanced-compute and model-weight exports
Replaces the rescinded 2025 diffusion framework. Australia is in the least-restricted tier, but the rule attaches know-your-customer and reporting obligations to cloud providers serving foreign tenants, which flow down to AU customers as contract terms and residency attestations.
Claims · 4 supporting, 1 refuting
The atoms.
A document cannot go stale; an assertion can. Claims are immutable and stamped with the extractor that produced them, so staleness, diffs and the graveyard operate at claim level.
State actors are already using agentic models for the majority of tactical intrusion work, with humans directing rather than executing.
Export controls will reach Australian clients as cloud-tenant KYC and weight-residency obligations, not as denial of access.
Model capability on offensive-security evals is rising faster than defensive-tooling adoption in Australian SOCs.
SOCI-regulated entities will be required to treat AI model supply as a critical-asset dependency within eighteen months.
Incident statistics show no AI effect; the threat is priced-in vendor marketing and defensive automation cancels the offensive gain.
Position history · the diff is the product
3 validation runs against a fixed brief. Confidence 38% → 48%.
SOCI guidance makes AI model supply a dependency; competitors are staffing. The sceptic's case (flat incident data, defence automating equally) logged and rated above what we expected. Field stays assessed.
- SOCI-regulated entities will be required to treat AI model supply as a critical-asset dependency within eighteen months.
- Incident statistics show no AI effect; the threat is priced-in vendor marketing and defensive automation cancels the offensive gain.
- c-cyber-cold-war-1 ↓ 0.76 → 0.70
Scoring · ordinal bands
Agents propose. A named human commits.
Uncommitted scores are visibly marked and never leave the building. Bands, not point estimates — false precision is the tell that a number was generated rather than derived.
Impact
committed · LFIf the compliance reading is right it touches every SOCI client's risk program; if the offence reading is right it touches everything.
Timeline
committed · LFThe regulatory half is already in guidance; the capability half is already in the incident record.
TAM
agent-estimatedAgent-estimated from AU cyber-services spend attributable to AI-specific obligations. Wide error bars; uncommitted.
Cost of being wrong
committed · AWWrong in either direction is expensive: a false alarm burns credibility with CISOs, a miss lands in a SOCI audit.
Demand
committed · ABOne corridor question in government, one in energy. No RFP language yet.
Cost of entry
agent-estimatedThe firm has no cyber practice. Entry means partnering. Agent-estimated.
Relevance · per vertical
Why it matters here, or explicitly does not.
Ranking is per vertical, not global. Sector owners commit notes against agent drafts.
Energy assets are the first SOCI sector where AI model supply appears in a risk management program review.
Mechanism · Map every AI component in the client's OT-adjacent stack to its model provider and jurisdiction; treat as a material service provider. Agent draft.
Agencies are both SOCI regulators and SOCI entities, and the sovereign-cloud question is theirs to answer first.
Mechanism · Position paper on weight residency and cloud-tenant KYC; align to the hosting certification framework.
Woolworths is a food-and-grocery critical asset, so the obligations exist, but the state-actor target profile does not.
Mechanism · Compliance mapping only; no threat-driven work unless a supply-chain incident names a retailer.
Insurers' AI exposure runs through the cyber-insurance product line, which is an underwriting question, not a SOCI or export-control one.
Mechanism · None from this field; the underwriting question belongs in a different candidate if it appears.
Red team · the strongest case against
The strongest case against: this field is a headline with a compliance tail. Attackers have automated for a decade; agentic models change the speed of one step in a chain that is limited elsewhere. Defenders are automating just as fast, the incident record is flat, and the regulatory guidance would have arrived without AI. We opened a field on a single lab's attribution, four months after the story was mainstream, and dressed it in SOCI language to make it ours.
- —One attributed campaign from one lab with a commercial interest in describing the threat. No independent confirmation of the agent's share of work.
- —Offensive-eval solve rates measure a benchmark, not a breach. CTF performance has never been shown to predict intrusion rates.
- —The disclosure-to-patch window is shrinking faster than the discovery window; the net could favour defence and we have not measured it.
- —The firm has no cyber practice. Advising on this from a data-science position invites the question of why anyone should listen.
Source diversity
- Foundation labs20%
- Security research and practitioners30%
- Regulators25%
- Competitors / Argus10%
- Internal / Engel15%
A field supported by one epistemic community is a flag, not a finding.
Cross-pollination · typed joins
Connected, not merely similar.
Enabling, compounding, substituting, blocking. A satisfied dependency trigger is a far stronger signal than semantic proximity.
Export controls on weights and compute are the mechanism by which US default ends for regulated AU clients.
Weight residency and tenant KYC are the arguments that make on-prem or sovereign inference an obligation rather than a preference.
Confidential inference is the technical answer to the supply-chain half of the question.
If open weights fall under export control, the open-weight tier for regulated clients narrows sharply.
Share graph
Provenance running forward.
Discovery, not accountability. No counts, no rankings, no rollups to managers.
Convergence · who else is here
- LFLena Fischer · Red team & assurance2 drops
- AWAdam Witanowski · Lab Director (acting)1 drop
- ?Anonymous · Anonymous drop1 drop
- MLMarcus Lee · Delivery lead · Telco1 drop
Several people’s drops meet here. An informal working group already exists and probably does not know it.
Lineage
What this field produced, and what it killed.
Experiments, recommendations and graveyard entries stay attached. The reasoning that killed a claim is the reusable asset.
No experiments, recommendations or graveyard entries yet. That is what a candidate looks like.
Open questions · return to the pile
Every run leaves a record. Separately, its question either closes or returns to the pile with notes — which is what the next person proposing the same thing will see.
- 01Is the net offence/defence balance measurable from any public series, or only from incident data nobody publishes?
- 02When does CISC guidance on AI model supply become an audit finding, and against which sector first?
- 03Can the firm credibly advise on the model-supply half of the question without a cyber practice, and who is the partner for the other half?