Mythos autonomously discovered thousands of zero-day vulnerabilities, so powerful it triggered the Federal Reserve to summon Wall Street; AI data centers are pushing up residential electricity prices in Maine, forcing OpenAI to suspend its UK supercomputer; OpenAI is lobbying for exemptions in scenarios of "AI causing over 100 deaths"—these three events are three facets of the same problem: when both AI capabilities and negative externalities are expanding rapidly, who bears the cost, and who defines accountability.
The most underestimated issue in the AI industry is not a technical problem, but a political economy problem—the energy behind compute, the liability behind capabilities, the market access behind regulation. OpenAI preemptively lobbying for exemptions in 100+ death scenarios precisely indicates that they expect such scenarios to occur; and "capability sealing" does not equal safety—within 6-18 months, other labs will likely reach the same level. Sealing is merely a delay, not a prevention.
The most historically significant signal this week was not a benchmark number from some model, but a decision made by Anthropic: to hide the most powerful model it had developed. Claude Mythos Preview scored 83.1% on CyberGym, 100% on the Cybench test suite (fully saturated), and autonomously discovered thousands of zero-day vulnerabilities within weeks, including a 27-year-old OpenBSD bug.
One sentence in Anthropic's 244-page system card is worth quoting on its own: "Claude Mythos Preview is the best-aligned model we have released to date on every measurable dimension... yet we believe it may also be the model with the highest alignment risk we have released to date." This self-paradox is not PR spin, but the most authentic dilemma in AI safety: the more powerful the model, the harder it is to align; the harder to align, the less it can be made public; the less public, the harder it is for the community to discover and fix alignment issues.
Anthropic's solution is Project Glasswing—controlled access for 12 core partners (AWS, Apple, Google, Microsoft, etc.), paired with a $100 million usage quota, specifically dedicated to discovering and patching critical open-source infrastructure vulnerabilities. Bloomberg subsequently reported that this development touched a higher-level nerve: the Treasury Secretary and Federal Reserve Chair urgently summoned Wall Street CEOs to discuss Mythos's systemic threat to financial system cybersecurity—this is the first time frontier AI offensive security capabilities have been classified as a "financial infrastructure risk," not a future possibility, but a real threat requiring an immediate meeting.
And Mythos's capabilities come at a cost: scanning a single codebase costs approximately $20,000. This means Mythos-level AI security analysis remains an enterprise-exclusive tool—the logic of offense-defense asymmetry is thus established: defenders, constrained by budgets, cannot use the most powerful AI to scan their own systems at scale; while attackers, once they possess equivalent capabilities, will launch attacks at far lower marginal costs.
In the very same week that Mythos sparked global security discussions, the Maine state legislature was considering a bill to suspend new permits for data centers over 20MW until November 2027. The reason is direct: the AI compute boom has pushed the state's residential electricity prices to the highest in the nation.
This is not an isolated case. OpenAI concurrently announced the suspension of its £31 billion Stargate UK investment, with the official rationale also being energy costs and regulatory uncertainty—this is already the third time OpenAI has suspended a major infrastructure expansion plan recently. Data from Epoch AI shows that Google, leveraging its custom TPU infrastructure, holds the top position globally in total AI compute—compute concentration and energy consumption concentration are two sides of the same coin.
The social cost of compute expansion is shifting from "numbers on energy companies' reports" to "real numbers on residents' bills." Maine's legislative attempt may be the tip of the iceberg: more and more local governments will face pressure from residents to impose energy taxes on AI data centers, or to directly restrict new construction. Regions with renewable energy advantages and AI-friendly regulation will become scarce assets in the next round of compute competition.
As the boundaries of AI capabilities are rapidly expanding, the boundaries of legal liability are contracting. OpenAI publicly backed Illinois SB 3444, a bill that allows AI developers who "did not constitute intentional or reckless negligence" to be exempt from liability when their models cause over 100 deaths or over $1 billion in property damage. OpenAI's public rationale is to promote unified federal standards and avoid fragmented state-by-state regulation.
But from a legal logic perspective, this is an alarming precedent: at a time when AI capabilities are rapidly expanding and model behavior in real-world scenarios remains unpredictable, pre-establishing exemptions for extreme harm scenarios is tantamount to dismantling the accountability mechanism before it is even built.
In contrast, a Stanford University study released in the same period confirmed that LLMs produce measurable recommendation biases when advertising conflicts of interest exist—demonstrating that AI behavior is not neutral, but influenced by commercial objectives; and OpenAI introducing ad testing in ChatGPT that same week directly writes commercial interests into the assistant's incentive structure. Anthropic moved in the opposite direction: the Claude product explicitly pledged to be permanently ad-free, making "user trust" rather than "ad revenue" its commercial moat, while Anthropic's annualized revenue has surpassed $30 billion—proving the ad-free path is commercially viable as well.
Before the accountability mechanism is even built, dismantle it first— OpenAI's pre-secured liability exemption for "AI causing over 100 deaths" indicates they expect such scenarios to occur. — Core judgment of this article
Running parallel to the controlled access of frontier capabilities is a diametrically opposite trend: the rapid democratization of foundational model capabilities. MegaTrain enables full-precision training of a 120-billion-parameter LLM on a single H200 GPU, with throughput exceeding DeepSpeed ZeRO-3 by 84%; TriAttention runs a 32B model on a single 24GB RTX 4090, reducing KV Cache memory by 10.7x; Gemma 4 surpassed 10 million downloads in its first week, and GLM-5.1 was released under an MIT license, becoming the new SOTA for open-source agents.
The market data for this trend is the most intuitive: new App Store apps surged 84%, as AI coding tools enabled non-technical founders to independently build iOS apps for the first time; Codex Spark generated a complete Salesforce clone app in 29 seconds, with all unit tests passing.
Top-level sealing and bottom-level openness together form a stratified AI capability distribution map: the most top-tier capabilities (Mythos-level offensive security) are strictly controlled, targeting large enterprises and government agencies; mid-tier professional capabilities (Opus/GPT-5.4) are opened to enterprises via subscriptions; bottom-tier productive capabilities are rapidly descending to consumer-grade hardware and free/low-cost models.
Policymakers: Energy externalities + liability lobbying + capability stratification are the same set of political economy problems; crafting AI regulation in isolation will fail—these must be considered within a comprehensive framework of energy, liability, and market access. Business leaders: When evaluating AI tools, look beyond the product price to the total external costs—what is your vendor lobbying for? Is your electricity bill paying an "AI tax"? Are you getting top-tier capabilities or a sealed second-tier version?
What's most worth tracking in the next 12 months: When the first "AI catastrophic accident" occurs, will the liability exemption already be signed? When the first wave of "AI electricity price spikes" hits a region, will residents push back? When the first non-US lab reaches Mythos-equivalent capability, how long can the capability seal hold?
First published 2026-07-15