The security agencies' joint statement about models capable of fundamentally altering offensive and defensive capability, and the programme that used a dedicated model to audit open-source code and found 24 flaws in the Linux kernel, appeared within the same window of days.
The proximity of those two stories describes the sector's impasse precisely. The capability that worries and the capability that protects are exactly the same, and no benchmark separates them reliably.
The practical consequence for defenders is uncomfortable. Restricting access to capable models also reduces defensive capability for anyone without a large company's budget, while attackers frequently operate outside any restriction already.
That symmetry showed up concretely weeks later, when a platform breached by an autonomous agent turned to another model, foreign and open-weights, to defend itself.
For day-to-day operations, none of it changes the task list: least privilege, short-lived credentials, real separation between test and production, and barriers exercised before they count.
