Status: Public working draft. This policy argument uses a fictional stress-test scenario. It does not claim knowledge of a specific planned attack, assign a literal 100-percent probability to economic destruction, provide legal advice, or dismiss conventional AI-loss-of-control risk.
1. The man in the room
It is 2:17 in the morning. The room could be in Richmond, Bucharest, Lagos, Shenzhen, or nowhere near the flag that will eventually be blamed. There are no glowing green maps and no cinematic countdown. There is a rack of commodity GPUs, several stolen cloud credentials, a refusal-stripped open-weight model, an autonomous offensive framework, and one tired human giving the system objectives.
The model does not need to invent one magical exploit that opens everything. It inventories. It fingerprints. It checks exposed management consoles, VPNs, hypervisors, identity systems, storage gateways, development servers, forgotten appliances, and remote-management tools. It correlates public documentation with leaked credentials and known vulnerabilities. It tests combinations that human triage once labeled “medium” or “low.” It remembers what worked. It dispatches subagents. When a target is difficult, it tries a different route.
The operator is not trying to steal one database. He is building a firing system. Once it reaches enough organizations, the payload will destroy accessible data, poison identity and configuration, disable management planes, move laterally into operational systems, and delete every recovery copy it can reach. The campaign will begin everywhere it can, nearly at once. The operator is waiting for coverage, not inspiration.
Then he will press the button.
This scene is fictional. It is not evidence that a particular person is running this exact operation. It is a stress test assembled from capabilities and precedents that already exist in pieces.
The pieces matter. The UK AI Security Institute reports that leading models went from less than 9-percent success on apprentice-level cyber tasks in late 2023 to roughly 50 percent, on average, in its 2025 testing; it also observed the first success on some expert-level tasks. The same report says models still struggle with realistic long sequences in cyber ranges. That limiting evidence is important: the autonomous super-hacker is not finished.1
But attackers do not need a finished super-hacker. Anthropic's September 2026 threat report—company threat intelligence, not an independent census—describes observed operations in which multi-agent systems conducted reconnaissance, exploitation, credential theft, lateral movement, malware adaptation, and exfiltration. It reports opportunistic actors using AI to accelerate scanning and exploitation of internet-facing systems and an actor using persistent, parallel workflows for vulnerability research and target reconnaissance.2
Dario Amodei describes the underlying barrier that AI is removing. Large-scale destruction has historically required both motive and ability. In his formulation, “ability and motive may even be negatively correlated”: the people with the rare discipline and expertise to cause extraordinary harm often have careers, stability, and much to lose. AI can “break the correlation between ability and motive” by renting capability to a malicious person who never developed the corresponding expertise.23 His discussion centers heavily on biology, but the general mechanism applies directly to cyber operations. The supply of people who want to burn systems down does not need to grow. The number who can plausibly try does.
And destructive propagation does not require AI. In 2017, NotPetya spread worldwide. The White House called it the most destructive and costly cyberattack in history at the time and said it caused billions of dollars in damage across Europe, Asia, and the Americas.3
The scenario is therefore neither prophecy nor science fiction. It is a planning question:
What happens when the reach of NotPetya meets the labor compression, persistence, adaptation, and parallelism of agentic AI?
That is what AI doom looks like in this paper.
2. Define the probabilities before they mislead us
Three symbols organize the argument.
p(hack) is the probability that a capable actor attempts an AI-amplified campaign intended to cause systemic cyber disruption across the American economy or its critical dependencies.
p(doom) is the probability that the post-attack system settles into sustained institutional, economic, and political breakdown: essential services fail for long periods, trust collapses, recovery becomes coercive or unequal, and advanced technology amplifies fragility rather than freedom.
p(fab) is the probability of the opposite long-run attractor: broadly shared, rights-preserving abundance in which AI, automation, and digital twins expand productive capacity while people retain standing, agency, security, and a meaningful claim on the gains.
p(hack)=100% is not a frequency estimate from a dataset. It is a preparedness axiom: the United States should plan as if at least one serious campaign will be attempted. The claim is about hostile intent meeting diffusing capability—not certainty that the campaign will succeed or that every system will fail.
Likewise, p(fab) + p(doom) = 1 is not an actuarial identity. Real futures can be mixed: abundance for some, collapse for others, long stagnation, partial recovery, or repeated shocks. The equation is a decision model that normalizes two opposing destinations. Every increment of survivable, legitimate, broadly distributed capacity moves the system toward Fab. Every increment of correlated fragility moves it toward Doom.
This framing also does not disprove runaway-AI or loss-of-control risk. The AI Security Institute treats that possibility seriously while reporting limited evidence that current models can autonomously reproduce and persist in real conditions.1 The point is narrower: we do not need to resolve the alignment debate before acting against a catastrophic AI-enabled cyber pathway already visible in the evidence.
Our generation is not choosing whether powerful AI arrives. It is choosing whether the institutions that deliver food, energy, health care, finance, communications, government, and employment can survive its offensive diffusion.
3. There are two economies, and they share one failure surface
The first economy is the AI-native economy. Its products and operations are designed around models, agents, machine-readable state, software-defined infrastructure, rapid deployment, and increasingly, digital twins. A digital twin can represent a codebase, factory, network, supply chain, customer operation, or business process closely enough that machines can simulate changes before committing them. In the best case, this economy can inspect, test, patch, replace, and restore at machine speed.
The second is the legacy economy. “Legacy” is not an insult and does not mean obsolete. It means the installed economy producing real revenue and essential services now: custom applications, old databases, unsupported appliances, industrial controls, medical devices, acquired business units, spreadsheets, VPNs, identity forests, managed-service relationships, manual approvals, and systems whose original engineers retired years ago.
Economy A is being born with the representational and automation layers defensive coscaling needs. Economy B usually is not.
But A and B are not separate islands. The AI-native economy depends on legacy electric power, telecom, water, finance, logistics, law, and government. The legacy economy increasingly depends on AI-native cloud, identity, software, and data platforms. A modern agent can be secure while the hospital, bank, energy provider, or government system it calls is not. A 40-year-old process can be protected by a modern cloud control plane until one tenant misconfiguration, stolen identity, or provider incident crosses the boundary.
The distinction is therefore analytical, not jurisdictional. The Hack wins through the coupling.
That is why waiting for Economy A to replace Economy B is not a strategy. The replacement could take decades; the attack window is measured in model releases, exploit cycles, and minutes of exposure.
4. The three paths in—and why reachable technology comes first
Most material intrusions can be organized into three overlapping pathways:
- Exploitable technology: unpatched software, insecure configuration, exposed services, weak architecture, vulnerable dependencies, zero-days, and combinations of individually modest conditions that form a usable route.
- Human and identity compromise: phishing, social engineering, token theft, session hijacking, password reuse, help-desk manipulation, consent phishing, and misuse of valid accounts.
- Trusted access abuse: malicious or coerced insiders, compromised vendors, managed-service providers, software updates, administrators, and supply-chain relationships.
These are not mutually exclusive. A phished credential may expose a management console; a vulnerable appliance may yield tokens; a compromised vendor may use legitimate remote administration; an insider may disable recovery before a wiper runs.
The first national sprint should focus on publicly reachable technical attack paths for three reasons.
First, they are discoverable by attackers at global scale. CISA already operates Cyber Hygiene scanning for enrolled internet-accessible assets, showing that continuous outside-in measurement is a deployable service, not a research fantasy.4
Second, they can become standardized machine work: discover, fingerprint, map dependencies, validate safely, find a fix or compensating control, test it, deploy it, and verify closure.
Third, the attacker can reuse them across victims. A phish usually requires some adaptation. A remotely exploitable service or common managed tool can create a correlated opening across thousands of organizations.
“Patching” in this paper is therefore shorthand for a larger closure operation. NIST defines enterprise patch management as identifying, prioritizing, acquiring, installing, and verifying patches, updates, and upgrades—and calls it preventive maintenance and a cost of doing business.5 Defensive coscaling also includes reconfiguration, isolation, decommissioning, identity hardening, segmentation, egress restriction, and verified recovery when no patch exists.
The focus on reachable technology does not mean phishing, insiders, zero-days, or poisoned updates can wait forever. It means national mobilization needs a first measurable boundary. The public attack surface is where adversaries already automate, where government can observe without entering private networks, and where leaving a known route open imposes risk on everyone downstream.
5. Defensive coscaling
Defensive coscaling is the continuous expansion of defensive speed, coverage, quality, and recovery capacity in step with—preferably ahead of—the expansion of attacker capability and the defended environment.
It is not “buy AI for the SOC.” It is a race between two closed loops.
The offensive loop is:
discover → understand → exploit → expand → destroy → adapt
The defensive loop must be:
inventory → model → detect → decide → remediate or contain → verify → recover → learn
The practical requirement is:
For material attack paths, defensive time-to-closure must remain below adversarial time-to-reliable-exploitation, at national—not merely enterprise—coverage.
That requires seven capabilities working together:
- Live inventory. Know the public service, domain, certificate, address, application, identity boundary, owner, vendor, version, business function, dependencies, and recovery tier—and know when any of them change.
- Contextual attack-path reasoning. Preserve severity information, but stop treating one score as the answer. NIST has long warned that CVSS should not be the sole measure of organizational risk and that it does not represent vulnerability chaining.6 Attack graphs exist precisely because multiple conditions combine into paths.7
- A remediation factory. Generate and test patches, configuration changes, isolation rules, compensating controls, and retirement plans. DARPA's 2025 AI Cyber Challenge demonstrated the possibility: competing systems analyzed 54 million lines of code, found 54 of 63 synthetic vulnerabilities, patched 43, found 18 real flaws, supplied 11 real-world patches, and averaged 45 minutes per patch submission. That was a competition, not proof of safe unattended production deployment—but it showed that machine-speed defensive engineering is real.8
- Bounded containment. If safe remediation cannot happen before exploitation, remove the service from public reach, revoke credentials, block the path, or isolate the asset. Containment should be narrow, reversible, logged, and preauthorized where seconds matter.
- Independent verification. The system that found or generated the fix cannot be the only system that declares success. Re-scan externally, re-test functionality, confirm policy, and retain a signed receipt.
- Recovery outside the blast radius. CISA advises offline, encrypted backups, regular availability and integrity testing, segmentation, and protection against deletion of accessible recovery copies.9 A backup administered through the same compromised identity plane is a promise, not recovery.
- Collective learning. Convert each observed attack, false positive, failed patch, workaround, and restoration into minimized, signed defensive knowledge that can protect other participants without centralizing their ordinary business data.
Defensive coscaling is achieved when those capabilities improve as quickly as offensive models, the number of assets, and the rate of change. A quarterly scan followed by a spreadsheet is not coscaling. Ten thousand unowned findings are not coscaling. A chatbot that recommends a patch nobody can test or deploy is not coscaling.
The unit of success is not the finding. It is the closed, verified attack path plus a tested way back.
6. The legacy economy pays IT to keep vulnerable systems stable
Some hyperscalers, defense contractors, major financial institutions, and very profitable technology firms can build portions of defensive coscaling. Most of Economy B will not—not because its operators are indifferent, but because the organization has given them the opposite objective function.
Operations teams are measured on uptime, latency, ticket closure, change failure, cost, and whether revenue systems remain available. A five-nines service-level agreement makes every minute of downtime visible. Vulnerability exposure is usually a finding in a report; an outage is an executive phone call.
The asymmetry is personal. The system administrator who delays a patch and preserves production may receive no consequence at all. The same administrator who deploys a vendor patch that crashes a revenue server can be blamed immediately, lose a weekend, and join a multi-day recovery. The company has taught the team the lesson it then condemns: a known vulnerability is somebody else's probabilistic future problem; a failed change is your present emergency.
NIST's patch-management guidance identifies a divide between business or mission owners and security or technology management over the value of patching, even while calling patching necessary preventive maintenance.5 Google's Site Reliability Engineering material describes the same incentive problem in operational terms: product teams are evaluated on velocity while SRE teams are evaluated on reliability, creating predictable resistance to change. Google uses shared error budgets to make the tradeoff explicit and align the teams.24
The legacy economy usually has an availability SLO. It rarely has an equally binding exposure SLO. It may reward five-nines uptime while imposing no comparable consequence for running a public service with a known reachable path to material control. Boards and C-suites ask for revenue growth or cost reduction. Aggressive patching consumes engineering capacity, requires redundancy and testing, creates visible change risk, and can hurt both targets in the current quarter. Avoided catastrophe does not appear as revenue.
That incentive structure makes defensive coscaling irrational from inside the current scorecard even when it is essential from the perspective of the country.
Other forces reinforce the trap:
- The benefit is diffuse. A company pays the full cost of remediation while many benefits flow to customers, counterparties, sectors, and the public.
- The harm is delayed and probabilistic. Revenue work is immediate; avoided catastrophe is invisible.
- Control is fragmented. The operator, software vendor, cloud provider, MSP, hardware maker, and business owner each control different parts of the path. Every contract can become an argument about whose job it was.
- Small firms lack people and bargaining power. They cannot staff 24-hour engineering, negotiate bespoke hyperscaler terms, reverse-engineer abandoned appliances, or evaluate an AI-generated fix.
- The market rewards claims more quickly than evidence. Certifications, dashboards, cyber insurance forms, and point-in-time audits can become substitutes for continuous verified closure.
- Attackers share exploit knowledge faster than victims share defensible fixes. Victims fear liability, reputation loss, and regulatory exposure; criminals monetize reuse.
Cloud does not dissolve this problem. Treasury found that adoption is concentrated particularly in AWS, Google Cloud, and Microsoft Azure and that a large provider failure or breach could affect multiple financial institutions or consumers. Treasury also cautioned that the mere presence of large providers is not itself the problem; architecture and use determine operational risk, and provider scale can improve zero-day patching.10 GAO similarly found that companies need clear responsibility boundaries, continuous monitoring, incident response, recovery planning, metrics, and exit strategies.11
The phrase “AWS/Azure/GCP must be 100-percent successful” captures the stakes but not the engineering. No provider can promise 100-percent prevention, and provider success is necessary but insufficient. AWS, Microsoft, and Google each publish a shared-responsibility model: the provider secures portions of the underlying cloud while the customer retains responsibility for data, identities, configuration, and varying layers of operating systems, applications, and networks.12
A flawless data-center floor cannot rescue a tenant that exposes an administrative interface, grants a destructive role to a phished identity, stores every backup under one account, or deploys vulnerable code. Conversely, perfect tenant configuration cannot repair a compromised provider control plane.
This is the market failure: everyone is responsible for a slice, nobody is responsible for the national rate of closure, and the people closest to the systems are punished for moving faster.
6.1 Replace the uptime SLO with a Continuity SLO
The answer is not to stop caring about uptime. It is to stop treating insecure uptime as success.
Every covered board should adopt a Continuity SLO with four coequal measures:
- Availability: the service performs its essential function.
- Clean exposure: the public surface has zero known, reachable, unmitigated attack paths under continuous independent measurement.
- Closure latency: a newly disclosed or discovered dangerous path is safely patched, isolated, or removed from public reach within the required interval.
- Recoverability: the essential function can be restored from a clean, independently administered recovery plane within a tested objective.
A service that is reachable but materially exploitable is not “up” for governance purposes. It is operating in a failed continuity state. A service removed from the internet for emergency containment is also unavailable—but the scorecard should distinguish a controlled defensive isolation from negligent exposure and should charge the root cause to the business owner and architecture, not scapegoat the operator who contained it.
The directive must start at the board, pass through the CEO, CIO, CISO, and business owners, and reach every engineering and operations team:
- the continuously clean public surface is the company's top operational priority during the mobilization;
- executive compensation and business-unit scorecards include exposure age, closure latency, and tested recovery—not uptime alone;
- security maintenance receives protected change windows, redundancy, digital-twin testing, blue-green or rolling deployment, automated rollback, and replacement funding;
- feature work and discretionary launches stop when the organization exceeds its exposure budget, just as mature SRE programs stop ordinary releases when reliability budgets are exhausted;
- a business owner who refuses remediation accepts the recorded risk and penalty rather than transferring it silently to IT; and
- no plan may depend on exhausted people working for 72 hours. Fatigue is itself a control failure, so relief coverage and maximum emergency shifts are part of continuity engineering.
The SEC already requires covered public companies to describe board oversight and management's role in material cybersecurity risk.25 Disclosure is not the same as performance. The Duty of Cyber Continuity should convert oversight into a measurable obligation: the board must know whether the company's public surface is clean, how long dangerous paths remain open, whether operators have the architecture and authority to close them, and whether recovery actually works.
The objective is uncompromising even though measurement is bounded by what can be known: 100-percent clean, 100 percent of the time, against everything the organization and national system can currently know and safely test. Unknown zero-days prevent proof that no vulnerability exists. They do not justify tolerance for a known reachable path.
7. A Manhattan Project for defense—without Manhattan Project secrecy
The analogy is scale, urgency, concentrated authority, scientific engineering, and guaranteed national demand. It is not a proposal for a secret wartime laboratory, one brittle super-system, or unlimited executive power.
America needs a National Defensive Coscaling Program with a ten-year charter and an emergency first three years. It should combine CISA, NIST, sector regulators, the National Cyber Director, national laboratories, universities, cloud and security providers, insurers, open-source communities, state governments, and a federally supported field workforce.
Its mission would be explicit:
Reduce the maximum time that a materially exploitable public attack path remains open; contain paths that cannot be fixed; prove essential-service recovery; and make every verified defense available across the economy faster than an attacker can reuse the route.
The program would not own every network. It would set the measurable duty, operate common infrastructure, finance the compliance path for organizations that cannot build it, and intervene when exposed risk threatens others.
7.1 The federal duty
Congress should impose a Duty of Cyber Continuity on every legal entity that operates a material service reachable by untrusted public networks.
The responsible party is not simply “who owns the public IP address.” Addresses may belong to clouds, carriers, CDNs, hosting providers, or shared platforms; they change, and one address may front many tenants. The duty should attach to a Responsible Internet Service Operator: the verified entity with operational control over the exposed service, together with every supplier that controls an indispensable layer of remediation.
Each operator must:
- register material public domains, addresses, certificates, services, cloud tenants, and responsible vendors in a protected national registry;
- designate a natural-person Business Authorizing Official and an accountable security operator;
- accept safe, continuous outside-in measurement by an accredited service;
- maintain machine-readable internal asset and dependency evidence sufficient to map an external finding to a business system and controlling party;
- close or contain remotely exploitable attack paths within statutory deadlines;
- preserve signed evidence of remediation and independent verification;
- maintain independently administered recovery for essential services and prove restoration through exercises; and
- report material exploitation, concealment, and recovery failure.
The board—not the system administrator—owns the resulting corporate duty. Each covered board must receive a continuous public-exposure dashboard, approve the Continuity SLO, fund the architecture needed to meet it, and certify at defined intervals that the company has no known, reachable, unmitigated material attack path. The CEO and responsible technology executives must attest to the same evidence. Operations teams own execution within authority; senior leadership owns priorities, resources, and accepted residual risk.
CISA's June 2026 BOD 26-04 already supplies a federal prototype. It warns that AI may narrow the time between patch release and exploitation; prioritizes using public exposure, known exploitation, exploit automation, and technical impact; requires continuing external scanning; and moves toward machine-readable asset reporting.13 The proposed law would extend the operating logic beyond federal civilian agencies, add attack-path context and recovery, and supply capacity rather than merely issue deadlines.
7.2 Do not abolish severity. Abolish severity as an excuse.
The instinct to discard “critical/high/medium/low/informational” is understandable. AI can chain conditions that appear modest in isolation. A medium-severity information leak plus a low-severity misconfiguration plus an overprivileged identity can become total compromise.
But removing severity information would make the defender stupider. The correct move is to stop allowing a base score to end the inquiry.
Every finding should enter a path calculation that includes:
- public reachability;
- active or known exploitation;
- feasibility of full automation;
- degree of post-exploitation control;
- available privileges and identity adjacency;
- chainability with other findings;
- business and safety criticality;
- prevalence across organizations;
- compensating controls; and
- recovery consequence.
Current BOD 26-04 expressly focuses resources on highest-risk combinations and defers lower-risk vulnerabilities.13 A private-sector regime should go further by detecting chains, but it should not force a rural clinic to patch an unreachable low-impact library before isolating an internet-facing route to domain administration.
The rule should be:
No known, unmitigated, remotely exploitable path to material control may remain open beyond its deadline merely because its component findings carry modest individual scores.
7.3 Deadlines that force action
The end state is not “patch monthly” or even “patch daily.” For public services, the target is patch or isolate within minutes of authoritative disclosure or validated discovery. The clock begins when defensive evidence becomes available, not when the next change window opens.
That target is unsafe on today's legacy architecture. Installing every new package immediately into a single production server would create the very outages operators are punished for. The national program must therefore make minutes possible by funding digital twins, redundant capacity, automated regression and exploit tests, signed update provenance, canary or blue-green deployment, automatic rollback, and preauthorized network isolation. If the fix cannot be proved safe in time, the service leaves public reach until it can be.
Congress should authorize CISA to set dynamic deadlines through transparent rulemaking. During the transition, a presumptive ceiling could be:
- 72 hours: publicly exposed, automatable paths yielding material or total control when exploitation is known or an emergency determination is issued; forensic triage is required.
- 7 days: other publicly exposed paths yielding material control, including chains with validated exploitability.
- 30 days: reachable conditions that materially reduce the work needed for compromise but lack a validated end-to-end path.
- 90 days: lower-risk conditions under a documented remediation plan, provided no new evidence shortens the clock.
Those are maximum legal ceilings for a legacy transition, not the defensive-coscaling objective. CISA should ratchet them downward as the national stack proves that a class of path can be closed safely in minutes.
If a vendor patch is unavailable or unsafe, compliant action can be isolation, removal from public reach, disabling the feature, adding a verified compensating control, migrating the service, or decommissioning the asset. “We cannot patch it” cannot mean “therefore everyone must accept the exposure.”
Deadlines should change when facts change. CISA already uses that logic: removing public exposure can change the required treatment, while addition to the KEV catalog can shorten the clock.13
7.4 Penalties with a hard edge and a constitutional spine
The original hard-line formulation—one percent of company revenue, per vulnerability, every 30 days, escalating to jail—correctly recognizes that trivial fines become a cost of doing business. As written, however, it would fail its own mission.
A scanner cannot prove “zero vulnerabilities.” Unknown flaws exist. Findings duplicate one root cause. Vendors control fixes customers cannot make. Shared addresses do not identify the responsible tenant. Good-faith patching can interrupt essential services. Compounding a percentage of revenue for every scanner signature could bankrupt a firm before it could remediate, create incentives to hide assets, punish the wrong entity, and turn independent researchers into existential threats. Automatic imprisonment for the existence of a flaw would erase intent and individual culpability—the opposite of federal sentencing's requirement that punishment be sufficient but not greater than necessary.14
The enforceable version should remain severe:
- Civil penalties attach to overdue verified attack paths or violated duties, not raw scanner findings.
- The first penalty band should be material—potentially up to one percent of annual U.S. revenue for each unresolved 30-day enforcement period involving an exposed material-control path—subject to entity-wide caps, aggravating factors, and judicial review.
- Penalties escalate for recurrence, concealment, broad prevalence, unsafe common products, missed emergency deadlines, and failure to protect recovery.
- Regulators may order removal from public reach, suspend a service, restrict procurement, require an independent monitor, or disqualify a vendor from high-consequence markets.
- Officers must certify material exposure and remediation evidence. Compensation clawbacks and director/officer consequences should attach to knowing false certification and sustained governance failure.
- Criminal liability is reserved for natural persons who knowingly falsify evidence, conceal material exposure, obstruct measurement, corrupt the defensive system, intentionally aid an attacker, or willfully defy a lawful emergency order while creating substantial risk. Ordinary mistakes, unknown zero-days, contested good-faith judgments, and inability despite documented effort remain civil or administrative matters.
DOJ's prosecution principles require assessment of evidence and culpability; federal sentencing law requires individualized proportionality.14 That is not softness. It is how a law survives, obtains truthful reporting, and distinguishes negligence from sabotage.
The FTC already uses data-security orders that require security programs, independent assessments, and truthful representations.15 CISA's Secure by Design program argues that manufacturers should own customer security outcomes instead of pushing the whole burden downstream.16 Congress should turn these fragments into one allocation rule: liability follows control, knowledge, duty, and refusal—not proximity to the last vulnerable address.
7.5 Capacity before punishment
A mandate without an affordable compliance path would accelerate consolidation, close small organizations, and transfer markets to the largest platforms. That is not resilience.
The federal government should therefore provide:
- no-cost baseline external measurement;
- an open-source local Continuity Node or accredited equivalent;
- national defensive model inference and signed remediation packs;
- a shared Cyber Steward option for small organizations;
- grants and zero-interest financing for replacement of unsupported systems;
- vendor-maintainer funds for critical open-source projects;
- emergency engineering teams for hospitals, utilities, local governments, and other essential services;
- catastrophe reinsurance and a conditional civil safe harbor for truthful, continuously verified participation; and
- a compensation fund for people harmed despite compliant defense.
The duty is mandatory. The federal implementation path is not. A capable firm can comply independently if it produces equivalent evidence. Everyone else can enroll in the public utility.
That design makes enforcement morally and operationally credible: the country is not jailing a small-business owner for failing to buy a product that does not exist. It is offering the machinery, setting the duty, measuring the result, and punishing refusal or deceit.
7.6 The open National Defensive Coscaling Stack
The common machinery should be a public good, not a procurement category. The federal program should maintain an open-source National Defensive Coscaling Stack that any organization can download and run against systems it owns or is authorized to test.
The stack should:
- verify the operator and authorized target scope;
- discover exposed services continuously and map them to an accountable entity and local asset;
- fingerprint software and configuration without unsafe exploitation by default;
- combine known exploitation, automability, technical impact, identity adjacency, dependency, and chainability into attack paths;
- call a federally operated, no-cost, frontier-class defensive model service to analyze unfamiliar systems and generate proposed patches, configuration changes, isolation rules, or migration plans;
- test proposed changes in a digital twin, sandbox, replay environment, or canary;
- deploy only within explicit local authority, with automatic rollback and a deterministic emergency-isolation path;
- verify closure from inside and outside the environment; and
- produce signed, machine-readable evidence for the operator, board, insurer, customer, and regulator.
The stack should be open source: connectors, data schemas, policy engine, test harness, action receipts, evaluation suites, and reference implementations. The federal frontier model service should be free at the baseline and operated as governed critical infrastructure. That does not require publishing unrestricted model weights or offensive tooling. Access can be purpose-bound, logged, rate-limited, scoped to verified assets, red-teamed, and independently evaluated. Company data remains local unless the operator authorizes a minimized defensive exchange.
This is the capacity counterpart to coercion. Every covered organization receives a credible answer to “with what?” before the government demands “by when?”
8. The operating architecture
The National Defensive Coscaling Program needs four separable planes.
8.1 National exposure plane
This plane maps material internet-facing services to verified entities, scans safely, correlates certificates and domains, receives cloud/provider attestations, assigns findings, starts deadlines, and re-verifies closure. Sensitive ownership and topology data must be compartmented; a national attack map would itself be a catastrophic target.
8.2 Local continuity plane
Inside each organization, the open defensive stack runs on a Continuity Node or equivalent. It maintains the living inventory and digital twin, joins technical findings to identities and business processes, tests remediations, applies preauthorized narrow containment, preserves evidence, and orchestrates recovery. Raw company content remains local by default.
8.3 National defensive reasoning and learning plane
This plane operates the free frontier-class defensive model service, evaluates models and tools, distributes signed policies and fixes, learns from minimized outcomes, compares exploit and closure rates, and makes a defense discovered in one organization available to others. No model may grant itself new privileges or declare its own consequential action safe.
8.4 Independent recovery and oversight plane
Recovery copies, clean images, keys, and restoration evidence must remain beyond the routine reach of production identities and the reasoning system. Independent evaluators challenge fixes and metrics. Courts and administrative reviewers hear contested findings and penalties. Inspectors general, civil-liberties bodies, sector experts, and public reporting constrain mission creep.
NIST's Cybersecurity Framework 2.0 spans Govern, Identify, Protect, Detect, Respond, and Recover.17 NIST's platform-resilience guidance likewise emphasizes protection, detection, and recovery from corruption.18 The architecture is not a new checklist. It is machinery that keeps those functions operating at the speed and coverage AI changes.
9. The first three years
First 180 days: know the boundary
- Enact the Duty of Cyber Continuity and establish rulemaking, privacy, appeal, and emergency authorities.
- Create the protected entity/service registry and begin with federal contractors, critical infrastructure, cloud providers, CDNs, identity providers, MSPs, remote-management vendors, and material software suppliers.
- Publish schemas for exposure, owner, dependency, remediation, verification, and recovery evidence.
- Expand Cyber Hygiene capacity and accredit independent measurement providers.
- Publish the first open National Defensive Coscaling Stack and launch a no-cost federal defensive-model service for bounded pilots.
- Establish the national model/tool evaluation service and a vulnerability-disclosure shield for good-faith researchers.
Year one: close systemic paths
- Apply the duty to critical and high-concentration providers.
- Require provider/customer responsibility maps for every material cloud and managed service.
- Enforce the 72-hour and seven-day classes.
- Require covered boards to adopt Continuity SLOs and report availability, exposure age, closure latency, and clean recovery together.
- Prove minute-scale patch-or-isolate workflows for selected high-prevalence public-service classes, with staged deployment and automatic rollback.
- Stand up emergency isolation and engineering teams.
- Fund replacement of unsupported internet-facing systems in essential services.
- Run sector exercises in which common cloud, identity, MSP, and update channels fail simultaneously.
Years two and three: reach the installed economy
- Extend the duty to every material public service, with subsidized shared Stewards and Nodes for small entities.
- Add internal attack-path, identity, and supply-chain evidence proportional to consequence.
- Require annual clean-room restoration of essential functions, not a screenshot claiming that backups ran.
- Link procurement, insurance, safe harbor, and lending incentives to continuing verified performance.
- Move mature service classes from day-scale ceilings to minute-scale patch-or-isolate requirements when public evidence shows the stack can do so safely.
- Publish aggregate national metrics without exposing exploitable entity detail.
The program should measure:
- time from public exposure to authoritative ownership;
- time from disclosure or discovery to external detection;
- time from authoritative patch release to safe deployment, verified isolation, or withdrawal from public reach;
- time to containment and verified closure by path class;
- percentage of measured time each public service remains in a continuously clean exposure state;
- percentage of material services with complete responsibility maps;
- prevalence and age of exposed KEVs and automatable material-control paths;
- successful clean restoration time for essential services;
- correlated dependency concentration by provider, identity plane, MSP, region, and software component;
- false-positive, appeal, and unsafe-patch rates;
- board and executive remediation decisions, including unfunded exceptions and business-owner refusals;
- emergency shift length, relief coverage, and fatigue-related control failures;
- small-business compliance cost and market exit; and
- the ratio of attack reuse speed to defense propagation speed.
The last ratio is the scoreboard for defensive coscaling.
10. How this changes RVA Cyber's other ideas
The National Cyber Steward Corps becomes the compliance utility
The published Corps proposal is voluntary: participating businesses receive a Continuity Node, national defensive reasoning, independent recovery, and an accountable human Steward in exchange for controls, exercises, minimized learning, and a contribution to collective defense.19
The new paper adds a mandatory floor without discarding voluntary institutional choice. The Duty of Cyber Continuity applies to every covered operator. The Corps becomes the publicly financed way to satisfy it and earn safe-harbor protection. Businesses can build an equivalent system, use an accredited provider, or enroll. This resolves the largest tension in the earlier paper: a voluntary network can protect its members, but it cannot close externally imposed risk from firms that remain outside it.
The Corps also prevents the new law from degenerating into a scanner-and-fine bureaucracy. Its Node, Steward, recovery plane, approval tiers, capability registry, and independent verifier supply the operating machinery between a finding and a durable closure.
ii.inc's intelligence utility needs a defense utility first
Our ii.inc assessment concluded that personal agents and local integration teams are plausible while the coin, population-identity, exclusive-franchise, and humanoid layers remain unproved.20 The two-economy model clarifies why the integration layer matters: AI-native agents can become the translation surface through which legacy organizations inventory work, build digital twins, and operate remediation.
But an intelligence utility built on a fragile identity, cloud, and legacy substrate multiplies correlated risk. The sequence must be: continuity before convenience; governed defense before universal agency; recovery before dependency. Local ownership is valuable only if local systems can reject poisoned instructions, operate during national-service failure, and restore without re-importing compromise.
The Last Copilot supplies the human boundary
Machine speed creates pressure to remove people from every decision. That is safe for observation, simulation, evidence collection, and some narrow reversible containment. It is unsafe for actions that can halt a hospital, disconnect a city, destroy evidence, or redefine who has authority.
The Last Copilot's concern—human standing and control in the AI economy—therefore remains central.21 Defensive coscaling must automate work without converting the accountable human into a ceremonial clicker or a liability sink. Material actions require comprehensible evidence, bounded authority, signed approval where time allows, dual control at enterprise scale, and an independent path to stop the defender itself.
No One Is Expendable constrains enforcement
A law that makes only the largest firms survivable would move p(doom) upward while claiming to reduce it. The abundance project requires capacity, reliability, rights, affordability, sustainability, resilience, and a human or offline path when automation fails.22
That means small organizations receive capacity before punishment; workers are not sacrificed to meet a patch clock; victims retain compensation; essential services receive emergency help; and no federal defensive plane becomes a back door for tax, immigration, labor, or general law-enforcement surveillance.
Defensive coscaling is infrastructure for Fab only if it preserves the people it claims to protect.
11. The strongest objections
“The government will build the world's best target list.”
Yes—unless the registry is designed as compartmented critical infrastructure. Public exposure measurement can remain outside-in; entity mappings can be separately encrypted; sector views can be minimized; access can require purpose-bound credentials and immutable audit; and no analyst or model should be able to export a national graph. Breach of the registry must be a rehearsed scenario, not an unspoken impossibility.
“A 100-percent vulnerability-free public surface is impossible.”
No measurement can prove the nonexistence of an unknown flaw. That epistemic limit is real and already reflected in the enforcement model. But organizations routinely convert impossible absolutes into uncompromising operating objectives. “Zero preventable deaths” does not mean omniscience; it means no accepted preventable death. Here, 100-percent clean means zero known, reachable, unmitigated attack paths under continuous current measurement, plus an architecture that can close a newly knowable path within minutes. The target is not a quarterly certificate of perfection. It is continuous convergence back to clean.
“Forced patching will break hospitals and factories.”
Sometimes. Legacy operations teams know this better than policy writers because they absorb the outage, the escalation, and the sleepless recovery. That is why the duty is closure or containment, not blind installation—and why the mandate must pay to rearchitect. Digital twins, redundant instances, test environments, staged rollouts, rollback, compensating controls, segmentation, and emergency engineering are part of the program. If a service cannot be patched safely, it may need to leave the public internet until it can be defended. The failure belongs to the architecture and its business owners, not to the operator who refuses to gamble a hospital on an untested package.
“Attackers will just use zero-days, phish people, or compromise vendors.”
They will. The first sprint removes cheap, repeatable, reachable paths and forces the attacker to spend scarce zero-days, identities, and trusted access. The same local inventory, identity map, containment, and recovery system then addresses the other pathways. Patching is the first mobilization boundary, not the whole war.
“Risk-based deadlines recreate the current excuse machine.”
Only if organizations grade themselves and findings remain isolated. The proposed regime uses external exposure, observed exploitation, automation, technical control, chaining, and consequence; keeps the clock visible to the regulator; and requires independent closure evidence. A modest base score cannot erase a validated path.
“This will destroy open-source development.”
Liability must follow control and commercial role. An unpaid maintainer is not the same as a vendor packaging a component into a revenue product or a critical service. The program should fund maintainers, require downstream vendors to inventory and patch what they ship, preserve good-faith research, and avoid making publication of code equivalent to operating an exposed service.
“The Hack is theatrical.”
The name is theatrical. The planning problem is not. Models already compress labor across the kill chain; federal policy already says AI may narrow the patch-to-exploitation window; autonomous defense already finds and patches real flaws; destructive malware already crosses borders; and cloud, identity, software, and managed-service concentration create correlated dependencies.2381013 The historical protection Amodei identifies—the negative correlation between destructive motive and rare technical ability—is exactly the protection capable AI can dissolve.23
The uncertainty is timing, composition, and impact. That is exactly what resilience is for.
12. Fab or Doom is decided before the button
After The Hack begins, speeches about cyber hygiene will be worthless. Procurement cycles will not accelerate enough. Unsupported devices will not develop maintainers. Recovery keys stored in the compromised identity plane will not become independent. A company discovering its dependencies for the first time during national disruption will already be late.
The decisive work occurs before the button:
- map what exists;
- know who controls each layer;
- make boards reward clean exposure and safe change instead of uptime alone;
- remove public paths faster than they can be weaponized;
- give every authorized operator an open defensive stack and free federal frontier-model capacity;
- make defenders learn collectively without centralizing private life;
- keep clean recovery beyond production compromise;
- exercise correlated failure;
- preserve accountable human authority; and
- give every organization a viable compliance path, then impose consequences on those that refuse it.
p(hack)=100% means stop debating whether someone will try.
The variable we control is the consequence.
If defensive capacity remains optional, fragmented, slower than offense, and concentrated in a few wealthy firms, The Hack can turn the legacy economy into the accelerant of Doom. A digital Pearl Harbor then becomes a planning certainty—not because we can name its date or prove its exact probability, but because motive is abundant, capability is diffusing, exposure persists, and the people who could close it are still punished for changing production. If defense coscales—technically, institutionally, legally, and economically—the same event becomes a brutal but survivable test. Essential systems isolate, restore, learn, and continue. Trust bends instead of breaking. The AI-native economy inherits a functioning society rather than a vacuum.
Future generations may remember the people alive now as the generation that decided which attractor became real. Not because we predicted the date. Because we saw the asymmetry, still had time to act, and chose whether defense would scale.
Evidence posture
- Observed facts: cited evaluation results, observed vendor threat intelligence, current federal directives and guidance, historical destructive incidents, cloud-responsibility documentation, SRE incentive design, current SEC governance disclosure, and published RVA Cyber designs.
- Supported inferences: AI reduces attacker labor constraints; operational scorecards bias legacy teams toward stability; correlated dependencies can amplify impact; machine-speed defense can reduce time-to-closure; voluntary adoption will leave substantial gaps.
- Stress-test assumptions: a capable actor will attempt a systemic destructive campaign; the campaign may combine known flaws, chains, identities, suppliers, and wipers.
- Policy proposals: the Continuity SLO, Duty of Cyber Continuity, Responsible Internet Service Operator, National Defensive Coscaling Program and open stack, free federal frontier-class defensive model service, deadlines, revenue-scaled penalties, registry, compliance utility, and phased rollout do not exist as described and require legislation, appropriations, rulemaking, technical pilots, privacy design, and judicial review.
Sources
- UK AI Security Institute, Frontier AI Trends Report, 2025.↩
- Anthropic, Detecting and countering misuse of AI: September 2026, Sept. 10, 2026. Anthropic reports observations from its own services and investigations; the evidence should not be treated as an independent prevalence estimate.↩
- White House Archives, “Statement from the Press Secretary”, Feb. 15, 2018.↩
- Cybersecurity and Infrastructure Security Agency, Cyber Hygiene Services.↩
- National Institute of Standards and Technology, SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology, 2022.↩
- National Institute of Standards and Technology, IR 7946, CVSS Implementation Guidance, §2.2, 2014. This document addresses CVSS v2 and is cited for its explicit discussion of contextual risk and chaining limitations, not as the current CVSS specification.↩
- National Institute of Standards and Technology, IR 7788, Security Risk Analysis of Enterprise Networks Using Probabilistic Attack Graphs, 2011.↩
- Defense Advanced Research Projects Agency, “AI Cyber Challenge Results”, Aug. 8, 2025. DARPA corrected the synthetic-vulnerability denominator from 70 to 63.↩
- Cybersecurity and Infrastructure Security Agency, #StopRansomware Guide.↩
- U.S. Department of the Treasury, The Financial Services Sector's Adoption of Cloud Services, 2023, pp. 56–58.↩
- U.S. Government Accountability Office, GAO-25-106369, Cloud Computing: Private Sector Leading Practices in Acquisition, Cybersecurity, and Workforce Development, 2025. GAO's company sample was nongeneralizable.↩
- AWS Shared Responsibility Model; Microsoft, Shared responsibility in the cloud; Google Cloud, Shared responsibilities and shared fate.↩
- Cybersecurity and Infrastructure Security Agency, BOD 26-04, Prioritizing Security Updates Based on Risk, June 10, 2026. The directive applies to covered Federal Civilian Executive Branch systems, not the private economy proposed here.↩
- 18 U.S.C. §3553(a); U.S. Department of Justice, Justice Manual §9-27.000, Principles of Federal Prosecution.↩
- Federal Trade Commission, “FTC Finalizes Order with GoDaddy over Data Security Failures”, May 21, 2025.↩
- Cybersecurity and Infrastructure Security Agency, “Applying Secure by Design Thinking to Events in the News”, Nov. 1, 2023.↩
- National Institute of Standards and Technology, Cybersecurity Framework 2.0, 2024.↩
- National Institute of Standards and Technology, SP 800-193, Platform Firmware Resiliency Guidelines, 2018.↩
- RVA Cyber, The National Cyber Steward Corps, Discussion Draft 4.0, Aug. 17, 2026.↩
- RVA Cyber, Can ii.inc Build an Intelligence Utility?, Sept. 5, 2026.↩
- RVA Cyber, The Last Copilot.↩
- RVA Cyber, No One Is Expendable.↩
- Dario Amodei, The Adolescence of Technology, Jan. 2026, §2 (“Ability and motive may even be negatively correlated” and “this will break the correlation between ability and motive”). The paper applies Amodei's general destructive-misuse mechanism to cyber; it does not attribute Jimmy Staley's paraphrase to Amodei as a quotation.↩
- Google, Site Reliability Engineering: Embracing Risk and Example Error Budget Policy. Google describes the incentive tension created when product teams are evaluated on velocity and SRE teams on reliability, and uses shared error budgets to align decisions.↩
- U.S. Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Release No. 33-11216, July 26, 2023. The rule requires covered registrants to describe board oversight and management's role; it does not establish the Continuity SLO or outcome duty proposed here.↩