The industry's answer to AI-found exploits so far is to use the same AI to find and fix them first. That answer is right, and it is only half of what defenders can do. This post is about the other half.
In April 2026, Anthropic showed what a frontier model can do against real software. Claude Mythos Preview found thousands of high-severity zero-days across every major operating system and browser. One was a 27-year-old flaw in OpenBSD that decades of human review had missed. In another case the model chained four vulnerabilities into a single exploit that escaped the browser sandbox, without a human steering it.
Anthropic did not release the model. It put it to work for vetted defenders through Project Glasswing, with partners across cloud, operating systems, chips and security, plus up to $100 million in usage credits.
OpenAI's Daybreak follows the same pattern. Gated cyber models and Codex Security find vulnerabilities, check whether they are reachable, write patches and validate them. OpenAI's own announcement warns that threat actors will use AI to attack at a speed and scale defenders have not faced before.
That warning is the point. Withholding one model buys time; it does not change the direction. The cost of finding an exploitable flaw is falling for everyone, adversaries included.
Glasswing and Daybreak are the right response. Both also rest on one assumption: that defenders can find and fix a flaw before an adversary can exploit it.
That holds for a browser that updates overnight. It does not hold for the systems that never update on time:
When finding exploits gets cheap for everyone, this backlog of unpatched systems becomes the attack surface. It is measured in years, not days, and no patch pipeline closes it fast enough.
So there is a second question next to "how fast can we patch?": what will the box do for the adversary once the exploit lands?
Today the answer is usually "everything". A device's identity is a key stored somewhere in software or firmware. An exploit that reaches it copies it, and from then on the adversary speaks with that device's voice. It signs traffic as the device, unlocks what the device can unlock, and moves to the next machine as a trusted peer.
Now change one thing. Let the identity come from the physical silicon itself, so it never exists as a stored secret. There is nothing in memory to copy. And because the identity cannot be lifted off the chip, the chip can gate the actions an adversary came for:
Each of these needs a fresh answer from the silicon that code on the box cannot produce or replay. The implant still runs. But the device stays uncooperative, and the record of what it computed stays signed by the hardware that actually ran it.
The breach happens; the payoff does not.
This does not stop the first compromise, and it is not a reason to stop patching. A compromised device can still misbehave locally. What changes is that the compromise stops paying off, whether or not the patch has arrived.
Defenders need both levers; only one depends on winning a patch race.
Inference is moving from a few hyperscale clusters onto many independent nodes, run by many operators. Every node is another place an adversary can land, and most of those nodes will not be patched on the same day.
It is the layer we called the glass door: every software control above it, patch pipelines included, assumes the hardware underneath is what it claims to be.
That is the layer UBIQS builds. Identity is a property of the chip rather than something the chip holds. It gates the actions that matter, and every AI execution is signed by the hardware that actually ran it. A customer does not have to trust that every node in the network was patched in time. They can check which hardware did the work, and an exploited node cannot claim to be one it is not.
Glasswing and Daybreak shrink the number of exploitable zero-days. Silicon-gated identity shrinks what each remaining exploit is worth. The question for every security team is a simple one: what does patch latency look like for the devices you cannot update overnight?
Every security solution operates above the execution layer. The layer beneath is the one they all assume.
Read →Which ML attacks hardware-rooted identity stops directly, and which it composes with.
Read →We're talking with teams who want a compromise to stop paying off, on the fleets and inference nodes that will never win a patch race.