The most common question I get right now from customers, boards, and reporters is some version of: are we ready for AI-discovered vulnerabilities? Usually with Anthropic's Mythos attached.
It's the right instinct pointed at the wrong frame. Readiness labels anchored to one AI model age out in a quarter. The Mythos label coined in April was already dated by July, after the model it named had been suspended by one government directive, cleared by another, and redeployed. The shift is real, and it is vendor-neutral. Discovery credited to AI-assisted research showed up by name across Windows, macOS, and Linux in a single patch cycle this spring. Five of the ten largest single-day CVE publication batches since 2017 landed in the last seven weeks (Jerry Gamblin, CVE List v5, July 2026).
Here is what the data doesn't show: a matching surge in exploitation. Google's threat intelligence team has documented exactly one case of a threat actor holding a zero-day it assesses was AI-developed, caught before the planned campaign began. Proofpoint's telemetry says attacker behavior remains opportunistic and technique-stable. The exploitation numbers that are climbing, like vulnerability exploitation reaching 31% of initial access in the Verizon 2026 DBIR, are a standing trend driven by known CVEs on edge devices. Two different curves. The AI-driven one hasn't landed.
It will. The arrival will be a step change rather than a ramp, because efficient adversaries don't retool until the advantage is unambiguous. Then they all retool at once.
That lag is not a reprieve. It's a construction window.
I've been calling the work you do inside that window frontier-pace governance: aligning oversight with execution at the cadence of frontier AI. It is a new mindset applied to an existing challenge, not a new toolset. If your automation already delivers patch velocity, configuration discipline, accurate inventory, and defense in depth, you are raising the attacker's cost no matter how the bug was found. The constraint that actually binds is how fast your governance lets that automation run. Last year, only 26% of known exploited vulnerabilities were fully remediated, down from 38% (Verizon 2026 DBIR). Discovery set records. Remediation went backward.
The pace changed. The work didn't.
The paper lays out the operating model: seven principles, the mechanics beneath them, and where patching and automated mitigation run as parallel tracks. It is offered as the commander's intent, not doctrine, because the honest answer is that this model will evolve as the community gains experience. The direction won't.
Read the data. Map your governance against your execution speed. Decide your risk appetite deliberately, not by default.
I've written the full argument in a short paper, Frontier-Pace Governance. If you own security operations and the board is asking whether you're ready, start there.

)