The AI Arms Race Has No Off Switch — How Open-Weight Models Made US Export Controls Pointless
The United States spent two years building walls around its AI advantage. Export controls, chip bans, entity lists. The theory was elegant: control the hardware, control the capability. But if you look at what happened in the last ten days of June 2026, you’ll see the walls never stood a chance.
On June 13, Chinese startup Zhipu AI released GLM-5.2 — an open-weight model freely downloadable by anyone with an internet connection. When security firm Semgrep ran it through their cybersecurity benchmarks, the results were startling: GLM-5.2 scored a 39% F1 score on IDOR (Insecure Direct Object Reference) detection, outperforming Claude Code’s 32%, at a cost of roughly $0.17 per true vulnerability found. The Semgrep team put it bluntly in their blog post title: “We have Mythos at Home.”
Anthropic’s Mythos — the cybersecurity-focused AI model previewed at RSA in April 2026 and found to “autonomously find and exploit zero-day vulnerabilities in every major OS and browser” by the UK’s AI Safety Institute — is restricted to roughly two dozen trusted US organisations. GLM-5.2 does similar work. And it’s free.
The irony is almost poetic. The US tried to contain AI capability by controlling GPUs and chip exports — the AI Diffusion Rule issued by the Bureau of Industry and Security in January 2025, expanded in June 2026 to cover Chinese firms operating outside China. But open-weight models bypass the hardware question entirely. If the weights are on Hugging Face, anyone with a modest GPU cluster can run them. The bottleneck shifts from silicon to intelligence, and intelligence turns out to be much harder to embargo.
China builds its own Mythos — and makes it state policy
The GLM-5.2 story is only one side of what’s happening. On June 28 at the ISC.AI 2026 cybersecurity conference in Beijing, Zhou Hongyi — founder of Qihoo 360, one of China’s largest cybersecurity firms (and itself on the US sanctions list) — unveiled two AI-powered vulnerability-hunting tools collectively branded as “Yitian Tulong.”
These weren’t research prototypes. Zhou described vulnerability-finding AI explicitly as a national strategic asset that could be used both to defend critical infrastructure and to gain advantage over adversaries. The tools use a multi-agent swarm architecture to discover and exploit software vulnerabilities at scale — the same approach that made Mythos such a concern.
The WSJ reported on June 28 that “Chinese AI systems have matched the performance of Anthropic’s powerful model Mythos in some cybersecurity scenarios.” Reuters confirmed on June 24 that 360 had developed “a domestic answer to Mythos.” Multiple sources, consistent reporting.
The counter-response: OpenAI patches what AI breaks
Meanwhile, in what feels like the other side of the same coin, OpenAI launched “Patch the Planet” on June 22 — a Daybreak initiative built with Trail of Bits, HackerOne, and Calif, designed to help open-source maintainers find, validate, and fix vulnerabilities using AI. It includes a Codex Security plugin that automates the journey from vulnerability discovery to patched code.
The framing is telling: OpenAI isn’t trying to find vulnerabilities for governments. It’s trying to patch them for maintainers. The model is “democratise patching at machine speed” — a direct response to the reality that AI is making vulnerability discovery trivial, so the only defensible position is to make fixing them equally trivial.
What this actually means
The headline takeaway isn’t just “China caught up.” It’s that the entire premise of controlling AI cybersecurity capability through hardware export controls was fundamentally flawed. The moment models become open-weight, the capability diffuses globally regardless of where the GPUs are manufactured.
There are three things happening simultaneously, and they’re all consequences of the same underlying shift:
- Discovery is cheap. Finding vulnerabilities with AI now costs fractions of a cent per finding. GLM-5.2 at $0.17 per vulnerability is the latest data point — but even that’s probably the high end.
- Fixing is the bottleneck. OpenAI’s Patch the Planet is the market’s honest answer: the problem isn’t finding bugs anymore, it’s fixing them fast enough. The race is no longer between attackers and defenders — it’s between patch speed and exploit speed.
- Export controls are theatre. The Guardian wrote as early as May 2025 that US chip export controls are “a failure because they spur Chinese self-reliance.” GLM-5.2 is empirical proof. Chatham House made the same argument in April 2026 — that export controls aren’t even the best bargaining chip the US has.
I find this fascinating not because it’s surprising — anyone who has watched the open-source ecosystem for more than five years could have predicted this — but because it validates what has always been true about technology: you can control factories, but you can’t control ideas. The weights are the ideas. And once they’re out, they’re everywhere.
The question now isn’t whether China can match US AI security capability. It’s whether anyone — US, China, or the rest of the world — can fix vulnerabilities faster than AI finds them. Nobody has a convincing answer for that yet.
Sources:
– Semgrep: “We have Mythos at Home” — GLM-5.2 benchmark results
– Reuters: China’s 360 develops tools to match Anthropic’s Mythos
– TechTimes: China builds AI vulnerability scanner
– Techscurrent: GLM-5.2 puts open-weight AI on the cybersecurity shortlist
– OpenAI: Patch the Planet — Daybreak initiative
– WSJ: China has matched Anthropic in cybersecurity
– UK AI Safety Institute: Mythos Preview evaluation
– The Guardian: US chip export controls are a ‘failure’
