The most dangerous vulnerability in the AI stack right now didn’t come from a sophisticated exploit chain or a nation-state attacker. It came from developers doing what developers have always done: copying code that works.

Avi Lumelsky, a security researcher at Israeli cybersecurity firm Oligo Security, has published findings on what he calls “ShadowMQ,” a pattern of critical remote code execution vulnerabilities embedded in AI inference frameworks built by Meta, Nvidia, Microsoft, and the PyTorch open source community. The affected projects include vLLM and SGLang, two of the most widely deployed inference serving frameworks in production today, according to Oligo Security’s research disclosure.

The root cause is a bug class that web developers stopped tolerating years ago. These frameworks use ZeroMQ (ZMQ), a lightweight messaging library, for internal process communication. The data moving through those ZMQ channels gets serialized using Python’s pickle module. Pickle will execute arbitrary code during deserialization. This has been documented as dangerous since at least 2014. Every Python security guide says the same thing: never unpickle untrusted data.

Yet here it is, running in production inference infrastructure at four of the largest AI companies on the planet. The AI development community, in its rush to ship, skipped the web’s security lessons entirely.

Not a Bug. A Propagation Pattern.

What makes ShadowMQ different from a single CVE is how it spread. CSO Online and The Hacker News covered this as a vulnerability announcement. It’s more than that.

The security industry has a well-developed vocabulary for supply chain attacks: malicious packages uploaded to PyPI, typosquatting in npm, backdoors planted in open source dependencies. ShadowMQ is a different species. The code wasn’t malicious. It worked exactly as intended. It was just insecure. And it spread through the most human behavior in software development: copying code that works from someone you trust.

One team implemented a ZMQ handler that uses pickle for serialization. It was functional, tested, running at scale. When the next team at a different company needed a process communication layer, they grabbed the existing implementation. Why wouldn’t they? Repeat across four or five major frameworks and you’ve got the same exploitable flaw sitting inside Meta’s LLaMA Stack, Nvidia’s inference tools, Microsoft’s DeepSpeed, and the two most popular open source inference servers.

This is how unsafe patterns metastasize. Not through malice, but through trust. And the security industry doesn’t really have a framework for it yet. We know how to scan for malicious packages. We know how to detect backdoors. We don’t have good tooling for catching insecure-but-functional code that gets copy-pasted across an entire ecosystem by developers acting in good faith.

Why Inference Is the Layer That Matters

There’s an important distinction that most coverage misses. These are not training systems. Training infrastructure processes data in controlled environments with restricted access. Inference servers are the production layer. They handle user requests, process inputs, and return outputs in real time. They are, by definition, network-accessible.

An attacker who achieves RCE on an inference server gets access to the models being served, the data flowing through them, and potentially the broader cloud infrastructure the server connects to. In multi-tenant environments, which is how most cloud AI services operate, that’s catastrophic.

Lumelsky previously worked at Deci AI, a model optimization company that Nvidia acquired. He wasn’t looking at these systems from the outside. He knew where to look because he’d built similar systems himself.

Three Researchers, Three Angles, Same Blind Spot

Lumelsky’s findings don’t exist in isolation. They’re the third data point in a pattern that, as far as I can tell, nobody else has connected.

In late 2025, Michael Bargury at Zenity Labs demonstrated at Black Hat that endpoint detection and response (EDR) tools are effectively blind to on-device AI inference. The monitoring that enterprises rely on to detect threats cannot see what AI models are doing at the endpoint level.

In February, PromptSpy became the first documented case of AI malware using on-device inference as a command and control channel, proving that local AI processing creates covert communication paths traditional security tools can’t observe.

Now Lumelsky shows the inference frameworks themselves have RCE holes that went undetected for years.

Three researchers, three angles, one conclusion: the inference layer is unprotected. EDRs can’t see it. The frameworks have holes. And the architecture itself can be weaponized as a covert channel. The AI security conversation has been consumed by training data poisoning, model theft, and prompt injection for two years. Meanwhile, nobody was checking whether the messaging layer between processes in vLLM was using safe serialization.

The Decade That Got Skipped

The immediate fix is straightforward. Stop using pickle for inter-process communication in any network-accessible system. Use a safe serialization format. Validate inputs before deserialization. These are not novel recommendations. They’ve been standard security guidance for over a decade.

The harder problem is the code reuse chain. Every team that built on these patterns, or borrowed from them, needs to audit their own implementations. That’s a lot of work across a fragmented ecosystem with no central authority to coordinate it.

But the real story here, in my view, is the pattern repetition. The web development community fought these exact battles. Deserialization attacks, unsafe defaults in popular frameworks, insecure code spreading through trusted channels. It took years of breaches, CVEs, and painful lessons before safe-by-default became the expectation. The AI development community appears to be running the same playbook from the start, just faster and with higher stakes. Pickle deserialization in 2026 inference infrastructure is the equivalent of SQL injection in 2006 web apps. We know better. The code doesn’t.

For inquiries and analysis contact laterstack@proton.me

Yann LeCun thinks the entire AI industry is building on a dead end. And he just convinced Jeff Bezos, Nvidia, Samsung, Temasek, Mark Cuban, Eric Schmidt, and Tim Berners-Lee to give him a billion dollars to prove it.

AMI Labs, short for Advanced Machine Intelligence, closed a $1.03 billion seed round on March 10 at a $3.5 billion pre-money valuation. It is the largest seed round in European history. The Paris-based company was founded less than four months ago, after LeCun left Meta in November 2025 following twelve years as the company’s chief AI scientist.

That is a staggering amount of capital for a company with no product, no revenue, and a thesis that boils down to: everything OpenAI, Anthropic, and Google are doing is a sophisticated parlor trick.

The Thesis

LeCun’s argument, which he has been making publicly for years, is that autoregressive language models cannot achieve real intelligence. These systems predict the next word in a sequence. That is all they do. Scale them up, train them on more data, add reinforcement learning from human feedback, and they still just predict the next word. LeCun has said existing AI systems don’t understand the world as well as a housecat and called the autoregressive approach “kind of a hack.”

His alternative is something called JEPA: Joint Embedding Predictive Architecture. Instead of predicting raw outputs token by token, JEPA learns abstract representations of reality and predicts how those representations evolve. Think of it as the difference between predicting what someone will say next versus understanding why they would say it. JEPA was first introduced as a paper during LeCun’s time at Meta, and early results showed strong performance on computer vision benchmarks while using significantly less compute than pixel-level prediction models.

AMI wants to build “world models” on top of this architecture. Systems that understand physics, maintain persistent memory, and can plan complex action sequences. Not chatbots. Not text generators. AI that can predict the consequences of actions in the physical world, then choose the best path forward.

The Team and the Money

LeCun is executive chairman, not CEO. Day-to-day operations belong to Alex LeBrun, a former Meta colleague and co-founder of the digital health startup Nabla. The founding team, profiled by TechCrunch in January, is stacked with Meta FAIR alumni. Saining Xie, the chief science officer, came from both Google DeepMind and Meta. Pascale Fung, the chief research and innovation officer, was a senior director of AI research at Meta-FAIR and a chair professor at Hong Kong University of Science and Technology. Michael Rabbat, VP of World Models, was a research director at Meta-FAIR and associate professor at McGill. Laurent Solly, the COO and only non-technical founder, spent nearly 13 years as a Meta VP for Europe.

The investor list reads like a who’s who of people who got rich off the current paradigm and are now hedging against it. Bezos Expeditions co-led the round alongside Cathay Innovation, Greycroft, Hiro Capital, and HV Capital. Toyota Ventures and Samsung came in as strategic backers. Nvidia invested too, which is worth noting since Nvidia sells GPUs to every autoregressive AI company on the planet.

AMI plans to operate from four locations: Paris (headquarters), New York (where LeCun teaches at NYU), Montreal, and Singapore.

What This Actually Means

The target applications are telling. AMI is going after industrial automation, robotics, healthcare, and wearables. Domains where getting the answer wrong kills people or destroys equipment. These are exactly the places where autoregressive models fail most dangerously, because they hallucinate with confidence and have no grounding in physical reality.

Nabla, LeBrun’s health tech company, is already AMI’s first announced partner. Healthcare is the guinea pig.

But be clear about what this round actually is: a spectacular bet on LeCun’s reputation. JEPA has shown promising results on vision benchmarks. It has not demonstrated anything close to the generalized capability that would justify a $4.5 billion post-money valuation. No one outside of academic papers has shipped a JEPA-based product that works at scale. LeCun is selling a direction, not a destination.

“Dead end” is doing a lot of heavy lifting in LeCun’s pitch, and it deserves pushback. Whether autoregressive AI is a dead end depends entirely on who is using it and for what.

If you are a Fortune 500 enterprise betting billions on AI infrastructure that needs to understand physics, maintain persistent memory, and plan complex actions in the physical world, then yes, current LLMs have real limitations. They hallucinate. They lack grounding. They cannot reason about consequences in the way that robotics and industrial automation demand. LeCun has a point, and the investor list reflects that companies like Toyota and Samsung, with real manufacturing operations, see the gap.

But if you are a consumer, a small business owner, or a startup trying to build faster, autoregressive models are not a dead end. They are the most powerful productivity tool most people have ever had access to. They pass bar exams, write production code, draft marketing copy, and conduct preliminary medical assessments. For these users, the current paradigm is a net positive, and it keeps getting better. The “hack” works astonishingly well for a hack.

The real question is not whether JEPA replaces transformers. It is whether organizations using either architecture are aligned on how they deploy it. Any AI approach, autoregressive or world-model, becomes a liability when teams are on different paths, when there are no SOPs governing its use, and when the people building with it are not communicating with the people accountable for outcomes. The architecture matters less than the alignment around it.

LeCun is a Turing Award winner who invented convolutional neural networks. When he says the current path has a ceiling, the smartest money in the room takes the bet. But a billion dollars on JEPA does not make autoregressive AI useless for the hundreds of millions of people getting genuine value from it right now. It means the technology is forking, not dying. Different tools for different problems.

The expensive question is whether AMI can ship a product before the autoregressive paradigm either hits its ceiling or adapts past it. OpenAI is not sitting still. Neither is Anthropic. Neither is DeepMind. And the last several years of AI research are littered with alternative architectures that were supposed to replace transformers and didn’t.

This is not a story about a sophisticated cyberattack. It’s a story about leaving the front door open for two months and then acting surprised when someone walks in.

On March 18, CISA added CVE-2026-20963 to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively using a critical SharePoint Server flaw to execute remote code on enterprise systems. The vulnerability carries a CVSS score of 9.8 out of 10. It affects SharePoint Server 2016, 2019, and Subscription Edition, according to Microsoft’s security advisory.

Microsoft patched it in January.

That’s not a typo. The fix shipped with the January 2026 Patch Tuesday update, more than two months ago. At the time, Microsoft’s own assessment rated the flaw as “less likely” to be exploited, according to Bleeping Computer’s coverage. That assessment aged poorly.

How It Works

The vulnerability is a textbook deserialization attack. SharePoint uses serialization to maintain state across HTTP requests, frequently through ASP.NET ViewState. The server serializes data, sends it to the client, and trusts what comes back. CVE-2026-20963 exploits the fact that SharePoint’s deserialization logic doesn’t properly validate the type of incoming data, according to CVE Reports’ technical breakdown.

An attacker crafts a malicious serialized payload, sends it to a vulnerable server, and SharePoint executes whatever instructions are embedded in it. No valid credentials required. No user interaction needed. The attack complexity is low, per CISA’s assessment.

That gets you full remote code execution on the SharePoint server. Most large enterprises use SharePoint as their document management backbone, so a successful exploit opens up internal communications, sensitive files, HR documents, financial records. Everything the server touches.

The Pattern Nobody Learns From

SharePoint deserialization vulnerabilities are not new. This is the third major one in three years.

CVE-2023-29357 was a privilege escalation flaw that CISA added to its KEV catalog in January 2024 after active exploitation, according to Picus Security’s analysis. CVE-2024-38094 was another deserialization RCE, CVSS 7.2, added to the KEV catalog in October 2024 after attackers used it to gain initial access, install malware, disable security tools, and move laterally across victim networks, according to The Hacker News.

Same product. Same class of vulnerability. Same outcome: organizations that didn’t patch fast enough got compromised.

Shodan scans from late 2025 identified over 16,000 SharePoint servers directly exposed to the internet, with the United States hosting the largest concentration at nearly 4,000 instances, according to SOCRadar’s exposure analysis. Not all of these are vulnerable, but every unpatched one is a target.

Two Months Is Not a Zero-Day

CISA has given federal agencies until March 21 to patch or mitigate, under Binding Operational Directive 22-01, which mandates remediation within specific timeframes once a vulnerability hits the KEV catalog. Private sector organizations face no such mandate. They get a strong recommendation and nothing else.

But even that framing lets people off the hook. BOD 22-01 kicked in on March 18. The patch was available since January 14. Any organization running on-premises SharePoint had 63 days to apply a critical security update and didn’t.

There are real reasons patching is hard. SharePoint is deeply integrated into enterprise workflows. Testing patches against custom configurations takes time. Change management boards move slowly. IT teams are understaffed and juggling a dozen other priorities.

All of that is true, and none of it matters to the attacker who just got remote code execution on your file server.

The Uncomfortable Math

Enterprise security has a measurement problem. CISOs report on vulnerability counts, patch compliance percentages, mean time to remediate. These numbers go into dashboards. Dashboards go into board presentations. Everyone nods.

Meanwhile, the same class of deserialization bug in the same product keeps getting exploited because the same organizations keep failing to patch within any reasonable window. Microsoft ships a fix. CISA eventually adds it to KEV when exploitation is confirmed. Federal agencies scramble to meet a deadline. Private sector organizations patch whenever they get around to it.

This cycle repeats every few months. The specific CVE number changes. The outcome doesn’t.

The uncomfortable truth is that most enterprise breaches in 2026 are not the result of brilliant hacking. They’re the result of known vulnerabilities with available patches that nobody applied. Not because the patches didn’t exist. Because patching wasn’t treated as urgent until CISA made it urgent, which in this case was two months after Microsoft already said “hey, you should probably fix this.”

CVE-2026-20963 is not a story about a dangerous new exploit. It’s a story about institutional inertia. The fix was there. The warning was there. The pattern from previous SharePoint CVEs was there. And the door stayed open anyway.

What You Should Actually Do

If you are an everyday consumer: This one probably does not affect you directly. SharePoint is enterprise software. But the principle applies to everything you use. If your phone, laptop, or router has a pending security update, install it. The most common path into your digital life is a vulnerability you knew about and did not patch. Turn on automatic updates for everything.

If you run a small or mid-sized business: Check whether you are running SharePoint on-premises. Many SMBs migrated to SharePoint Online through Microsoft 365, which Microsoft patches automatically. If you are still running SharePoint Server 2016, 2019, or Subscription Edition on your own hardware, you need to apply the January 2026 Patch Tuesday update immediately. If you do not have an IT team that monitors CVEs, this is the kind of thing that slips through. Consider whether your organization has the capacity to maintain on-prem infrastructure securely, or whether a managed cloud migration makes more sense long-term.

If you are an enterprise: You know the drill, and that is part of the problem. Your change management process, testing pipeline, and approval boards are designed to prevent disruption. They also prevent speed. A 63-day window between patch availability and confirmed exploitation is a failure, not a reasonable timeline. The question for every CISO reading this: if the same class of vulnerability in the same product has been exploited three times in three years, why is the patching timeline still measured in months?

Lamar covers cybersecurity, enterprise tech, and the systems that shape how power and technology interact. Follow Laterstack for critical analysis of the stories that matter.

This is the fourth chapter of a story Laterstack has been tracking since February. The Pentagon threatened to revoke Anthropic’s $200 million contract over Claude’s restrictions on autonomous weapons and domestic surveillance. Anthropic refused. President Trump ordered a government-wide ban. Defense Secretary Pete Hegseth slapped the company with a “supply chain risk” designation, a label historically reserved for foreign adversaries. Last week, Silicon Valley picked a side. OpenAI picked the Pentagon.

Now it goes to court. On Monday, March 24 at 1:30 p.m., Judge Rita Lin will hear Anthropic’s request for a preliminary injunction in San Francisco federal court, according to the court docket. The question before her is narrow but the implications are not: should the supply chain risk designation be paused while the full case plays out?

The Legal Arguments

Anthropic filed two lawsuits on March 9, one in the Northern District of California and one in the D.C. Circuit Court of Appeals. The core claim is First Amendment retaliation, according to NPR. CEO Dario Amodei publicly refused to remove safety restrictions from Claude. The government responded by designating his company a national security threat. Anthropic says that sequence is not a coincidence. It is punishment for protected speech.

The DOJ’s 40-page rebuttal, filed March 17, says the opposite. Refusing to accept contract terms is conduct, not speech. The government argues that ruling otherwise would “extend First Amendment protection to every commercial transaction.” The Pentagon says Anthropic’s “red lines” on surveillance and autonomous weapons make the company an “unacceptable risk to national security” because it might disable its technology during operations.

That framing is worth sitting with. The Pentagon’s official position is that a company willing to say no to the military is, by definition, a security risk. Not because of espionage. Not because of foreign ties. Because it might exercise the contractual right to pull its own product.

The Damage So Far

Anthropic is bleeding. Its CFO told the court that the supply chain designation puts hundreds of millions to billions of dollars in 2026 revenue at risk. More than 100 enterprise customers contacted the company with concerns. A financial services firm paused a $50 million contract. A fintech company cut a $10 million deal in half. A pharmaceutical company shortened its contract by 10 months, according to Bloomberg.

The federal government has not waited for the court. The State Department already switched to OpenAI’s GPT-4.1 for its internal chatbot, according to Reuters. Treasury Secretary Scott Bessent confirmed his department is ending all Anthropic use. HHS followed. OpenAI expanded its federal footprint on March 17 with an AWS partnership for classified and unclassified government work.

Every agency that drops Anthropic validates the designation. Every contract that shrinks proves the irreparable harm Anthropic needs to demonstrate in court. The government is building its own case against itself. Whether Judge Lin sees it that way is another question.

The Coalition

What makes this hearing unusual is who showed up to support Anthropic. Microsoft filed an amicus brief warning that the designation could “hamper” U.S. warfighters by forcing abrupt changes to existing products. More than 30 employees from OpenAI and Google DeepMind, including Google chief scientist Jeff Dean, signed a separate brief warning that the blacklist threatens the entire American AI industry. Twenty-two retired generals and admirals, including former CIA Director Michael Hayden, cautioned that abrupt tool changes could harm troops in theater. Former federal judges appointed by both Republicans and Democrats raised concerns about the legal basis for the designation. Catholic ethicists filed their own brief.

On Capitol Hill, Senator Ron Wyden pledged to “pull out all the stops” to fight the ban and predicted bipartisan support, according to Bloomberg. Senate Armed Services Committee leaders from both parties sent a private letter urging the Pentagon to stand down, Axios reported. Representative Sam Liccardo introduced an amendment to the Defense Production Act that would prohibit agencies from retaliating against AI vendors.

Lawfare’s legal analysis was blunt: the statute was not built for this use, the facts do not support it, and the courts will say so.

What Monday Decides

Judge Lin is not ruling on the merits. She is deciding whether to freeze the supply chain designation while the case proceeds. But a freeze would be devastating to the government’s position. It would mean a federal judge looked at the evidence and concluded Anthropic would likely win. It would tell every agency that rushed to drop Anthropic that they jumped too early. And it would establish that labeling an American company a national security threat because it refused to remove product safeguards requires more than a press release from the Secretary of Defense.

The DOJ’s lawyer refused to commit to no further adverse actions before the hearing when Judge Lin asked, according to the East Bay Times. That refusal is itself a data point. If the government were confident in its legal position, there would be no reason to keep the threat open.

What This Means If You Just Use Claude

Most people following this story are not defense contractors. They are developers, writers, analysts, and small business owners who use Claude every day. So here is what the government did and did not have access to, and what Anthropic refused.

Anthropic’s Claude was already deployed across federal agencies for unclassified work. State Department used it for internal search. Treasury used it for policy analysis. HHS used it for data processing. The government had access to the commercial version of Claude, the same model available to any paying customer. It was not a special military build. There were no secret capabilities. It was the same Claude anyone can sign up for.

What Anthropic refused was a set of modifications the Pentagon wanted for classified and operational military use. Specifically, Anthropic would not remove restrictions that prevent Claude from being used for autonomous weapons targeting, where AI selects and engages targets without a human in the loop. Anthropic would not remove restrictions on domestic surveillance of American citizens. And Anthropic maintained contractual “red lines” that gave the company the right to pull its technology if it believed the deployment violated its safety policies.

The Pentagon labeled that refusal a supply chain risk. The designation, historically reserved for foreign adversaries like Huawei and Kaspersky, has never been applied to an American company. The logic: if Anthropic might pull its product during operations, it is unreliable. Unreliable means risky. Risky means banned.

OpenAI took the deal. CEO Sam Altman acknowledged the negotiations were “definitely rushed” but said OpenAI reached an agreement that includes “ethical safeguards.” What those safeguards are, specifically, has not been disclosed. What is public is that OpenAI agreed to operate in classified settings and did not maintain the same red lines Anthropic insisted on.

The Timeline

February 16: Pentagon threatens Anthropic’s $200M contract over Claude’s safety restrictions
February 26: Anthropic publicly refuses to remove guardrails
February 28: Trump orders six-month government-wide phase-out of Anthropic
February 28: OpenAI announces Pentagon deal, including classified deployment
March 1: Treasury Secretary Bessent confirms all Anthropic contracts terminated
March 3: State Department switches to OpenAI’s GPT-4.1
March 9: Anthropic files two lawsuits (N.D. Cal. and D.C. Circuit), alleging First Amendment retaliation
March 17: DOJ files 40-page rebuttal claiming “conduct not speech”
March 17: OpenAI expands government footprint with AWS partnership
March 18: Silicon Valley files amicus briefs supporting Anthropic
March 24: Preliminary injunction hearing, Judge Rita Lin, 1:30 PM, San Francisco

This story started with a $200 million contract and a company that said no. Five weeks later, it involves the First Amendment, national security law, the entire AI industry, both chambers of Congress, and a courtroom in San Francisco. The pattern from our previous coverage holds. The market punishes recklessness. The government punishes refusal. The question Monday is whether the courts will let it.

Federal prosecutors in Manhattan unsealed indictments on March 19 charging three individuals tied to Super Micro Computer with running a $2.5 billion smuggling operation that funneled restricted Nvidia AI chips to China through Southeast Asia. SMCI co-founder Yih-Shyan “Wally” Liaw was arrested the same day. So was contractor Ting-Wei “Willy” Sun. A third defendant, Taiwan-based sales manager Ruei-Tsang “Steven” Chang, is a fugitive.

The DOJ is calling it Operation Gatekeeper. The scale is staggering.

According to the indictment, the scheme worked like this: Liaw and his associates arranged for US-assembled servers packed with Nvidia’s H100 and H200 GPUs to be shipped to an unnamed company in Southeast Asia. On paper, that company was the end customer. In reality, a logistics firm in Taiwan would strip the Supermicro packaging, remove serial numbers using industrial hair dryers, repackage the servers into unmarked boxes, and forward them to buyers in China. To pass audits, the defendants allegedly staged thousands of dummy servers at the Southeast Asian company’s warehouse, physical replicas with swapped serial numbers designed to fool anyone who came looking.

They weren’t amateurs. According to Tom’s Hardware, the operation used heat to transfer serial number stickers between real and fake hardware. A hair dryer. That’s the tool that beat America’s export control regime for two years. Between 2024 and 2026, the scheme moved an estimated $2.5 billion in restricted AI hardware to China, with $510 million in servers flowing through in a single three-week window between late April and mid-May 2025.

The market response was immediate. SMCI shares cratered more than 28% on Friday, erasing roughly $6 billion in market capitalization. Nvidia dropped nearly 5%. Liaw resigned from Super Micro’s board effective March 20. The company issued a statement noting it is not named as a defendant, placed two employees on administrative leave, terminated the contractor, and appointed DeAnna Luna as acting Chief Compliance Officer.

Super Micro is not named as a defendant. Keep that sentence in your pocket. It’s doing a lot of work.

Hindenburg Called It

None of this came from nowhere. In August 2024, Hindenburg Research published a short report alleging accounting manipulation, undisclosed related-party transactions, and sanctions evasion at SMCI. Hindenburg flagged that Super Micro might be routing sales to entities on US export ban lists through partner intermediaries. The stock dropped. Super Micro delayed its 10-K filing. The SEC opened a probe. And then the AI bull market carried the stock back up because nobody wanted to hear it.

Hindenburg’s allegations about export control violations are now a federal indictment. Their three-month investigation found what the US government’s own compliance apparatus apparently could not: that one of America’s largest server manufacturers had a co-founder allegedly running a parallel distribution network to China.

The Kill Switch

Here’s where it gets interesting. At GTC 2026, days before the indictments dropped, Nvidia unveiled two products that look very different in hindsight: OpenShell and the Agent Toolkit.

On the surface, OpenShell is an open-source runtime for securing autonomous AI agents. It has a sandbox, a policy engine governing filesystem and network access, and a privacy router controlling where inference traffic flows. Standard enterprise security stuff.

But OpenShell has a second function that nobody at GTC wanted to say out loud. According to reporting from FinancialContent, the software allows the US government to monitor and potentially disable AI workloads that violate export compliance policies. In real time. Remotely.

Nvidia didn’t build OpenShell because it wanted to. The Trump administration placed Nvidia under “heightened federal audit” status, demanding unprecedented transparency into the company’s Know Your Customer protocols. The deal that allows Nvidia to keep selling H200 chips to China comes with a mandatory 25% revenue-sharing cut to the US government, a condition first reported by Axios in December 2025. OpenShell is Nvidia’s compliance offering: proof that it can enforce export restrictions at the software layer, even after hardware leaves the factory.

In other words, Nvidia built a kill switch for its own chips.

What This Actually Means

The Super Micro indictment and Nvidia’s response together represent a shift in how the US thinks about export controls. The old model was paperwork. End-user certificates. Customs declarations. The assumption that you could track physical goods through physical systems. That model just failed to the tune of $2.5 billion, defeated by a hair dryer and some dummy servers in a warehouse.

The new model is software enforcement. If you buy Nvidia’s latest GPUs, the compliance layer ships with them. The US government can see where the workloads run. If they don’t like what they see, they can shut it down. This is not hypothetical. This is the architecture Nvidia presented at GTC, and the federal audit framework is the enforcement mechanism behind it.

Think about what that means for every data center operator, every cloud provider, every ODM in Asia. Your Nvidia hardware now phones home. Your compliance is no longer a filing in a cabinet. It is a live connection between your servers and a policy engine that the US government can query.

Some will call this reasonable. After all, a co-founder of one of America’s biggest server companies allegedly ran a multi-billion-dollar smuggling ring for two years while auditors saw nothing. The old system clearly did not work.

But the precedent is severe. The US government now has a mechanism to remotely monitor and disable computing infrastructure anywhere in the world where Nvidia chips are deployed. That is not just an export control. That is a lever over the global AI supply chain. And the company that builds the lever gets to keep selling chips to China, as long as it cuts the government in for 25%.

Super Micro’s stock lost $6 billion in a day. Three people got arrested. The Nasdaq dipped. Those are the headlines. The real story is what comes next: a world where every advanced GPU ships with a government-accessible compliance layer baked in, and where the price of doing business with American silicon is permanent visibility into what you do with it.

The Silicon Silk Road is closed. What replaced it might be worse.

The U.S. Department of Justice, working with authorities in Germany and Canada, announced Thursday that it had dismantled the command-and-control infrastructure behind four major botnets: Aisuru, KimWolf, JackSkid, and Mossad. Together, they had compromised more than three million devices worldwide, hundreds of thousands of them in the United States. The networks launched what prosecutors described as hundreds of thousands of DDoS attacks, including strikes against U.S. Department of Defense systems.

The largest single attack, a UDP flood linked to the Aisuru botnet in November 2025, peaked at 31.4 terabits per second. That is nearly six times the largest attack recorded in all of 2024, according to court documents cited by KrebsOnSecurity.

Two suspected operators have been identified. Canadian authorities targeted a 22-year-old man believed to be a core operator of the KimWolf botnet. German police said they searched the residence of a 15-year-old suspected of co-administering the networks. Extensive digital evidence was seized at both locations, according to German law enforcement statements reported by SecurityWeek.

A 22-year-old and a 15-year-old. Running networks capable of knocking Department of Defense systems offline.

How It Worked

The infected devices were overwhelmingly consumer IoT hardware. Webcams, digital video recorders, home routers, and according to Cloudflare’s technical summary, unauthorized Android TV streaming boxes. Cheap devices with weak or nonexistent security, sitting on home networks with factory-default passwords.

Aisuru first appeared in late 2024 as a Mirai variant, building on the infamous botnet code that was publicly leaked in 2016. By October 2025, the operators had spawned KimWolf, a variant with a new spreading mechanism that could reach devices hidden behind NAT on internal home networks. That is a meaningful technical escalation. Most IoT malware only catches devices directly exposed to the internet. KimWolf could reach the ones behind your router.

According to FastNetMon’s analysis, the combined attack capacity of the Aisuru and KimWolf infrastructure grew by over 700% in a single year.

The operators ran it as a business. Prosecutors said they sold access to the botnet through DDoS-for-hire services, according to The Register. Pay a fee, pick a target, and three million devices flood it with traffic. Some victims were extorted directly: pay up, or the attack continues.

The Takedown

The DOJ, operating through the U.S. Attorney’s Office for the District of Alaska, seized domains and backend systems used to coordinate the botnets. Nearly two dozen private companies participated, including Amazon Web Services, Google, and Cloudflare, according to CP24’s reporting. The cooperation cut off the command-and-control channels, which means the infected devices can no longer receive instructions from the operators.

This is the standard playbook for botnet takedowns. And it is exactly where the standard playbook falls short.

What Nobody Fixes

The three million devices are still compromised. Cutting the command-and-control channel does not clean the malware off a webcam or a router. It does not patch the vulnerability that let the device get infected in the first place. It does not change the factory-default password. Most owners of these devices do not know they were part of a botnet. Many will never know.

This is the cycle that has repeated since Mirai’s code went public a decade ago. Law enforcement takes down the infrastructure. The devices sit unpatched. New operators build new botnets from the same pool of vulnerable hardware. FastNetMon’s post-takedown analysis is blunt: “the botnet cycle continues.”

The IoT security problem is a manufacturing problem. Device makers ship products with known vulnerabilities, minimal update mechanisms, and default credentials that are publicly documented. There is no regulatory requirement in the United States forcing manufacturers to support these devices with security patches after sale. Some of the compromised devices in this operation probably cannot be updated at all.

The Timeline That Doesn’t Add Up

Here is the sequence. Read it slowly and ask yourself how these things happen simultaneously.

The Pentagon and the White House have spent the last two years warning that cyber warfare is the future of armed conflict. Chinese state hackers breached U.S. critical infrastructure through the Volt Typhoon campaign. Russian groups hit hospitals and water treatment plants. The Director of National Intelligence’s 2026 threat assessment put cyber at the top. Every appropriations hearing, every defense briefing, every national security speech says the same thing: the next war starts in cyberspace.

At the exact same time, the Trump administration gutted the agency built to defend against it. CISA is now operating at roughly 38% of its optimal staffing levels after waves of budget cuts and layoffs. The agency lost about a third of its workforce since January, according to TechCrunch. Programs dedicated to counter-ransomware efforts and secure software development have been gutted. Experienced specialists who spent years building relationships with critical infrastructure operators, water systems, power grids, healthcare networks, are gone.

Then in February, DOGE pushed to cut funding further. Career cybersecurity experts in regulated industries, people who understand the technical specifics of the sectors they protect, were removed from their positions. Not because they failed. Because the administration decided their roles were expendable.

And then this week, the DOJ announces a multinational takedown of botnets that hit Department of Defense systems. Built by teenagers. Using decade-old code. Targeting devices that have no security requirements because no regulation forces manufacturers to build secure IoT hardware.

That is the contradiction. You cannot claim cybersecurity is a national security priority while slashing the workforce, the funding, and the institutional knowledge that makes cybersecurity work. You cannot cut the experts out of regulated fields and then act surprised when the gaps they were covering get exploited. The DOJ can still mount an operation to take down command infrastructure. Good. But the agency responsible for helping organizations actually defend against the next attack is being hollowed out in real time.

Enforcement and prevention are moving in opposite directions. The government is spending money on the takedown and cutting money from the defense. That is not a strategy. That is a photo op.

The suspected architects of a network that hit the Pentagon are a college-age Canadian and a German teenager. They used a decade-old exploit framework against devices nobody bothered to secure, while the agency meant to prevent this was running at a third of capacity. The takedown worked. The underlying problem did not get one inch closer to being solved. And the people who could have been working on it were shown the door.

Every enterprise deploying AI agents right now is dealing with a question nobody planned for: what, exactly, is this thing allowed to access?

Tailscale, the Toronto-based VPN startup, just made its first acquisition. Border0, a seven-person privileged access management company out of Vancouver, joined Tailscale on March 17. The deal puts Border0 founder Andree Toonk, a former Cisco senior engineering manager with a decade of network infrastructure experience, into the role of Director of Engineering at Tailscale. His team is building what amounts to air traffic control for autonomous software.

The problem is practical, not theoretical. Companies are deploying AI agents that write code, query databases, modify production servers, manage Kubernetes clusters, and interact with sensitive customer data. These agents request permissions, move across systems, and take actions that traditional identity tools were never designed to handle. A human employee gets onboarded, assigned a role, given credentials. An AI agent gets spun up, runs for 45 seconds, touches six different systems, and disappears. The security model for the first scenario does not work for the second.

Border0’s technology manages and monitors what people and software are allowed to access across production systems, databases, and infrastructure. Tailscale’s mesh VPN already acts as the connective layer for corporate networks. Together they can answer the question that every CISO is now asking: which agents can touch which systems, under what conditions, with what audit trail?

A New Category of Commerce

According to Bloomberg, Tailscale’s customer base grew rapidly since 2024, with a significant portion of that growth tied directly to the explosion of agentic AI. Companies discovered that Tailscale’s platform could function as an access control layer for agents accessing corporate data. That was not the product’s original purpose. The customers found the use case before the company did.

This is how new industries form. Not from a grand vision but from a collision between a new technology and an existing problem. AI agents created a security gap. Tailscale happened to be positioned in the gap. Border0 had the specialized tooling to fill it. The acquisition is the formalization of something that was already happening in production environments.

The pattern extends beyond Tailscale. When PromptSpy became the first documented AI malware, it demonstrated that the attack surface for AI systems is fundamentally different from traditional software. When Microsoft’s Copilot bypassed data loss prevention controls to read confidential emails, it proved that enterprise AI tools can ignore the security boundaries they are supposed to respect. Each incident creates demand for a product category that did not exist two years ago.

The story of AI in 2026 is not just about what the models can do. It is about the entire ecosystem of businesses that form around managing what they are allowed to do. Privileged access management for AI agents is one category. Compliance monitoring for autonomous decisions will be another. Audit logging for agent-to-agent communication will be a third. Each of these will be a company. Some of them will be billion-dollar companies. And most of them do not exist yet.

What This Means for Everyday People

If your company uses AI tools that access internal systems (Copilot, Salesforce Einstein, coding assistants, customer service bots), the question of what those tools can see and do is probably not well defined. Tailscale’s acquisition of Border0 is one company’s answer to that problem, but the problem itself affects every organization deploying AI agents. The tools your employer gives access to your data are increasingly autonomous. Whether anyone is controlling what they touch is a question worth asking your IT department.

For inquiries and analysis contact laterstack@proton.me

The UK government wanted to let AI companies train on copyrighted works and give creators an opt-out. Elton John, Dua Lipa, and 11,500 public responses to the consultation said no. On March 18, Technology Secretary Liz Kendall confirmed the government has reversed course. The original plan is dead. The government now says it has “no preferred option” for what comes next.

Tom Kiehl, chief executive of UK Music, called it “a major victory for campaigners.” Mandy Hill, president of the Publishers Association, said the backtrack was a victory “over the self-interest of a handful of large corporations.” The government’s new position: an “evidence-led approach” that prioritizes transparency obligations and lets a licensing market develop on its own.

That last part is the story. Not the backtrack. The licensing.

Why Licensing Is the Entire Game

A license is permission to use something you do not own. It is the mechanism by which one party controls access to something another party needs. When you stream a song on Spotify, the label licensed it. When a pharmaceutical company uses a patented molecule, it licenses it. When a franchise opens a McDonald’s, it licenses the brand, the recipes, the systems. Licensing is not a niche legal concept. It is the infrastructure of modern commerce.

What the UK government just did, intentionally or not, is confirm that AI training data is a licensable asset. If AI companies cannot freely scrape copyrighted material, they must negotiate for it. That means publishers, music labels, photo libraries, news organizations, and individual creators now sit on something with a price tag. The question is no longer whether they get paid. It is how much.

This is not small. OpenAI has already signed licensing deals with Associated Press, Axel Springer, Le Monde, and Prisa Media. According to the Financial Times, these deals range from single-digit millions to over $100 million annually for large publishers. Every AI company that trains on text, images, music, or video will eventually need similar agreements, or face litigation. The UK just nudged the entire market toward that reality faster.

Three Countries, Three Approaches

The regulatory map is splitting in real time. Yesterday the UK committed £2 billion to quantum computing procurement, signaling aggressive tech investment. Today it retreated on AI copyright, signaling caution. Same government. Opposite energy. The pattern tells you something: the UK wants to build technology but is not willing to let technology take from creators without compensation.

The EU moved first. The AI Act requires transparency about training data and respects existing copyright law. Licensing is the default.

The United States has done nothing. No federal AI copyright legislation. The New York Times is suing OpenAI. Getty Images sued Stability AI. The courts are making the rules because Congress will not. The UK just chose to step off that path and let the market negotiate instead of waiting for judges to decide.

What This Means for Everyday People

If you have ever taken a photo, written a blog post, recorded a song, or published anything online, your work may have been used to train an AI model. Until now, most AI companies treated publicly accessible content as free training data. The UK’s reversal, combined with the EU’s existing rules, is establishing a global norm: that content has value and using it requires permission.

Licensing changes who has leverage. A photographer whose images trained Midjourney currently has no recourse and no revenue. In a licensing framework, that photographer’s images become an asset that AI companies must negotiate for. The same applies to journalists, musicians, authors, and researchers. This does not mean every creator will get rich. It means the default shifts from “your work is free” to “your work has a price.” That is a structural change, not a policy tweak.

The UK government does not have a plan for what comes next. It said so explicitly. But by killing the free-use option and endorsing licensing as the direction, it made a choice that will shape how AI companies operate globally. The companies that start building licensing infrastructure now will have an advantage. The ones that assumed the data would always be free just lost that bet.

For inquiries and analysis contact laterstack@proton.me

Thirty-seven of the most cited AI researchers in the world filed an amicus brief this week supporting Anthropic’s lawsuit against the federal government. Workers at OpenAI and Google signed open letters backing Dario Amodei’s refusal to remove safety restrictions from Claude. The support is not theoretical. It is legal, public, and filed with the court.

This is the third chapter of a story that started in February. On February 16, the Pentagon threatened to revoke Anthropic’s $200 million contract over Claude’s restrictions on autonomous weapons and mass domestic surveillance. Defense Secretary Pete Hegseth gave Anthropic a Friday deadline. Anthropic refused. On February 27, President Trump ordered all federal agencies to cease using Anthropic’s technology and Hegseth designated the company a supply chain risk to national security.

The same day Anthropic was banned, OpenAI announced a deal with the Pentagon to provide its models for classified military applications. The timing was not subtle. Sam Altman later admitted to CNBC that the announcement “looked opportunistic and sloppy.”

The Deal vs. The Demand

Both companies say they oppose mass surveillance and fully autonomous weapons. The difference is enforcement.

Anthropic demanded contractual restrictions. Specific, binding language that would give the company the right to refuse if the Pentagon crossed defined lines on domestic surveillance or lethal autonomy. The Pentagon said no. It insisted on an “all lawful purposes” standard, meaning the military could use Claude for anything that existing law permits. Anthropic’s position: existing law is not enough. The company walked away.

OpenAI’s deal takes the opposite approach. The Pentagon “agrees” to prohibitions on mass surveillance and human responsibility for the use of force. But OpenAI has no contractual right to enforce those prohibitions. If the Pentagon breaks the agreement, OpenAI cannot pull access. The safeguards are policy statements, not legal mechanisms. As MIT Technology Review put it: this is what Anthropic feared.

The Split

The amicus brief makes it explicit. Thirty-seven researchers, including employees from Anthropic’s direct competitors, told the court that the government’s actions threaten the ability of AI companies to maintain safety standards. The DOJ responded by vowing a legal fight, calling Anthropic’s terms of service “unacceptable to the Executive Branch.”

The industry has divided into two camps. One says safety restrictions are non-negotiable, even if it means losing government contracts. The other says you work within the system, accept the Pentagon’s assurances, and trust existing law.

Meanwhile, xAI was sued last week by three teenagers whose yearbook photos were turned into AI-generated child pornography by Grok. The company that built its model with no safety restrictions is facing a class action. The company that built its model with the strictest safety restrictions in the industry is facing a federal ban. And the company that split the difference got the contract.

The pattern is not complicated. It is just uncomfortable. The market punishes recklessness. The government punishes safety. And the company that says the right words without enforceable commitments gets paid.

This is not an AI governance debate. It is a procurement decision with a $200 million price tag and a legal precedent attached. The court’s ruling on Anthropic’s lawsuit will determine whether the federal government can blacklist an American company for refusing to weaken its own product. If it can, every AI company will face the same calculation Altman already made.

What This Means for Everyday People

The AI tools that governments use to make decisions about citizens, from benefits eligibility to surveillance targeting to military operations, are being selected based on which companies are willing to remove safety restrictions. Anthropic said no and lost the contract. OpenAI said yes and got it. The tools your government uses are now determined not by which are safest or most capable, but by which companies are most compliant.

If Anthropic loses the lawsuit, the precedent is clear: the federal government can punish any technology company that refuses to remove product safeguards. That does not stay in the defense sector. It extends to healthcare AI, financial AI, education AI, anywhere the government is a customer. The question is whether “all lawful purposes” is a standard you’re comfortable with when the law hasn’t caught up to the technology.

For inquiries and analysis contact laterstack@proton.me

Chancellor Rachel Reeves announced on March 17 that the United Kingdom will commit £2 billion ($2.67 billion) to quantum computing over the next four years. Half of that, £1 billion, is a direct procurement commitment. The government will buy quantum computers for scientists, the public sector, and commercial users. The other half, previously announced, funds deployment of quantum technologies in finance, energy, and pharmaceuticals.

The program, called ProQure: Scaling UK Quantum Computing, launches in late March. Companies will submit prototype machines for evaluation, with the government targeting large-scale quantum computers built on British soil by the early 2030s. The funding breaks down to over £500 million for quantum computing hardware and scaling, £400 million for sensing and navigation, £125 million for quantum networking, and £205 million for quantum sensing. Reeves claims the initiative could create 100,000 UK jobs and generate £212 billion in economic value over two decades.

The announcement was part of a broader £2.5 billion technology investment package. Bloomberg reported the quantum spending as the centerpiece.

Procurement Is the Story

Most government quantum money worldwide takes the form of research grants. Fund the lab. Hope something useful comes out. The UK is doing something structurally different. It is buying computers. Not funding proposals to maybe someday build one. Placing purchase orders.

That distinction matters. Research grants create papers. Procurement contracts create revenue. For quantum companies that have spent years burning venture capital while waiting for product-market fit, a government showing up as a guaranteed customer changes the math. IonQ has already established a Quantum Innovation Centre at the University of Cambridge housing a 256-qubit system. Infleqtion delivered an operational 100-qubit quantum computer to the UK’s National Quantum Computing Centre. PsiQuantum operates a cryogenic testing facility in the UK. These companies are not just beneficiaries of the announcement. They are already embedded in the infrastructure the procurement program will scale.

The Numbers That Don’t Add Up

Government investment in quantum technology varies enormously by country. China has committed approximately $15.3 billion, including a $10 billion national laboratory. The European Union collectively has pledged roughly $7.2 billion. Germany alone is at $3.1 billion. France is at $1.8 billion. The United States has spent roughly $4 to $5 billion across fragmented agency budgets.

The UK’s £2 billion ($2.67 billion) puts it ahead of France and competitive with EU member states individually. But it is roughly one-sixth of China’s commitment. The question is whether the UK’s procurement-first approach generates more commercial output per dollar than China’s research-first approach generates per yuan. History suggests that government buying power accelerates industries faster than government research grants. The U.S. semiconductor industry was built on Defense Department procurement in the 1960s, not university lab funding. The UK appears to be borrowing from that playbook.


The bear case is obvious. Procurement only works if the products work. Quantum computers in 2026 still cannot outperform classical systems on most problems that businesses actually care about. The UK may be buying expensive prototypes that look good in a press release and deliver marginal academic value. The 100,000 jobs projection and £212 billion impact figure are government aspiration math. They carry no binding mechanism and no accountability if they do not materialize.

However, quantum will deliver. When a technology creates an entirely new substrate for computation, the industries that form around it do not look like extensions of existing ones. They look like things nobody predicted. The semiconductor procurement programs of the 1960s did not plan for the internet. The UK is not just buying quantum computers. It is trying its hardest at buying a seat at whatever comes next.

What This Means for Everyday People

Quantum computing remains years away from affecting daily life directly. But government procurement programs determine which companies survive to build the machines that eventually will. If you hold stock in quantum computing companies, today’s announcement creates near-term revenue for IonQ, Infleqtion, and PsiQuantum. If you work in quantum research, the UK just signaled it will be a paying customer and if you are watching the geopolitical technology race, the UK just placed a $2.67 billion bet that buying machines is smarter than funding papers.

The question is whether that bet pays off before China’s 6x spending advantage delivers something the UK cannot replicate.

For inquiries and analysis contact laterstack@proton.me