On 1 May 2026, three researchers at a Palo Alto firm called Calif (Bruce Dang, Dion Blazakis, and Josh Maine) had a working exploit running against Apple's Memory Integrity Enforcement on the M5 chip. Five days, end to end. Apple had spent roughly five years and a budget estimated in the multi-billions building MIE, and had positioned it as the strongest memory protection ever embedded in consumer silicon. Independent security researchers had said publicly that getting through it would take years, if it could be done at all. The protection went down in five working days of human time.
The team disclosed in person at Apple Park on 14 May. They were direct about how the work had been done. They had used a restricted Anthropic model called Claude Mythos Preview as an accelerator. The model recognised known bug classes and helped move exploit code along. The novel work, the part that bypassed MIE, was human expertise. Their own line: "Part of our motivation was to test what's possible when the best models are paired with experts."
Now read the headlines.
AppleInsider: "Anthropic's Mythos AI outsmarted Apple's Mac security systems."
Cult of Mac: "The iPhone and Mac security Apple spent 5 years building? AI broke it in 5 days."
Beginners in AI: "Claude Mythos Cracked Apple's Mac M5 Security in 5 Days."
AI outsmarted. AI broke. AI cracked. Three publications. Three sentences in which the subject doing the verb is the tool, not the person. The exploit did not outsmart, break, or crack anything. Three named humans used a tool to bypass an Apple defence. The work was named at the source. The credit was changed at the headline. That gap is the article.
The grammar swap
AI does not act. Humans using AI act. Every sentence that says "AI did X" is a sentence where a human chose X, deployed AI to accelerate X, and put their name on X. Removing the human from the sentence is not a writing style. It is an editorial choice. Editorial choices serve outcomes.
The swap is not just sloppy writing. It is engineered sensationalism. "AI outsmarted Apple" travels further than "three researchers used a tool to bypass an Apple defence." One reads as the future arriving. The other reads as Tuesday. The grammar gives the same event the weight of a science fiction milestone, and the perception manufactured by that weight does the rest. Fear sells. Clicks compound. The story keeps moving because the framing has been cut loose from anything as small as the people who actually did the work.
A familiar trick
This trick has been run before. For three years, on the people of every country.
People did not die of COVID at the rate reported. Most people died with COVID, which is a different sentence with different policy consequences. The ridiculous edge cases (the car accident victim coded as a COVID death because of a positive test) revealed the trick. The grammar was changed at the certification layer, not at the cause of death.
Look back at the headlines on the M5 exploit. All three do "died of AI". AI named as the actor doing the verb. Outsmarted. Broke. Cracked. The title of this article matches their grammar on purpose, so the reader notices the move. The "died of" framing carried the COVID policy. The "died of" framing is now carrying the AI panic.
The diagnostic that certified hundreds of millions of those cases was PCR. Kary Mullis, who invented PCR and won the Nobel for it, was on the record across decades stating that PCR was a manufacturing tool, not a diagnostic instrument, and that it should never be used to determine viral load or infection status. He died on 7 August 2019. The Event 201 pandemic deployment exercise ran on 18 October 2019. Ten weeks. The man who would have been the loudest credentialled voice against the planetary deployment of his instrument as a binary diagnostic was not in the room when the deployment was rehearsed.
This is not a COVID article. The point is that the "died of" framing was not an editorial curiosity. It produced the case-count headlines that drove lockdown policy, vaccine mandates, business closures, and the largest expansion of executive emergency powers in living memory. The grammar carried the policy. The certification grammar was changed at the instrument. The framing grammar was changed at the headline. The same trick is now being applied to AI, where "this is too dangerous" becomes the foundation for regulatory consolidation that quietly concentrates the most capable tools inside a small approved set of state-aligned operators.
The part most people miss
Some of the fear is well-founded. A capable tool in the hands of someone with malicious intent has always been a problem, and AI is no different. Evolve or Be Remembered covered this at length. AI is absorbing the operating system of a fractured species, and a fractured species using a powerful tool produces consequences we should take seriously. That work stands.
What is being done with the fear, however, is something different. The public is being told that AI itself is too dangerous to release. Ordinary people cannot be trusted with these tools. The companies that build them are holding the line on safety. That is the story. The same fear is then being used to justify civilian access restrictions and regulatory consolidation, while the technology described as too dangerous for the public is deployed at scale by the agencies whose stated wishes include exactly the harms the public is being trained to fear.
The lived reality, on the record, in mainstream reporting, is different.
The same Claude Mythos Preview that the public is told is not for general release is running on classified networks at the US National Security Agency. Axios reported it. Reuters confirmed it. The NSA falls under the Department of Defense. The Department of Defense designated Anthropic a "supply chain risk" on 27 February 2026, after Anthropic refused to remove two contractual red lines that the Pentagon wanted dropped. No autonomous weapons. No mass domestic surveillance of Americans.
Read that last bit again. No mass domestic surveillance of Americans. The state asked the company to remove the prohibition on using the model to surveil Americans at scale. The company refused. The state retaliated publicly. The intelligence arm of the state kept using the model anyway.
Now note what is absent from that list. Mass surveillance of Australians, Britons, New Zealanders, Canadians. The rest of the Five Eyes. Mass surveillance of Europeans. Mass surveillance of anyone outside the United States. Use against non-American residents on US soil. The silence in the contract is its own grammar. The prohibition the company refused to drop named one population. The protocols it did not name remain available.
A former DOD and NSA official, Adam Maruyama, is on the record stating that Chinese state-backed adversaries likely have equivalent capability already, and that the offensive tooling on their side is unknown and probably exquisite. The arms race is not coming. It is here.
A tier above Mythos is already named in public reporting (Copybara). Anthropic itself has stated that the next round of safeguards is being developed on an upcoming Claude Opus model, with the goal of eventually deploying Mythos-class capability more broadly. The trajectory is more capability, not less. The civilian release schedule runs behind the classified one.
Over forty additional critical infrastructure organisations have access. Some named. Some not.
None of this is new in pattern. The atomic age launched with civilian assurance about deterrence and oversight while operational doctrines were being written that would not be declassified for decades. The mass surveillance era launched with civilian assurance about minimal collection while operational reality was vastly broader, as Snowden's 2013 disclosures documented. The AI era is following the same template. Public framing of restraint. Operational reality of unconstrained deployment inside the perimeter the framing protects.
This is the architecture. The fear is the cover. The deployment is the point. None of it requires conspiracy. It is documented, on the record, with named sources. The leader's job is to read it.
Fear the hand, not the tool
Step back from the M5 case for a moment and look at the AI fear discourse as a whole. Once you have read the architecture, the public message describes the wrong variable.
A gun in a locked safe is not dangerous. A scalpel on a surgical tray is not dangerous. A car parked in a driveway is not dangerous. A nuclear reactor running inside an engineered containment vessel is, by design, not dangerous. The danger in each case is the hand and the intent. The variable that determines outcome is who is using the tool and to what end. The tool itself is neutral until the hand picks it up.
AI works the same way. AI in the hands of a researcher disclosing exploits responsibly to Apple is not the problem the fear discourse describes. AI in the hands of a clinician supporting diagnoses, a teacher building course material, a journalist verifying a source, or a small business owner running their accounts is not the problem either. AI in the hands of an intelligence agency that has just asked the developer to drop the prohibition on mass surveillance of its own people is a different proposition. AI in the hands of a state-aligned operator running offensive cyber operations against civilian infrastructure is a different proposition. AI in the hands of a contractor whose business model depends on producing the framing the public will then react to is a different proposition again.
The hand and the intent are the variables that matter. The grammar swap obscures the hand. The civilian-facing fear narrative misdirects attention to the tool. Both run in the same direction. Both produce the same result. The public worries about AI. The actors with the most consequential intent acquire the most capable AI with the fewest restrictions.
This is the trick to name. Fear is not the wrong response. Fear is the right response misdirected. Fear the hand, not the tool.
On your team's desks
Here is what this looks like at the level of running a business. The framing reaches your team through the news they read on their phones in the morning, the LinkedIn posts they scroll between meetings, and the consultancy reports that land in your inbox with quarterly regularity. By the time AI shows up on the executive agenda, the conversation has already been shaped. Vendor selection runs through the framing. Contract terms run through the framing. Internal usage policies run through the framing. Risk assessment, the most consequential of the four, runs entirely through the framing. Decisions about what your people can and cannot do with AI are being made inside someone else's grammar. The leader who has not noticed the grammar cannot exit it.
The fear that lands first inside companies is data leakage. The model might learn from your inputs. Your competitors might see your trade secrets. Customer data might end up on someone's training set. The concern is real but it is not new. Every cloud storage decision, every SaaS deployment, every email service since the 1990s has carried the same shape of question. What is new is the unfamiliarity of the surface. Leaders feel less control because they have not been holding the reins long enough to recognise the leather. The substance is what they have been managing for a decade.
What is harder to spot is the second pattern, the one I see consistently in client work. The most consequentially bad AI decisions inside companies are usually being made for self-protective reasons rather than strategic ones. A senior who blocks a useful internal AI deployment because it might make their role visibly automatable. A function that bans AI internally while quietly relying on AI-generated content from external agencies. A leader who commissions an expensive AI strategy report because the existence of the report covers them in a future post-mortem. These are job-preservation behaviours dressed as AI policy. They show up in the same rooms where the engineered framing is being absorbed without examination, because the framing provides cover for the behaviour. The leader's job is to spot both at once.
Reading causation honestly
Leaders are being asked to make decisions about AI inside a fear framing that is engineered, not earned. The leader who accepts the engineered framing makes engineered decisions. The leader who reads causation honestly makes choices.
There are two deviations from a working standard here. The first is the grammar swap that erases the human and installs the tool. The second is the public posture of restraint where the operational reality is unrestricted classified deployment. Both are visible once you look. The Standards Sniper™ job, for those who know the work, is to surface both and refuse them.
A distinction I keep coming back to in client work. A decision is made after consideration and subject to it. A choice is made after consideration but independent of it. A decision can point backwards at the reasoning that led to it. A choice cannot, because the call was yours regardless of what the evidence suggested. Decisions create responsible people. Choices create accountable ones.
State use of AI for mass surveillance is a choice. State refusal to be bound by the limits it negotiated in a contract it signed is a choice. The framing that buries those choices under "AI did X" is also a choice. None of them are decisions. There is no reasoning trail to retreat behind in any of them. Someone, somewhere, considered and then stood on their own judgement.
Leaders who read causation honestly make choices. Leaders who do not are making decisions inside a framing they did not pick and cannot see. Responsibility flows easily through that mechanism. Accountability does not.
The honest sentence
Bruce Dang, Dion Blazakis, and Josh Maine put their names on the work. That is what conviction looks like in the wild. The publishers who erased them and credited a tool. That is what cowardice looks like, dressed as a headline.
Widen out. The story of AI is full of named humans making named choices. The researchers at Calif. The Anthropic executives who refused to drop the surveillance prohibition. The Pentagon officials who asked them to drop it. The intelligence agency operators using the model on classified networks while their parent department was busy publicly designating the supplier a risk. Kary Mullis, ten weeks before Event 201. Three publications running headlines that erased three researchers.
There are no AI actors in this story. There are human actors. The framing that pretends otherwise is the story.
When you read "AI did X," ask three questions. Who did X using AI? Why was the sentence written to remove them? Who benefits from the removal? Read every consequential story this way. Not just the AI ones. The honest sentence is always available. Someone chose not to write it.
Paul Lange advises owners, executives, and boards on the decisions that define commercial outcomes and organisational character, and on what a working board actually contributes. He has spent close to four decades across finance, technology, hospitality, professional services, and operating roles, in Europe, Asia, the Middle East, and Australia, on both sides of the table, with private equity and venture capital one part of it, and has taken five of his own companies through to exit. He is the creator of the Total QX™ and TILE Theory™ frameworks, and the author of The 20% Leader, Mis(très)s Entrepreneur Manifesto, Evolve or Be Remembered, and The Inheritance Manifesto. He runs his advisory practice, Manolutions, from the Gold Coast, Queensland. He writes Conviction because leadership without accountability is just theatre.


