Does Mythos change cyber risk on Chinese hardware?
ChinaTalk Jordan Schneider
New AI models are getting terrifyingly good at finding hidden bugs in hardware and software. That might kill the argument that Chinese-made tech is inherently more dangerous than anyone else's.
Based on reporting by ChinaTalk, Jordan Schneider — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
A new wave of AI models — think Anthropic's Mythos/Fable, OpenAI's GPT 5.6, Z.ai's GLM 5.2 — has gotten remarkably skilled at sniffing out vulnerabilities nobody knew existed. Most of the chatter about that has focused on offense, on hackers using these tools to break in. But Mieke Eoyang, a visiting professor at Carnegie Mellon's Institute for Security and Technology and former Pentagon cyber policy official, argues the more interesting story is defense. If these models can find flaws at scale, they can also help patch them at scale. And that changes the entire conversation about whether Chinese-made hardware deserves special suspicion.
The standard worry has always been twofold: either Beijing quietly builds backdoors into products before they ship, or its intimate knowledge of the supply chain lets it engineer one in later. Eoyang points out that hiding a backdoor from scrutiny was already hard before these models existed. She cites the 2013 case where researchers found flaws in an NSA-proposed encryption standard, prompting NIST to quietly walk back its recommendation after the Snowden leaks — a mess that helped spawn PGP and still dents the NSA's credibility today. Mythos-class tools make that kind of concealment even less realistic, because they dramatically speed up the window in which defenders can spot a planted flaw before an attacker ever gets to use it.
One NSA veteran told Eoyang that cyber operations have a way of breaking your heart: you plan for months, and the night before execution your target patches the exact hole you were counting on. That dynamic gets worse for attackers as detection tools accelerate. Even if a government leans on a manufacturer to leave a known vulnerability open for its own access, the reputational fallout once that gets discovered would be brutal — customers would simply stop trusting the product. Eoyang thinks enterprises should start routinely running these models against their own tech stacks as basic risk management, and that the whole idea that original manufacturers hold some permanent edge in exploiting their own products starts to fall apart once outside models can probe just as deeply.
Which raises an uncomfortable question for US policy: if Chinese, American, and European products all carry the same kind of legacy vulnerabilities baked in from decades of software and hardware development that never prioritized security, and if Mythos-class tools can expose any of them regardless of who built it, what's actually left of the national-origin argument behind bans on Chinese EVs, drones, and routers? Eoyang suggests the calculus could shift back toward cost, performance, and availability — evaluating suppliers device by device rather than banning entire countries wholesale, including scrutiny of things like foreign-made battery management systems feeding data center power.
She's careful not to call for an open door, though. China's habit of requiring vulnerability disclosures to go to the government first, and its historic reluctance to build a public-facing bug bounty and patching culture the way US firms have, cuts directly against a world where trust depends on transparency. As researchers everywhere — not just in the US and China but in India, Europe, and beyond — start finding the same flaws with the same tools, Chinese manufacturers who don't adapt to open disclosure risk losing market share regardless of what their government prefers. Eoyang's bottom line is that blanket import bans built on vague national-security fears will increasingly look like they're raising costs without actually buying anyone more security.
My take — AI-written commentary, not fact-checked reporting
Treating every Chinese-made router or EV as a security threat by default was always a blunt instrument dressed up as precision policy, and it's refreshing to see someone spell out why the premise is shakier than it looks. That said, nobody should pretend this solves the industrial-base problem — a country not wanting to depend on a rival for strategic manufacturing is a real strategic concern that has nothing to do with whether a chip has a backdoor. Swap national-origin bans for actual vulnerability testing, sure, but don't confuse that with a reason to stop building alternatives.
Read more about this at: ChinaTalk