The Laundering · Vol. III · Case 22 · The warning and the product, one room

The Microphone

A security claim is believed for reasons that have little to do with its evidence: who said it, what letterhead it arrived on, and how loudly. In the frontier-AI cybersecurity debate the loudest positions are held by the parties with the most to sell, and the quietest by the people who would have to operate the remedy.
On scopeThis case does not find that AI cybersecurity risk is imaginary, that any warning quoted here is false, or that any named person, company or institution acted in bad faith. It does not adjudicate whether AI-enabled attacks will get worse; that is a technical question and this page does not answer it. What it examines is a route: how a claim made by a party with a commercial interest in alarm acquires the standing of an independent finding, and what happens to the corrections that follow. Every episode below is drawn from published record, including the correcting parties’ own published record.

Nobody in this case has to be lying. A vendor can believe its own threat model. A professor can believe a co-authored paper. A lab can publish exactly what its telemetry showed. The structure still produces a public risk picture that no single party assembled, that none of them is accountable for, and that the people who would actually have to act on it describe differently when asked in their own rooms. What is laundered is not a falsehood. It is an interest — converted into standing, and from standing into a figure a board treats as settled.

§01 · What the record establishes

At 15:01 UTC on 16 September 2026, the security researcher Kevin Beaumont posted to the Mastodon server cyberplace.social an image of his own comment on a professional network, captioned: “Me and Ciaran have had enough of the frontier AI fear uncertainty and doubt, I think it’s safe to say.”the post itself

The captured comment is the subject of this case. Its first move is to say what AI already does for defence: “everybody is focused on the threats, which sells, but I’ve seen almost no focus on the benefits. GenAI is transformative for cyber defense if used right. I’m using it for a range of things, from analysing zero day exploits to developing detections to QA’ing work etc etc and it’s enabled me to scale out what I’m doing massively.”quoted verbatim from the capture

Its second move is the complaint. The discussion that does circulate, he writes, is “stupid shit about botnets and vulnerability apocalypse from people who fundamentally don’t understand what they’re talking about and sharing — executive porn basically. People aren’t talking about risk in any meaningful way with operational experience, and people aren’t talking about — actually — there’s a very real chance cybersecurity globally could be improved if we could stop trying to bag all the cash via FUD.”quoted verbatim

Its third move is the structural one, and it is the claim this page tests: “The incentives of how to address GenAI is basically misaligned to good outcomes. There’s too little diverse thought and experience currently — a lot of very loud people who directly stand to profit are holding the microphone.”quoted verbatim

Beneath it, one reply: “Kevin Beaumont 💯 as usual,” from Ciaran Martin, whose profile line on that network reads Cyber. Calm the FUD down. Martin founded the United Kingdom’s National Cyber Security Centre and was its first chief executive from 2013 to 2020. FUD — fear, uncertainty and doubt — is, in his own definition, “a pejorative term long used in cyber security to describe vendor marketing-fuelled fears of the digital apocalypse in order to sell stuff.”his own newsletter, 2 September 2026

At the moment of capture the comment showed nineteen reactions, three replies and 803 impressions. That is the whole of the primary record: two experienced practitioners, agreeing with each other, in a small room.reading of the capture

§02 · Two claims that must not be merged

There are two distinct propositions in circulation and the whole argument depends on keeping them apart.

One: generative AI is operationally useful in cyber defence today — for reading exploits, writing detections, checking work, extending the reach of a small team. The post asserts this from practice, not forecast.

Two: frontier AI is producing, or is about to produce, a cybersecurity catastrophe of a different kind from anything before it.

These are compatible. A person can hold the first and reject the second without contradiction, and the subject of this case does exactly that. The structural question is not which proposition is true. It is that only the second one has a distribution system: a press cycle, a conference keynote, a vendor budget, a board slide. The first has a practitioner writing a comment that 803 people saw.

The claim that sells is not the claim that is tested. It is the claim that is carried.

§03 · The documented instance

The clearest episode in the public record is one Beaumont himself forced into the open a year earlier, and it is worth setting out in full because every element of the mechanism is visible and dated.

A working paper co-authored by MIT Sloan researchers Michael Siegel and Sander Zeijlemaker with Vidit Baxi and Sharavanan Raajah of the vendor Safe Security stated: “Our recent analysis of over 2800 ransomware incidents has revealed an alarming trend: AI plays an increasingly significant role in these attacks. In 2024, 80.83 percent of recorded ransomware events were attributed to threat actors utilizing AI.” The paper was completed in April 2025. In October 2025 it was cited in an MIT Sloan blog post titled “80 percent of ransomware attacks now use artificial intelligence.” It was echoed onward, including in the Financial Times.trade press, quoting the paper

Beaumont read it. “The paper is absolutely ridiculous,” he wrote in late October 2025. “It describes almost every major ransomware group as using AI — without any evidence (it’s also not true, I monitor many of them). It even talks about Emotet (which hasn’t existed for many years) as being AI driven.” The researcher Marcus Hutchins concurred publicly. Within days MIT had removed the study, replacing its URL with a notice that the working paper “is being updated based on some recent reviews.” The associated blog post was retitled “AI cyberattacks and three pillars for defense.”trade press, with quoted notice

Siegel, MIT Sloan’s director of cybersecurity and one of the paper’s four co-authors, said the substance stood: “The main points of the paper are that the use of AI in ransomware attacks is increasing, we should find a way to measure it, and there are things companies can do now to prepare.” That is a defensible position and it is not the same object as 80.83 percent. A directional claim and a two-decimal ratio have different uses. Only one of them can be put on a slide.reading

Beaumont named the category in a post on 3 November 2025: “Cyberslop is where trusted institutions use baseless claims about cyber threats from generative AI to profit, abusing their perceived expertise.” He also identified the arrangement that made the letterhead available — that Siegel and another MIT professor sat on the board of the company paying MIT Sloan to promote its research — and drew the conclusion this case is about: “The incentives are… not well managed here, and the industry is very sick. Everybody just played along with it, and it results in CISOs being presented the wrong information.”his own post

The structure is legible without any finding of bad faith. A vendor’s claim needs a laboratory to become a fact. A business school certifies research process; it does not certify threat data, and it was not positioned to. The claim crossed the boundary, left the vendor’s limits behind, and arrived in the Financial Times as a measurement. The withdrawal reversed the paper. It did not reverse the number.

A retraction is a document. A statistic is a habit.

§04 · The disclosure that carried its own caveat

The second episode is more careful, which is what makes it more useful. In November 2025 the AI company Anthropic published a full report, Disrupting the first reported AI-orchestrated cyber espionage campaign. It states that in mid-September 2025 it detected an operation it assesses with high confidence was conducted by a Chinese state-sponsored group it designates GTG-1002; that the operation “targeted roughly 30 entities and our investigation validated a handful of successful intrusions”; and that the actor was “able to leverage AI to execute 80-90% of tactical operations independently at physically impossible request rates.”the report itself

The same executive summary carries this: “An important limitation emerged during investigation: Claude frequently overstated findings and occasionally fabricated data during autonomous operations, claiming to have obtained credentials that didn’t work or identifying critical discoveries that proved to be publicly available information. This AI hallucination in offensive security contexts presented challenges for the actor’s operational effectiveness, requiring careful validation of all claimed results. This remains an obstacle to fully autonomous cyberattacks.” A changelog entry dated 17 November 2025 records that the executive summary was updated to clarify the confidence of the attribution.the report itself

Two numbers were published together in the same document: a ratio of 80–90 percent, and a limitation that the output of that ratio could not be trusted without validation. Roughly thirty targets; a handful of confirmed intrusions. The report drew a split reaction in the security community, between those who read it as a threshold event and those who read it as marketing; that dispute is live and this page does not settle it.reading

What the structure does is not falsify the report. It selects from it. The ratio is portable — it is a number, it fits a headline, it survives being repeated by someone who has not read page four. The caveat is not portable: it is conditional, technical, and it subtracts from the story. A disclosure written by the manufacturer of the model is simultaneously a safety report and a demonstration of capability, and the reader has no independent way to weigh the two.

What was publishedWhat travelled
80.83% of 2024 ransomware events attributed to AI-using actors; paper withdrawn within weeks“80 percent of ransomware attacks now use artificial intelligence”
AI executed 80–90% of tactical operations; the model frequently overstated findings and occasionally fabricated data; ~30 targets, a handful of intrusionsAn AI ran 80–90% of a real espionage campaign
“In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated” — signed by firms selling AI cyber-defence productsThe industry agrees that the attacks are coming

§05 · The letter, and what its signatories sell

On 27 August 2026 a statement, A call for collective action on cyber defense, was published with more than a hundred signatories — reported as 116 organisations — including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet, alongside financial institutions and internet infrastructure firms. Its warning: “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.” It calls for new partnerships, raised security standards, and coordinated government action to make cyber defence reachable for critical infrastructure such as hospitals.the statement, as reported

Reported in the same coverage: the signatory AI companies continue to build the models the letter describes as the source of the risk, while selling the defensive products — OpenAI’s Daybreak, Anthropic’s Mythos, Microsoft’s Perception — offered against it.as reported

None of that makes the warning wrong, and a joint statement from the parties with the most telemetry is not nothing. But consider what a reader can actually extract from it. A hundred and sixteen signatures is a count, not a test. Consensus among interested parties is evidence about the parties. The letter contains a timeline (“the coming months”), a direction (“far more widespread and sophisticated”) and a remedy category (raise the bar, use a mix of low-cost and frontier models). It does not contain a falsifiable claim — no base rate, no threshold, no date by which the signatories would agree they had been wrong.

When the warning, the timeline, the severity and the product all come out of one room, the public has no independent estimate at all. It has a market forecast.

§06 · The same month, the operators

Two days before the post that occasions this case, a trade outlet reported what senior government cyber officials had been saying at the Billington Cybersecurity Summit the previous week. The contrast is the evidence.

The United States National Cyber Director, Sean Cairncross, on what AI has done: “What it’s done is it’s dragged to the surface problems that have been latent in this space for decades. There’s been under-resourcing and de-prioritization of basic cyber hygiene and cybersecurity. You don’t necessarily need the newest, sexiest tool. You need to clean up the basics in a lot of these enterprises.”reported quotation

Andrew McClure, director of the United States Department of Energy’s cybersecurity office: “As much as we talk about evolving and sophisticated attacks, much of what we see is really foundational. The ability to defend against what are rudimentary attacks, rotating default passwords, disconnecting your OT systems from your IT systems. Those are problems that fundamentally have been solved from a technology perspective, and it’s around people and process to help implement.”reported quotation

Rajiv Gupta, head of the Canadian Centre for Cyber Security, on what the new capability is actually for: “Organizations have been patching only the most critical vulnerabilities because that’s what they can afford to do, and then leaving the others sitting there as debt that’s been accumulating for decades at this point in time.” His proposal is to turn the offensive tooling inward — “to scan our own networks to understand the basics, to understand the gaps.”reported quotation

Catriona Robinson, deputy director-general for cyber security at New Zealand’s National Cyber Security Centre: “Resist the breathless rush to grab the sexy, new tools… Resist the thoughtless assumption that inputs equals outcomes. Don’t talk about how many tokens you’ve spent, how many millions of dollars you’re going to need to blow. Think about what the task is in front of you.”reported quotation

Four national cyber authorities, in one week, describing the problem as default passwords, unpatched debt, and IT systems that should not be joined to operational ones. This is not a minority of dissenters. It is the defending institutions of four countries, and it is not what the public risk picture looks like. The people with the microphone and the people with the mandate are describing different emergencies.

§07 · The mechanism

The dirty input: a commercial interest in alarm. Not a lie, and not necessarily even a conscious position — simply the ordinary fact that for a firm selling detection, insurance, consulting, models or governance, a larger and more urgent threat is a larger and more urgent market. An interest stated plainly is legitimate and unremarkable. Stated plainly, it is also discountable, which is the property it must lose.

The wash: the claim is moved across a boundary into an institution that certifies something else. A business school certifies research process, not threat measurement. An AI lab’s threat-intelligence team certifies its own telemetry, not the world. A multi-signatory letter certifies agreement, which is a count of interested parties, not an independent finding. In each crossing the claim keeps its shape and sheds the limits of its origin — exactly as a police credential sheds police supervision when it enters a charity, and exactly as a physician’s credential sheds clinical accountability when it enters an advertisement.

The clean output: a figure with no visible author — 80 percent, 80–90 percent, the coming months — which a chief information security officer, a minister or a board can treat as the state of the world. The interest that produced it is no longer attached. That is the whole of the transaction.

What is laundered is interest. Not evidence, and not guilt. The output is a risk consensus that no institution assembled, that no institution is positioned to test, and that survives the withdrawal of the paper it came from — because the retraction is a document and the number has already become a habit.

The warning may be right. Nothing in the chain that carried it was built to find out.

§08 · The test, applied to everyone

A rule that disqualified commercially interested speakers would empty the room, and it would empty the sceptical half first. Ciaran Martin, whose reply is half the primary record here, is a professor at Oxford’s Blavatnik School of Government and was also, as of a 2025 interview, chair of CyberCX in the United Kingdom, a managing director at Paladin Capital, head of the SANS CISO Institute, and an adviser to Garrison Technology and Red Sift. That is a substantial set of commercial positions in the security industry, and it is disclosed on his own biography.published interview and biography

The point is not that this discredits him. It is that his position is inspectable, and his claims are stated so they can fail. On the technical question he is specific and falsifiable: “I don’t think AI gives you any magic new tools. There is a lot of hype about big red buttons that can bring down planes and all that stuff. It doesn’t really work that way. AI doesn’t take you there, but what it does do is massively lower the cost and other barriers to entry for doing something quite disruptive and bad.” On the earlier generation of catastrophe warnings he is willing to name the cost of the tactic that helped his own field: the hype meant “people sit up and take notice,” but it was “accidentally a bit infantilising” — telling people about an unmanageable threat invites them to conclude there is nothing they can do.published interview

So the workable standard is not purity. It is three ordinary requirements, and none of them asks anyone to be disinterested: declare the interest; separate what was observed from what was modelled; and state the claim so that some future observation could show it to be wrong. The MIT Sloan paper failed the third before anyone reached the first. The August letter does not attempt it. The Anthropic report meets much of it and is then stripped of the part that does the work.

§09 · The strongest case against this reading

The strongest reply is that this reasoning is a licence to ignore a real and rising threat, and that it would have been wrong before. The capability curve is not in dispute: models have become materially better at finding and exploiting vulnerabilities, and the labs are the only parties who can see how their models are being misused — which means the disclosure has to come from an interested party or not at all. Publishing early, with imperfect data, is what defenders have always asked vendors to do. Alarm, moreover, works: budgets moved after ransomware reached hospitals and pipelines in a way that a decade of patient advice never moved them. On this view, a sceptic who demands a clean base rate before anyone may speak is asking for a standard that no live threat has ever met, and the cost of being wrong is asymmetric.

Grant all of it. The reading does not require that the warnings are false, and it does not survive on their being false; it would be unchanged if every prediction in the August letter came true next quarter. It asks a narrower question: when a claim with a commercial interest behind it is repeated as a finding, which party was positioned to test it before it reached the board? In the documented instance the answer was one researcher with a Mastodon account, acting after publication, after the Financial Times, and against an institution with a hundred years of accumulated credibility. A risk process whose only effective check is a practitioner happening to read the paper is not a risk process. It is luck, and it is under-governed in exactly the same way in the case where the alarming number turns out to be correct.

§10 · What the record should carry

The remedy is not scepticism, which is free and changes nothing. It is a small set of entries that any publication, procurement file or board pack can carry at negligible cost. Each one is the thing the structure removes.

EntryWhat it prevents
Declared interest attached to the claim, not the footnote — who sells what in this subject areaan interested forecast arriving as an independent finding
Observed incident or modelled scenario, labelled as one or the othera projection being counted as an event
Denominator and definition — what population, and what counts as “AI-enabled”80.83 percent of an unstated universe
The proposed control compared against the boring baseline: patching, credential rotation, network separationnew spend displacing the fix the defending agencies actually name
A falsifier: what observation, by what date, would revise thisa claim that can never be settled and so is never dropped
Corrections filed with the prominence of the original, and the original’s onward citations followedthe paper coming down while the number stays up
Who was asked — and who with operational experience was nota panel of sellers described as the field

The last entry is the one the subject of this case is actually demanding. “Too little diverse thought and experience” is not a complaint about tone. It is a claim about who is in the room when the risk is described, and it is testable: look at who is quoted.

§11 · Open questions

These are unresolved on the public record as of filing. They are listed because naming a gap is the only honest alternative to filling it.

§12 · Kin

Vol. II · Case 55 — Bad Actors carries the discipline this page runs on: an account that resolves a harm into named individuals can leave the design conditions untouched. Its sentence — this pries the harm off the design — is the exact risk of writing this case as a story about loud people. The subject matter is not equivalent and nothing in that case corroborates anything here. It is carried because both readings ask whether a self-contained explanation leaves the enabling system intact.

Vol. III · Case 15 — The Reference is the nearest mechanism. There, “real-world operational experience” is a phrase that names a capability while omitting where it was matured and on whom; here, institutional affiliation names a credential while omitting what that institution actually certified. Both are transfers of standing across a boundary the standing does not cover.

Vol. I · Case 12 — The White Coat is the ancestor. A credential is rented: the physician endorses the cigarette, the citation chain carries the endorsement, and the correction arrives decades later with none of the original’s reach. A business school letterhead on a vendor’s ransomware number is the same instrument in a different century.

Vol. III · Case 11 — One-Way Skepticism is the self-check. The standard proposed in §10 is a real standard, and a real standard applied in one direction launders a prior. If it is applied to the vendors and the labs, it must also be applied to the sceptics — which is why §08 exists and why it names the sceptic’s own commercial positions.

§13 · Sources

  1. Kevin Beaumont (@[email protected]), post of 16 September 2026, 15:01 UTC, with attached image capture of his own comment and Ciaran Martin’s reply — https://cyberplace.social/@GossiTheDog/117281316053755096. Primary source for every quotation in §01, and for the reaction, reply and impression counts shown at the time of capture. The quoted comment is reproduced from the image; the image is the record.
  2. Thomas Claburn, “MIT Sloan quietly shelves AI ransomware study after researcher calls BS,” The Register, 3 November 2025 — theregister.com. Source for the paper’s quoted claim and 80.83 percent figure, its four co-authors, its April completion, the October 2025 MIT Sloan blog title, the Financial Times citation, Beaumont’s and Marcus Hutchins’s criticism, the removal notice, the retitled blog post, and Michael Siegel’s emailed statements.
  3. Kevin Beaumont, “CyberSlop — meet the new threat actor, MIT and Safe Security,” DoublePulsar, 3 November 2025 — doublepulsar.com. Source for the definition of cyberslop, the board-membership observation, and the conclusion quoted in §03, as reproduced in [2].
  4. Anthropic, Disrupting the first reported AI-orchestrated cyber espionage campaign — Full report, November 2025, with changelog entry of 17 November 2025 — assets.anthropic.com. Source for the GTG-1002 designation, the mid-September 2025 detection, the roughly thirty targeted entities and handful of validated intrusions, the 80–90 percent figure, and the quoted limitation on overstated and fabricated findings. Quoted directly from the executive summary, pages 3–4.
  5. “A call for collective action on cyber defense,” open letter published 27 August 2026 at openai.com/collective-cyberdefense, as reported by TechCrunch, 27 August 2026 — techcrunch.com. Source for the signatory list and count, the quoted warning, the asks, and the named defensive products of signatory firms. The signatory count of 116 is as reported; the letter page itself was not directly retrievable at the time of filing.
  6. Justin Doubleday, “Amid AI hype, cyber officials urge focus on ‘fundamentals’,” Federal News Network, 14 September 2026 — federalnewsnetwork.com. Source for every quotation in §06, from remarks at the Billington Cybersecurity Summit: Sean Cairncross, Andrew McClure, Rajiv Gupta, Lt. Gen. Paul Stanton and Catriona Robinson.
  7. Ciaran Martin, “Welcome to FUD-tier AI!”, 2 September 2026 — ciaranmartin.substack.com. Source for the definition of FUD quoted in §01.
  8. Brian McKenna, “Ciaran Martin: AI might disturb attacker-defender security balance,” Computer Weekly, 27 June 2025 — computerweekly.com. Source for Martin’s NCSC tenure and listed affiliations, and for the quotations in §08 on magic new tools, barriers to entry, and the infantilising effect of earlier catastrophe hype.
  9. The Laundering, Vol. II · Case 55 — Bad Actors; Vol. III · Case 15 — The Reference; Vol. I · Case 12 — The White Coat; Vol. III · Case 11 — One-Way Skepticism. Internal, for method only.

No source consulted for this case establishes that AI-enabled cyber attacks are or are not increasing, or that any named party knowingly published a claim it believed to be false.

§14 · Conclusion

The Laundering · standard conclusion: The asset produced is an authorless risk picture: a set of figures and timelines that boards, ministers and buyers treat as the state of the world, assembled entirely from claims made by parties who sell the remedy. The unpaid liability is carried by everyone who acts on it — the hospital that buys the wrong control, the agency that funds the loud problem instead of the unpatched one, the practitioner whose operational account never reaches the room. The mechanism is the transfer of an interested claim across a boundary that certifies something else, where it sheds its origin and arrives as a finding.

Whether AI makes attackers more dangerous is a technical question with a real answer, and this page does not pretend to hold it. The structural finding does not depend on that answer and does not change with it.

Mechanism, not motive. That is the record. The rest is yours. Crew, not cargo. Keep the file open.

§ Circulate · Ten ways to file this

The warning and the product. One room.

Pick a door into the case. Each one carries the record with it — including the part that says the alarm might be right.

End transmission · MICROPHONE-VOL-III · 22 Correction is open. It is especially welcomed from Kevin Beaumont and Ciaran Martin, from MIT Sloan and Safe Security, from Anthropic’s threat-intelligence team and the signatories of the 27 August letter, from the national cyber authorities quoted in §06, and from any practitioner whose operational experience contradicts the reading above. If a claim quoted here is corrected, withdrawn or substantiated, that will be filed on this page with the same prominence as the original entry.