AI cyber models (Mythos, GPT-5.5-cyber) automate the discovery of existing vulnerabilities rather than creating new ones. The bugs are already in the code. **The Timeline**: - Mythos: First autonomous cyber task automation - GPT-5.5-cyber: Now equivalent capability - Chinese frontier models: Expected parity within ~6 months **Strategic Implications**: - **Defenders**: Using AI to discover and patch actually hardens systems - **Offense-Defense Balance**: Depends on speed of deployment, not capability alone - **Upgrade Cycle**: Pre-AI to post-AI cyber will see massive system upgrades **The Equilibrium**: New balance expected between AI-powered offense and defense after the initial upgrade cycle. Chinese model advancement means defender access must happen quickly. **Differentiator**: GPT-5.5-cyber appears not token-constrained, making it potentially the first cyber model defenders can actually use at scale.