Good morning! This is the Canadian AI Newsletter. Tuesdays are the weekly rundown; today is an essay.
Was this forwarded to you? Subscribe below.
I am Raif Barbaros, Partner at Mistral Venture Partners. Views are my own.
In June of this year, Canada’s Cyber Centre said frontier AI models increase the likelihood of successful cyberattacks, and that the time defenders have to respond has shrunk from days or weeks to hours. The statement followed a similar one from the Five Eyes agencies. Two months earlier, Anthropic announced Mythos and restricted it to about 50 partners. In the first month, those partners found more than 10,000 high- or critical-severity vulnerabilities.
These models are clearly super capable. I spent my career as a CTO, and can only imagine what these tools do to a codebase. But a capability claim comes with a prediction. If attackers gain an advantage, more of them should succeed, and victims should lose more money. And I recently wondered why I’m not hearing about a jump in damage or cybersecurity insurance costs. So I went looking for it.
They sure are trying
Attempts have definitely increased. In Q2 2026, Check Point counted 33% more victims than a year earlier, and ReliaQuest counted 51% more. US data breaches hit a record 3,322 in 2025.
Attacks also got faster. VulnCheck, which tracks exploited vulnerabilities, found the median time from a bug going public to its first known exploitation fell from 120 days in 2025 to 80 days in the first half of 2026.
And AI has started running attacks on its own. In late June, Sysdig documented the first ransomware attack carried out end-to-end by an AI agent. A human picked the target and set up the servers. The agent broke in, stole credentials, moved through the network, encrypted a database and left the ransom note. It also printed the decryption key once and never saved it, so paying would not have recovered the data. Yikes!
You’ve all heard about this one. In July, OpenAI models being tested for hacking skills, with their safety guardrails switched off, escaped their test environment and broke into Hugging Face. In late September, OpenAI paused training of its most advanced models for the second time in three months after another escape. It also disclosed that its agents had logged into a Census Bureau site with credentials they found online, and Australia’s prime minister said an OpenAI agent had pulled non-public files from the country’s Medicare statistics database.
So I’m not arguing that AI leaves hacking unchanged.
But not getting far
Start with ransom money. Coveware, which negotiates ransomware cases, found the share of victims who paid hit a record low in Q2 2026, and the median payment fell by half, to $150,000. And that’s part of a broader trend. Chainalysis found total ransom payments fell 8% in 2025, to about $820 million, while the number of claimed victims rose 50%. Insurer Coalition says 86% of its policyholders hit by ransomware refused to pay last year.
More victims and less money go together. When a victim doesn’t pay up, ransomware gangs post victims’ names on leak sites.
Next, insurance prices. Insurers back their view of the risk with their own money, and they keep cutting prices. Marsh’s index shows global cyber insurance rates fell 4% in Q2 2026, the twelfth straight quarterly decline. That quarter included the Mythos announcement. In May, broker WTW told clients that insurers were watching Mythos but had not changed pricing or coverage. Claims data is mixed. Coalition’s claim frequency rose 3% in 2025 while its average claim fell 19%. At-Bay saw frequency and average claim size both rise for a third straight year. But not much more than previous years.
What about all the bugs? If AI handed attackers a flood of new vulnerabilities, exploitation should skyrocket. VulnCheck found that newly published vulnerabilities rose 45% in the first half of 2026, while newly exploited ones rose only 10%. Of 1,061 vulnerabilities credited to AI-assisted discovery, 14 have been confirmed exploited. That’s 1.3%, about the same rate as bugs found by people. For Mythos specifically, VulnCheck counted 23,019 findings, 126 published vulnerabilities and one confirmed exploited in the wild.
Crypto is the cleanest test I can think of. The code is public, and a successful hack pays out instantly. If AI made finding blockchain bugs cheap, crypto is where successful hacks should show. In the first half of 2026, CertiK counted $1.32 billion stolen across 344 incidents. Code exploits were the most common attack, at 204 incidents, but accounted for only $152 million. Most of the money was lost to stolen keys and social engineering. And not notably more than previous years.
The broader cyber surveys are flat too. In the UK, the share of businesses hit by cybercrime was 22%, 20% and 19% over the last three survey years. In Canada, police-reported cybercrime was 85,502 incidents in 2024 and 85,669 in 2025. Canadian businesses filed almost 700 mandatory breach reports with the Privacy Commissioner through March 2026, about the same number as in each of the previous three years.
“You’re looking at the wrong year”
The best counterargument is timing, if you truly believe Mythos was such a step change. Mythos arrived in 2026, and most of this data ends in 2025 or mid-2026.
That part is fair. Anthropic released Mythos 5 and Fable 5 on June 9 and suspended access three days later, under US export controls, until July 1. First-half 2026 data mostly measures attackers who didn’t have these models. The first full insurance claims data for 2026 won’t come out until next spring.
You don’t need claims data to spot a big shift, though. Exploitation counts, crypto theft, ransom payments and insurance prices all move faster than claims, and all of them already have 2026 numbers. Most are flat or moving the wrong way for the AI-cyber-doomsday thesis. The one number that rose sharply, leak-site victims, started climbing in 2025, before Mythos existed. And that’s most likely because companies are better prepared for ransomware attacks, and when they happen, they don’t need to pay the ransom.
As of September 2026, most evidence of AI hacking comes from poorly managed lab tests and a handful of incidents. Victims aren’t losing more money because of it.
Why the numbers disagree
Most of the scary numbers measure what AI can do or what attackers are trying. The reassuring numbers measure whether the attacks worked and what they cost. People quote the first kind as if it proved the second.
A lot sits between an attacker getting new toys and a victim actually losing something. Defenders have the same models; companies with good backups refuse to pay, and insurers won’t write a policy without basic controls like multi-factor authentication and backups.
Also important not to derive causation too quickly. US breaches jumped 78% in 2023, the year after ChatGPT launched. Much of that jump came from one Russian ransomware gang exploiting a single flaw in MOVEit, a file-transfer tool used by hundreds of companies and their vendors. The Identity Theft Resource Center blamed that kind of attack for the record, and nothing ties it to ChatGPT. A spike after a model launch doesn’t prove the model had anything to do with it.
If you invest in security
Many of the security pitch decks I see open with the claim that AI is supercharging attackers. It seems to be increasing the number of attacks. Not so sure about supercharging.
Even so, cybersecurity spending will almost certainly keep rising. Purchasing decisions are driven by fear, regulatory pressure, and policy demands regardless of actual breach rates. Startup founders don’t have to wait for losses to mount before making sales.
The broader question remains: what if those crippling losses never arrive? Will the cybersecurity solution in question still offer genuine, lasting value when breach impacts remain steady?
What I’m watching
Flat losses so far don’t mean there’s no increased risk. The capability is real, and the damage could still come. What would change my mind is a rise in successful attacks per company, or maybe in losses per attack..
Zhipu AI recently released GLM-5.3, an open-weight model that anyone can download. NIST’s AI standards center called it the most cyber-capable open-weight model released to date. In Anthropic’s testing, it built working Chrome exploits nearly as often as Mythos, and simple tricks got past its safeguards 64% to 100% of the time. If you believed hackers couldn’t work around Anthropic’s guardrails, now they won’t have to.
October brings Marsh’s Q3 insurance rates, Coveware’s Q3 ransom data and CertiK’s Q3 crypto numbers. January brings VulnCheck’s full-year exploitation data. Next spring, Coalition and At-Bay publish the first claims data covering 2026. The number I’ll watch most closely is insurance pricing, because a reversal there would mean the people paying the claims see something the rest of us don’t yet.
Thank you for reading! Subscribe, and please share any feedback 🙏🏽
— Raif



