NSA's unauthorized use of Anthropic's restricted model, Atlassian quietly enabling data collection, Notion's four-year-unpatched email vulnerability, Claude Desktop silently registering browser permissions, Tesla concealing thousands of self-driving accidents—five cases, one pattern: every technological advance leaves a new crack in some regulatory blind spot. The problem isn't too few rules; it's that the speed of capability expansion leaves rules forever playing catch-up.
In one sentence: the problem isn't too few rules—the speed of capability expansion leaves rules forever playing catch-up.
It's not a shortage of rules, it's that rules can't keep up—regulation isn't a problem solved by "adding more clauses"; it's a structural speed gap: capabilities change daily, while statutes update only once a year.
After the Pentagon placed Anthropic on a "supply chain risk" blacklist, all government agencies should theoretically have stopped using its products. But an Axios exclusive revealed: the NSA is widely using Anthropic Mythos Preview internally—and instead of scaling back, its usage is expanding.
This incident itself isn't surprising—government agencies bypassing procurement rules to use effective tools has plenty of historical precedent. What's truly worth noting is the underlying logic: when a tool's capabilities are powerful enough, internal demand automatically generates the motivation to bypass restrictions. Mythos can autonomously discover 27-year-old unfound security vulnerabilities in the Linux kernel; faced with such a tool, any security officer would find it hard to truly say "no."
This logic isn't limited to government. Every enterprise IT compliance team faces the same tension: the more capable the tool, the greater its compliance controversy tends to be. Copilot, Claude Code, Cursor—each has faced internal "prohibited use" policies, and each has survived through engineers' quiet, persistent use.
MIT Technology Review's piece on the illusion of "human-in-the-loop" in AI warfare raises a deeper question: when AI systems make decisions far faster than human approval processes, "human oversight" itself becomes a ceremonial existence. Compliance frameworks are designed assuming humans have enough time to intervene—but AI's speed has already invalidated that assumption.
The more capable the tool, the greater its compliance controversy tends to be—yet they all survive through quiet use.
Mechanism · Dual-authorization desync
Implication for enterprise executives: blanket bans are rarely truly effective—capability assessment and controlled pilots manage risk far better than hard blockades. You can't seal off employees' demand for a genuinely useful tool; you can only choose whether or not you see that usage.
In the same week, two entirely different data privacy incidents pointed to the same larger problem.
Atlassian quietly enabled data collection in Jira and Confluence to train its AI models, with the opt-out deliberately hidden. This isn't the first time—Zoom, Slack, and LinkedIn have all followed similar paths. "Default consent" has become standard operating procedure for SaaS platforms, because every case where users genuinely pushed back proved one thing: most users will take no action at all.
Meanwhile, Notion's public page vulnerability—allowing anyone to obtain editors' full names and emails without authentication—was reported in 2022 and remains unpatched four years later. This isn't technical incompetence; it's more likely a priority judgment: fixing this vulnerability incurs costs, while most affected users neither know nor care.
Taken together, these two events reveal the core dilemma facing enterprise data sovereignty: you cannot control what you do not understand. Enterprises store their most sensitive internal information—product roadmaps, customer data, engineering documents—in SaaS tools, yet most haven't even carefully read these tools' data usage terms.
The urgency of AI training data needs will only worsen this problem. SaaS platforms now have stronger incentives than ever to expand their data rights, because the competitiveness of their internal AI products depends on it directly. Users have fewer and fewer choices—either accept, or migrate to a competitor (who most likely has the same terms).
Notion's email vulnerability remaining unpatched for four years stands in stark contrast to tools like Mythos that can discover thousands of new vulnerabilities within minutes—the throughput of disclosure and remediation processes is becoming a harder bottleneck than vulnerability discovery capability itself.
Claude Desktop silently registers a browser Native Messaging host on installation, granting itself permissions to read browser state and manipulate the DOM—this is to enable browser integration features, but there is no explicit user notification throughout the process. In the same week, Vercel confirmed a security incident, where the attack was launched through a weak link in a third-party AI OAuth integration, affecting some customer data.
These two events point to a new risk surface in AI platform expansion: AI tools are acquiring permissions faster than enterprise security teams can understand and audit them.
Claude Desktop's situation is particularly typical. Anthropic's intentions are benign—browser integration allows Claude to serve users better. But the combination of "benign intent + unnotified permission expansion" is precisely the problem by privacy tool community standards. More importantly, when enterprise IT departments deploy Claude Desktop, chances are no one checked what it does to the Chromium browser on every employee's computer.
Vercel's incident represents another category of risk: the high-value target nature of AI development platforms. Developers store not just code on AI development platforms, but also API keys, database connections, and production data samples used for AI testing. Any third-party OAuth integration with lax security auditing becomes a weak entry point for the entire platform.
"Install-time consent" can't protect you—runtime behavior can silently change without your knowledge.
Mechanism · Dynamic permission hot-loading
The fractures discussed above are all at the security and governance level, but this week another set of data pointed to questions about AI's commercial value itself.
A survey of 6,000 executives showed nearly 90% believe AI has had no substantial impact on productivity over three years, with executives using AI only 1.5 hours per week; Uber's $3.4 billion AI partnership saw its Eats division's AI copy unanimously rated as having "no practical effect"; the launch of Claude Design put Figma in an absurd position: paying API costs that fuel a competitor's capabilities, while that competitor's marginal cost is nearly zero.
These three cases appear independent, but together they point to one issue: there is a chasm between AI's technical demonstrations and its commercial value that has yet to be systematically crossed. Mythos can find 27-year-old undiscovered security vulnerabilities; Claude Design can let non-designers "explore a dozen design directions in minutes"—these are genuine technical achievements. Yet most business leaders cannot perceive this capability in their daily work, for three reasons:
First, there are integration costs between capability and workflow. No matter how powerful AI is, without appropriate use-case packaging and process embedding, executives won't see it.
Second, multi-tool fatigue obscures the value of any single tool. When employees are simultaneously required to use five AI tools, each one seems "not very useful."
Third, the measurability of commercial ROI is itself an engineering problem. Most organizations haven't built the data infrastructure to measure AI's contribution at all.
Governance failure discusses "capabilities expanding too fast for rules to keep up"; this section addresses the flip side of the coin—most organizations haven't even learned how to use the capabilities they already possess. Together, these show that the speed of AI diffusion and the speed of AI understanding are moving along entirely different curves.
Looking back at all of this: the NSA's unauthorized use of Mythos, Atlassian silently enabling data collection, Notion's vulnerability unpatched for four years, Claude Desktop silently registering browser permissions, Tesla concealing self-driving accidents—behind each event, there are no bad actors, but rather rule-makers and rule-enforcers collectively losing their rhythm amid a rapidly advancing technological wave.
Behind these five cases are three counter-consensus insights worth repeating—more important than any single news item:
What does this mean for three different groups of people?
Add "AI tool runtime permissions" to your audit cycle—install-time consent terms cannot protect you; feature gate hot-loading means runtime behavior can silently change. Start with three things: ① List all SaaS tools in use, confirm each tool's AI training data terms, and disable unneeded data sharing options; ② Confirm what system permissions all AI tools acquire after installation, and whether they match official documentation; ③ For currently used AI tools, establish even the roughest before/after measurement framework.
Regulatory frameworks need to shift from "rule matching" to "capability monitoring". Capabilities changing every second cannot be managed by statutes updated annually; rather than waiting for a perfect regulatory framework (which will always be catching up), prioritize establishing continuous visibility mechanisms.
The "I agree" you click has already failed. What truly determines your data boundaries is the software's actual runtime behavior, not the legal document at installation—this means you must continue to monitor what it's actually doing after installing it.
The five failures of AI governance are not about "insufficient rules," but about the design assumptions of rules—that capabilities change slowly, disclosure cycles are long, and consent is valid forever—all of which are now obsolete. This isn't purely a regulatory issue, but a generational shift in governance paradigms: the nations or companies that can build "dynamic compliance" frameworks will become the de facto standard-setters for next-generation AI governance. Governance doesn't have to wait for perfect institutions; it can start with visibility within organizations.
First published 2026-07-15