Skip to content
← DeepDive Governance & Geopolitics · 中文
DEEPDIVE / [SIGNAL] · AI Governance Watch · Five Cases DD · AI-GOVERNANCE-FAILURE · 2026-05-09 · v1
In one week, five seemingly unrelated events

When Rules Meet Capabilities
AI Governance's Five Failures

NSA's unauthorized use of Anthropic's restricted model, Atlassian quietly enabling data collection, Notion's four-year-unpatched email vulnerability, Claude Desktop silently registering browser permissions, Tesla concealing thousands of self-driving accidents—five cases, one pattern: every technological advance leaves a new crack in some regulatory blind spot. The problem isn't too few rules; it's that the speed of capability expansion leaves rules forever playing catch-up.

AI Buzzwords · DeepDive  |  2026-05-09  |  ~3,300 words · 10 min read
NSA · Mythos
Usage scale expanded
after supply chain blacklist
Atlassian
Data collection enabled
by default; opt-out hidden
Notion
Email vulnerability
unpatched for four years
Claude Desktop
Silently registers browser
permissions on install
Tesla
Thousands of accidents;
data solely controlled by vendor
TL;DR / 30 sec

Five events,
five failures

In one sentence: the problem isn't too few rules—the speed of capability expansion leaves rules forever playing catch-up.

#
Event
Failure Type
01
NSA's unauthorized use of Anthropic restricted model
Compliance boundaries set by model vendor, enforcement by government—dual-authorization desync
02
Atlassian quietly enables data collection
User right to know bypassed via "fair use" clauses
03
Notion email vulnerability unpatched for four years
Security disclosure throughput can't keep pace with vulnerability discovery
04
Claude Desktop silently registers browser permissions
"Install-time consent" ≠ "runtime actual permissions"—dynamic permission hot-loading
05
Tesla conceals thousands of self-driving accidents
Accident data solely controlled by vendor; regulators lack independent audit authority
Counter-consensus insight · Core thesis

It's not a shortage of rules, it's that rules can't keep up—regulation isn't a problem solved by "adding more clauses"; it's a structural speed gap: capabilities change daily, while statutes update only once a year.

§ 01 / NSA · MYTHOS

Technical demand overrides compliance limits:
The NSA vs. Mythos contradiction

Failure type · Dual-authorization desync

After the Pentagon placed Anthropic on a "supply chain risk" blacklist, all government agencies should theoretically have stopped using its products. But an Axios exclusive revealed: the NSA is widely using Anthropic Mythos Preview internally—and instead of scaling back, its usage is expanding.

This incident itself isn't surprising—government agencies bypassing procurement rules to use effective tools has plenty of historical precedent. What's truly worth noting is the underlying logic: when a tool's capabilities are powerful enough, internal demand automatically generates the motivation to bypass restrictions. Mythos can autonomously discover 27-year-old unfound security vulnerabilities in the Linux kernel; faced with such a tool, any security officer would find it hard to truly say "no."

This logic isn't limited to government. Every enterprise IT compliance team faces the same tension: the more capable the tool, the greater its compliance controversy tends to be. Copilot, Claude Code, Cursor—each has faced internal "prohibited use" policies, and each has survived through engineers' quiet, persistent use.

MIT Technology Review's piece on the illusion of "human-in-the-loop" in AI warfare raises a deeper question: when AI systems make decisions far faster than human approval processes, "human oversight" itself becomes a ceremonial existence. Compliance frameworks are designed assuming humans have enough time to intervene—but AI's speed has already invalidated that assumption.

The more capable the tool, the greater its compliance controversy tends to be—yet they all survive through quiet use.

Mechanism · Dual-authorization desync

Implication for enterprise executives: blanket bans are rarely truly effective—capability assessment and controlled pilots manage risk far better than hard blockades. You can't seal off employees' demand for a genuinely useful tool; you can only choose whether or not you see that usage.

§ 02 / Data Sovereignty

The systemic erosion of data sovereignty:
From Atlassian to Notion

Failure type · Right to know bypassed · Disclosure can't keep up with discovery

In the same week, two entirely different data privacy incidents pointed to the same larger problem.

Atlassian quietly enabled data collection in Jira and Confluence to train its AI models, with the opt-out deliberately hidden. This isn't the first time—Zoom, Slack, and LinkedIn have all followed similar paths. "Default consent" has become standard operating procedure for SaaS platforms, because every case where users genuinely pushed back proved one thing: most users will take no action at all.

Meanwhile, Notion's public page vulnerability—allowing anyone to obtain editors' full names and emails without authentication—was reported in 2022 and remains unpatched four years later. This isn't technical incompetence; it's more likely a priority judgment: fixing this vulnerability incurs costs, while most affected users neither know nor care.

Taken together, these two events reveal the core dilemma facing enterprise data sovereignty: you cannot control what you do not understand. Enterprises store their most sensitive internal information—product roadmaps, customer data, engineering documents—in SaaS tools, yet most haven't even carefully read these tools' data usage terms.

The urgency of AI training data needs will only worsen this problem. SaaS platforms now have stronger incentives than ever to expand their data rights, because the competitiveness of their internal AI products depends on it directly. Users have fewer and fewer choices—either accept, or migrate to a competitor (who most likely has the same terms).

Notion's email vulnerability remaining unpatched for four years stands in stark contrast to tools like Mythos that can discover thousands of new vulnerabilities within minutes—the throughput of disclosure and remediation processes is becoming a harder bottleneck than vulnerability discovery capability itself.

§ 03 / Boundary Expansion

Silently expanding boundaries:
Claude Desktop and Vercel

Failure type · Install-time consent ≠ runtime permissions

Claude Desktop silently registers a browser Native Messaging host on installation, granting itself permissions to read browser state and manipulate the DOM—this is to enable browser integration features, but there is no explicit user notification throughout the process. In the same week, Vercel confirmed a security incident, where the attack was launched through a weak link in a third-party AI OAuth integration, affecting some customer data.

These two events point to a new risk surface in AI platform expansion: AI tools are acquiring permissions faster than enterprise security teams can understand and audit them.

Claude Desktop's situation is particularly typical. Anthropic's intentions are benign—browser integration allows Claude to serve users better. But the combination of "benign intent + unnotified permission expansion" is precisely the problem by privacy tool community standards. More importantly, when enterprise IT departments deploy Claude Desktop, chances are no one checked what it does to the Chromium browser on every employee's computer.

Vercel's incident represents another category of risk: the high-value target nature of AI development platforms. Developers store not just code on AI development platforms, but also API keys, database connections, and production data samples used for AI testing. Any third-party OAuth integration with lax security auditing becomes a weak entry point for the entire platform.

"Install-time consent" can't protect you—runtime behavior can silently change without your knowledge.

Mechanism · Dynamic permission hot-loading

§ 04 / Commercial Fracture

Three fractures in commercial value:
CEOs, Uber, Figma

Failure type · The chasm between capability demonstration and commercial value

The fractures discussed above are all at the security and governance level, but this week another set of data pointed to questions about AI's commercial value itself.

A survey of 6,000 executives showed nearly 90% believe AI has had no substantial impact on productivity over three years, with executives using AI only 1.5 hours per week; Uber's $3.4 billion AI partnership saw its Eats division's AI copy unanimously rated as having "no practical effect"; the launch of Claude Design put Figma in an absurd position: paying API costs that fuel a competitor's capabilities, while that competitor's marginal cost is nearly zero.

These three cases appear independent, but together they point to one issue: there is a chasm between AI's technical demonstrations and its commercial value that has yet to be systematically crossed. Mythos can find 27-year-old undiscovered security vulnerabilities; Claude Design can let non-designers "explore a dozen design directions in minutes"—these are genuine technical achievements. Yet most business leaders cannot perceive this capability in their daily work, for three reasons:

First, there are integration costs between capability and workflow. No matter how powerful AI is, without appropriate use-case packaging and process embedding, executives won't see it.

Second, multi-tool fatigue obscures the value of any single tool. When employees are simultaneously required to use five AI tools, each one seems "not very useful."

Third, the measurability of commercial ROI is itself an engineering problem. Most organizations haven't built the data infrastructure to measure AI's contribution at all.

Governance failure discusses "capabilities expanding too fast for rules to keep up"; this section addresses the flip side of the coin—most organizations haven't even learned how to use the capabilities they already possess. Together, these show that the speed of AI diffusion and the speed of AI understanding are moving along entirely different curves.

§ 05 / Conclusion

From five failures
to one recommendation

Looking back at all of this: the NSA's unauthorized use of Mythos, Atlassian silently enabling data collection, Notion's vulnerability unpatched for four years, Claude Desktop silently registering browser permissions, Tesla concealing self-driving accidents—behind each event, there are no bad actors, but rather rule-makers and rule-enforcers collectively losing their rhythm amid a rapidly advancing technological wave.

Behind these five cases are three counter-consensus insights worth repeating—more important than any single news item:

#
Counter-consensus
Implication
01
It's not a shortage of rules, it's that rules can't keep up
Regulation isn't solved by "adding more clauses"—it's a structural speed gap
02
The concept of "consent" has already failed
Install-time consent terms vs. runtime hot-loaded permissions create a dynamic gap; Atlassian / Claude Desktop both exploit this gap
03
Disclosure speed can't keep up with discovery speed
Mythos finds far more vulnerabilities than have been patched; Notion's email vulnerability unpatched for four years—manual verification disclosure processes are the new bottleneck

What does this mean for three different groups of people?

Enterprise Compliance Teams

Add "AI tool runtime permissions" to your audit cycle—install-time consent terms cannot protect you; feature gate hot-loading means runtime behavior can silently change. Start with three things: ① List all SaaS tools in use, confirm each tool's AI training data terms, and disable unneeded data sharing options; ② Confirm what system permissions all AI tools acquire after installation, and whether they match official documentation; ③ For currently used AI tools, establish even the roughest before/after measurement framework.

Policymakers

Regulatory frameworks need to shift from "rule matching" to "capability monitoring". Capabilities changing every second cannot be managed by statutes updated annually; rather than waiting for a perfect regulatory framework (which will always be catching up), prioritize establishing continuous visibility mechanisms.

Regular Users

The "I agree" you click has already failed. What truly determines your data boundaries is the software's actual runtime behavior, not the legal document at installation—this means you must continue to monitor what it's actually doing after installing it.

The five failures of AI governance are not about "insufficient rules," but about the design assumptions of rules—that capabilities change slowly, disclosure cycles are long, and consent is valid forever—all of which are now obsolete. This isn't purely a regulatory issue, but a generational shift in governance paradigms: the nations or companies that can build "dynamic compliance" frameworks will become the de facto standard-setters for next-generation AI governance. Governance doesn't have to wait for perfect institutions; it can start with visibility within organizations.

Revision history

First published 2026-07-15

Companion material