Proposed
Mandatory vulnerability-sharing with national CERTs before launch
If the model can find it, defenders see it first.
No compiled flow or public database names this control yet.
Who should own it
Labs and national CERTs
Governments
How quickly it can land
Weeks
A dedicated squad can land it inside two months.
Expedited implementation
3 weeks
21 calendar days with a crash team
Normal implementation
3 months
90 calendar days as a planned program
Risk this mitigates
19Given that at least one lab has rated an upcoming model ‘critical’ for cyber under its own preparedness framework, there is a possibility of a generally available or stolen model that can find and exploit novel vulnerabilities at scale resulting in wide compromise of software supply chains, hospitals, utilities, and public agencies.
Residual composite 19 · still above the threshold
Effect if implemented
Applied to every failure scenario on that risk, then re-ranked. Axes are clamped at 1.
- Likelihood
- −0
- Consequence
- −1
- Urgency
- −0