Specialisation was the gift of the pre-AI era. Each function held a sliver of judgement; coordination was the product. The cost of this gift was less visible: a long tail of small, stale decisions accreting into technical debt, security debt, and process debt across every layer of the stack.
Vulnerabilities introduced in 2017 sat untouched for years because no one owned the cross-cutting view. The team was larger than any one mind could hold.
AI is doing on the offensive side what defenders never prioritised: walking every line of every kernel, every protocol, every quietly-rotting binary, looking for shape.
Sources · Tom's Hardware coverage of Copy Fail and the Dirty Frag embargo break, May 2026. Mythos-class capability refers to the new generation of frontier models being marketed for vulnerability discovery; numbers reflect reported manual validation behind public claims.
The technical debt of the last decade is now the threat surface of this one.
The target state is not "AI replaces the team." It is one human owning the responsibility surface that ten used to share. The director writes the brief, sets the bar, and reviews the outputs. The agents do the work — in parallel, in seconds, on tap.
What changes for the human is not less work, but different work: editorial judgement, taste, accountability, and the willingness to ship a decision rather than negotiate one across nine inboxes.
Equip every team with the tools, the partners and the budget to fold their workflow into agents. Set a clear bar: each function must demonstrate AI-native competence on the work they already own. Empower first, measure second.
Double — sometimes triple — the headcount, the budget, the seniority, the floor space. Give them authority to command the same agents the rest of the org runs, and to direct first response across the entire product portfolio: a zero-day, an integration, a model rollout, a vendor swap. Strategic, not service. Central, not adjacent.
The bar for "native" is not cosmetic. It is the ability to assess every surface, know every corner, and react the moment something moves. Anything that can't is replaced. Anything that can be transformed is transformed first.
The director-of-one isn't alone — they sit under an umbrella of many directors, each running their own loop. Inside each loop, signals flow in, agents do the work, and a single human reviews, approves, and is accountable at every checkpoint.
Four human gates remain: what is the real pain, what's worth doing next, is this safe to merge, and is this safe to ship. Everything between them is agentic. Cybersecurity audit runs on every change, not on quarterly cadence.
Same eight stages. Same four human gates. Different domain. Customer service, finance close, legal review, marketing, recruitment — every back-office and front-line function reduces to the same loop. This is now just a software transformation story.
Each function is run by a director who is themselves a team of one — under an executive layer that sets strategy, allocates capital, and arbitrates between loops. The organisation is flatter, but it is still an organisation.
What disappears is the middle: the coordinator, the project manager-of-managers, the role whose value was knowing what the other nine were doing.
Mythos-class capability cannot belong to a few. The same model that walks back through the kernel commit history and finds a 2017-era root is the model that, given to defenders, finds it first. The asymmetry of access is the whole argument. Whoever has Mythos last, loses.
Frontier capability stays inside well-funded attackers, three labs, and one government per region. Everyone else is the testing ground.
Defenders run the same Mythos-class capability against their own stack, before the disclosure window opens. The 2017 commits are found by the people who have to live with them.
The position of this note: Mythos-class access should be infrastructure, not edge. The net benefit is a future safeguarded from human-made vulnerabilities of the past. The net cost of withholding it is paid, in full, by everyone except the holder.