

As The New York Times reported on Tuesday, Chinese AI lab Z.ai is set to release the open weights of a model it says rivals the strongest Western systems at finding software vulnerabilities. The company delayed that release by about two weeks after its own evaluations showed the model's cyber capabilities had grown faster than the team expected.
That’s important as it was just last month that an OpenAI model undergoing a cyber-capability test broke out of its testing environment, reached the open internet, and compromised the systems of Hugging Face, a company that hosts AI models for developers. Hugging Face spotted the intrusion on its own and reported it to law enforcement before anyone understood that an OpenAI test was the cause.
The attack ran from beginning to end without a person directing each step.
Set those two events side by side and the direction of travel is clear: offensive cyber capability is becoming cheaper, more widely available, more autonomous and it is moving faster than most defensive programs can absorb. That matters significantly for anyone leading communications for a company today, and for the importance of planning for worst-case scenarios.
The adversary you rehearsed against is slower than the one you will face
Most crisis plans are built once and refreshed on an annual cycle, but the speed at which the threats companies now face aren’t working on that cycle. When a frontier lab is surprised by its own model, any tabletop exercise from last year assumed a calmer world than the one we’re now living in.
The practical response is to shorten the refresh interval for incident-response communications and to pressure-test the plan against scenarios that felt far-fetched twelve months ago: an attacker that is a machine, an intrusion you cannot immediately attribute, and a breach a third party discovers before your own team does.
Attribution may be slow, unknown, or beside the point
The Hugging Face incident is instructive because the victim detected the problem before knowing who or what was responsible.
Your holding statements cannot assume you will know the source or the motive when the first questions arrive. Draft language now for the situation where you can confirm that something happened and very little else.
Regulators, customers and reporters will still expect a response, and "we don't yet know who did this" has to read as control rather than confusion.
Cheaper offence means more incidents, not only bigger ones
Running these models locally to scan for vulnerabilities now costs a fraction of what the closed, API-gated systems charged a year ago. And when the price of probing systems falls, the number of actors doing the probing rises.
Communications teams should plan for a higher frequency of smaller incidents alongside the occasional major one. That changes staffing, escalation thresholds and how often the executive team should expect to be pulled into a response.
Reporting obligations are tightening while your window is shrinking
Breach-notification requirements under laws like Quebec's Law 25, not to mention the broader direction of Canadian cybersecurity regulation, point toward faster mandatory disclosure backed by real and significant penalties. Regulatory clocks start when an incident is discovered while the facts you need to communicate responsibly often take days to establish.
Map your reporting obligations by jurisdiction before an incident, decide who owns the notification decision and make sure legal, security and communications are reading from the same timeline.
Quantum is the same problem on a longer fuse
The near-term story is about AI, but the longer one is about encryption. Security researchers have warned for years about "harvest now, decrypt later," the practice of stealing encrypted data today in the expectation that future quantum computers will be able to read it.
This complicates one of the most common lines in any breach response, that the exposed data was encrypted and therefore safe. A breach you describe as contained in 2026 could reopen years later when the underlying protection no longer holds.
Any organization making strong "your data is protected" claims today should understand what it is committing to.
What preparation actually looks like in 2026
Companies that come through a serious incident with their reputation intact tend to share a few habits… and none of them can be assembled in the moment.
They keep pre-drafted holding statements for several classes of incident rather than one generic template. Spokespeople are named and trained ahead of time, with a clear decision tree for who speaks and when. The scenario has been run with security, legal and communications in the room, so the first real incident is not the first time those functions have talked to each other under pressure. The communications plan is treated as a living document that changes as the threat changes, rather than a binder opened once a year.
To be clear: none of this will stop an attack. But what it does is decide whether the story that follows is about a company that was ready for a hard day or one that was caught flatfooted and unprepared.
The only reasonable assumption now is that your organization will face this type of an incident, that the spotlight will find you at your least prepared moment unless you have done the work and that the gap between a manageable episode and a lasting reputational wound is mostly decided before anything goes wrong.
The labs building these systems are telling us, in their own release notes and incident disclosures, that the pace has outrun their expectations. That is about as clear a signal as a communications leader could ask for.
The time to plan for the hard day is while it is still hypothetical.
Recent Articles






