Four stories this week point at the same fracture: every lever anyone thought they had on AI — military, technical, geopolitical, commercial — turned out to be looser than advertised.

Start with the one still bleeding. Nine days into the export-control ban that took Claude Fable 5 and Mythos 5 offline worldwide, the official explanation keeps getting worse. Senate Intelligence Committee vice-chair Mark Warner told reporters that General Joshua Rudd — who runs both the NSA and Cyber Command — informed him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours.” That’s a sharper claim than the “fix this code” jailbreak story that circulated last week, and it reframes the ban as less about a researcher’s prompt trick and more about a government watching its own model breach its own defenses faster than its own people could respond. None of that has restored access: the refund window for usage credits closed Friday, Anthropic’s international chief still says only “coming days,” and prediction markets put the odds of restoration before July 1 at 57%.

Cybersecurity’s other lesson this week came from the opposite direction — not a model too dangerous to leave on, but an agent framework too trusting to leave unpatched. Microsoft disclosed AutoJack, a three-step exploit chain against pre-release builds of its own AutoGen Studio: a malicious webpage’s JavaScript reaches a local service that wrongly trusts anything running on the same machine, skips authentication on its control socket, then runs whatever command shows up in a request parameter. Get an agent to open one planted link — a prompt injection will do — and it hands over the host, no login screen involved. The vulnerable code never shipped in a stable release, but the lesson generalizes badly: every capability an agent gets — browse, click, execute — is a capability any webpage it visits inherits too.

China’s answer to this whole climate of uncertainty is to stop relying on anyone else’s hardware or anyone else’s restraint. Beijing is drafting a $295 billion, five-year plan to wire together a national grid of AI data centers run by China Mobile and China Telecom, with at least 80% of the chips inside sourced domestically — Huawei filling in for the Nvidia and AMD silicon Washington won’t reliably sell it. It’s the same instinct behind the export-control directive, pointed the other way: if a government three time zones away can switch off your model overnight, the rational move is to never again need that government’s permission for anything.

Even without a government involved, dominance is proving short-lived. Sensor Tower’s State of AI 2026 report found ChatGPT’s share of AI-assistant usage fell to 46.4% in May — below half for the first time since the category existed — as Gemini climbed to 27.7% and Claude to 10.3%. ChatGPT still leads by raw numbers, 1.1 billion monthly users to Gemini’s 662 million, but “majority” was the one claim OpenAI didn’t need a competitor’s help to lose.

Different mechanisms, same shape. The capability keeps compounding — Mythos got good enough to alarm its own government, agents got useful enough that a single webpage can weaponize one, China is rich enough to route around an entire supply chain, and three different chatbots are now good enough to split a market that one company used to own outright. None of that growth came with a matching grip on where it ends up. Nobody — not a government, not a lab, not a vendor with a thousand-day head start — controls this as tightly as the headlines from three months ago implied.