Skip to content

Runtime: Why AI can't defeat every security challenge

+ MCP's push to improve messaging, why HiddenLayer is One To Watch, and AWS's Bahrain region is down and out.

Runtime: Why AI can't defeat every security challenge
Photo by Bozhin Karaivanov / Unsplash

Welcome to Runtime! Today: Despite Anthropic's attempts, cryptography is still too hard for AI models to defeat, how Uber got over tokenmaxxing, and more.

Please forward this email to a friend or colleague! If it was forwarded to you, sign up here to get Runtime for free every week, or level up here.


First up: Crypto keeper

In the wake of a fitful summer during which advanced AI models appeared to take on supernatural cybersecurity powers, it's no surprise that worries about the staying power of cryptographic algorithms — even the post-quantum ones — would crop up. After all, given enough time and tokens, is anything designed before the advent of LLMs really safe?

But cryptography experts think those concerns are overblown, despite Anthropic's announcement in July that its Mythos model "weakened" the HAWK cryptography algorithm, leading the team behind that project to pull it from NIST's project to vet post-quantum standards. "The notion that AI will break all cryptography or that we would need some kind of post-AI cryptography is a take that doesn't make sense to me," HAWK researcher Léo Ducas told The Stack.

AI is having a moment, but is it a danger to cryptography?
After Mythos “broke” an algorithm submitted to NIST, how are AI agents impacting the world of cryptography?

The weakness that Mythos identified in the HAWK algorithm was real, but could be dealt with by doubling the size of the cryptographic keys used to protect the system, and given that the NIST challenge was focused on efficiency the researchers decided to pull it from consideration, Ducas said. However, that's a far cry from Mythos being able to defeat those protections altogether.

Still, advanced AI models could find ways to work around cryptographic algorithms by exploiting weaknesses in how they are deployed, according to Puneet Bakshi, a researcher at the Centre for Development of Advanced Computing in India. "AI can definitely help us in finding the loophole, which is different from attacking the fundamental basic mathematical hard problems," he said, meaning that security teams in the post-quantum world (assuming that ever arrives) will still have plenty to worry about even if AI models can't defeat their encryption protocols.


The rest of The Stack

Get the message: MCP has developed into an essential building block for enterprise AI, and is probably as responsible as any model breakthrough in paving the way for agentic AI. At the first MCPCon in Europe Thursday, Anthropic's David Soria Parra — one of the co-creators of the protocol — told attendees that the next goal for the project is to improve the way end users communicate with agents through MCP.

MCP team focused on “agentic messaging” says co-creator
The protocol’s first MCPCon in Europe since joining the Linux Foundation provided an overview of its future.

MCP Uber alles: MCP is also a crucial part of Uber's AI strategy, and after launching and ending the brief "tokenmaxxing" era the company has now figured out how to run MCP servers at scale without breaking the budget. "Weekly active users of its AI coding tools rose 7x and weekly agent requests climbed 9.4x between February and August 2026 while Uber kept total spend roughly flat since April," Ed Targett reported.

1,000 MCP servers, no schema bloat? Uber attacks AI costs
Tool access architecture is a sweet cost lever, even before you think about model choices…

Layer cake: When companies start building a whole new class of applications, as we're seeing during the current rush to deploy AI agents, unforeseen security issues tend to proliferate. In this week's One To Watch, Noah Bovenizer talked to HiddenLayer co-founder and CEO Chris ‘Tito’ Sestito, whose company is working on updating endpoint security principles for the AI era.

One To Watch - HiddenLayer
HiddenLayer CEO Chris ‘Tito’ Sestito talks AI cybersecurity, agentic intent, and handling government data.

Benioff bashes Brussels: Hawaii land baron and Salesforce CEO Marc Benioff had a strong message for European AI companies and researchers Tuesday at Dreamforce: you're falling behind. He also talked about the headless software movement and debated AI policy with Sam Altman and Dario Amodei, as our report from San Francisco lays out.

Benioff: Europe is slipping behind China and US in AI
Salesforce’s CEO also talked up the headless software movement and the need for AI regulation with Jensen Huang and Dario Amodei.

Lost and gone forever: In what appears to be a first in the twenty years of cloud infrastructure computing, AWS said this week that it does not expect it will be able to recover some customer data from its Bahrain region, which has been offline since March following Iranian drone attacks. "The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand," AWS said, although it intends to return to the region next year.

AWS: Cloud instances in Bahrain, UAE might be lost for good
Several availability zones in the two regions have been down since March, when they were attacked by Iranian drones.

Stacking up: The week ahead

Turing Fest kicks off Tuesday in Edinburgh, bringing together UK startups and investors as well as those who might be in the market for adding startups to their larger companies.

The National Cyber Summit runs Tuesday through Thursday in Huntsville, Ala., featuring current and former government officials alongside industry security professionals with a lot to talk about in the AI era.

Oktane hits Las Vegas Tuesday through Thursday, a showcase for Okta's identity-management services, which have taken on new challenges with the rise of AI agents.

UiPath Fusion will be crosstown in the desert during the same days, with updates on the transition from RPA to agentic AI.

Quantum World Congress starts Wednesday in College Park, Md., with presentations from industry and government leaders about the road to quantum computing.


We're also reading:

Why Software Factories Fail: HumanLayer CEO Dex Horthy on AI coding agents, loop engineering, and the challenges and opportunities presented by this shift in software development strategies.

Agents: The new, New Kingmakers: Redmonk's Stephen O'Grady has an update (of sorts) to his seminal book on developer experience now that AI agents play an increasing role in software development.

Intel CEO Warns Against 95% Reliance on One Taiwan Chipmaker: Just too funny, coming from a company that had more than 90% of the server chip market for a decade.


Thanks for reading — see you Saturday!

Add The Stack on Google