Available for day contractsFrom 21st September I have availability for day and half day contracts. Please contact for more information.

Contact →
mikepreston.org

The Assumption Nobody Wrote Down

A grand mid-century trading hall where a human clerk reaches for tall doors that snap shut faster than he can move, while a small swift brass automaton darts through the last closing gap — 1960s gouache.

On Polymarket, you can watch arbitrage die in real time. The average window for exploitable price discrepancies on short-duration crypto contracts shrank from 12.3 seconds in 2024 to 2.7 seconds in early 2026 — measurable, on-chain, public.[1] A bot turns $313 into $414,000 in a single month not by predicting anything, but by exploiting the gap between how fast Bitcoin moves on Binance and how slowly Polymarket's contracts reprice. The gap closes. Then it closes faster. Then a developer claims to have rebuilt the entire strategy in Rust, with Claude, in forty minutes.

That's the mechanism. The rest of this piece is about where else it's operating, invisibly, because most industries don't happen to publish their pricing lags in public.

Nate Jones's recent piece on AI and arbitrage[1:1] covers the economic taxonomy well — speed gaps, reasoning gaps, fragmentation gaps, discipline gaps — and is worth your time if you haven't read it. I want to take the argument somewhere he doesn't go, because I think the security implications of that same mechanism run considerably deeper than the framing suggests. Deeper, and considerably less comfortable.


The Gap That Was Always There

Arbitrage, stripped back, is just the exploitation of an inefficiency — a gap between what something costs to produce and what the market will bear. The instinct is to read this as predatory, but that misses the structural point. Most business models, most career paths, and most institutional arrangements exist because of a gap, not despite one. The law firm that bills ten hours for two hours of thinking and eight hours of document retrieval isn't running a scam; it's running a business model built on the historical cost of legal research. The offshore development team exists because a San Francisco engineer costs four times a Bangalore engineer and the productivity differential doesn't come close to closing that gap. These aren't bugs in the market. They're the water it swims in.

What's changing isn't that arbitrage exists — it always has, back to Ea-Nasir and his famously substandard copper — but the rate at which gaps close. Previous technologies compressed arbitrage windows on timescales of decades: it took a generation for railroads to flatten the regional price differentials that had sustained entire merchant classes. AI is doing it on the timescale of model releases. Months, sometimes weeks. And the particular property that makes this genuinely different from previous automation waves is that every time one gap closes, several new ones open, and the new ones open at a higher level of abstraction than the old ones occupied.

The institutions, business models, and careers built on the old gaps are not necessarily doomed — but they are operating on borrowed time, and the loan terms are considerably shorter than most people are pricing.


The Assumption Nobody Wrote Down

Here is the thing that almost nobody has made explicit, probably because it never needed to be: every system designed after approximately 1970 contains an implicit assumption that humans are the most capable reasoning agents operating on it.

It was never written in a design document. It didn't need to be — it was just physics. You design fraud detection around human investigator throughput because there is no other kind of throughput available. You design compliance regimes around human auditor capacity. You design legal process around human reading speed and the natural friction imposed by the cost of adversarial complexity — the fact that mounting a sophisticated multi-jurisdiction legal challenge requires expensive humans doing expensive things for a long time, which limits who can do it and how often. You design oversight mechanisms with the assumption that the entities being overseen are also human-speed, operating under human cognitive constraints.

That assumption is dissolving. Not eroding gradually — dissolving. The interesting consequence isn't that AI makes existing processes faster. It's that an enormous number of systems were relying on human cognitive limitations as a de facto rate limiter, and nobody catalogued which ones because the assumption was invisible. You don't document load-bearing walls until someone starts knocking things down.

The argument you'll hear is that this just pushes value upstream — toward judgment, taste, relationships, the things that are harder to systematise. That's largely true, and it's not wrong as career advice. But it skips a step. Judgment depends on reliable signal. In a world where the noise floor is rising — where synthetic content, AI-generated code contributions, deepfake communications, and automated disinformation are all operating at machine scale — exercising good judgment becomes harder, not just more valuable. The asset appreciates; so does the cost of deploying it correctly. These are not the same problem, and conflating them leads to dangerously optimistic conclusions about how smoothly the transition goes.


Horrifically, Not Holistically

On 7 April 2026, Anthropic announced Project Glasswing[2] — a coalition of twelve major technology and finance companies given access to a preview of Claude Mythos, an unreleased frontier model, for the explicit purpose of finding and patching vulnerabilities in critical software infrastructure before the model becomes more widely available. The coalition includes Amazon, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. A further forty organisations building or maintaining critical software have access to the preview. Anthropic is committing $100 million in usage credits and $4 million in direct donations to open-source security organisations.

The model has, in initial testing, identified thousands of previously unknown high-severity vulnerabilities across every major operating system and web browser. Many of them are a decade or more old.

The standard read on this is "AI finds vulnerabilities faster." That reading is wrong, and the error matters.

Traditional vulnerability tooling is local. A scanner looks for known bad patterns; it's essentially a very fast grep with a large signature database. Sophisticated fuzzing explores a search space, but with heuristics that are fundamentally bounded — one component, one interface, one protocol boundary at a time. Human security researchers chain vulnerabilities together, but they're working against the combinatorial explosion manually, guided by intuition and constrained by working memory and time. The genuinely catastrophic exploits — the ones that make headlines and end careers — almost always involve chains of three, four, five individually unexploitable weaknesses that compose into something that shouldn't be possible. Human red teams find these by luck, reputation, and pattern-matching built over years. They don't find them systematically, because the search space for a five-hop chain across a realistic software stack is not a space that human systematic exploration has ever been able to cover.

The closer analogy to what Mythos appears to be doing isn't a faster scanner. It's closer to what numerical control did for PCB fabrication. Before NC routing and automated optical inspection, PCB complexity was bounded by what a human could reliably trace and inspect — the tooling didn't make existing boards faster to produce, it unlocked board designs that were literally impossible to manufacture reliably by hand. Multi-layer, fine-pitch, BGA packages. The complexity ceiling moved. A model that can hold a full dependency graph in context and reason about multi-hop vulnerability chains across trust boundaries isn't operating faster in the same search space. It's operating in a search space that wasn't previously reachable.

Someone in a conversation about this suggested "AI can reason about attack surface horrifically, not holistically." That's the right word. I'd have used it myself.

The libcurl framing illustrates why. It's not that libcurl had a ten-year-old vulnerability — it's that every system that inherited the trust assumption about libcurl was exposed, and every system that trusted those systems, and so on through the dependency graph. The vulnerability isn't in a library; it's in an assumption that propagated silently through the software ecosystem for a decade. Mythos can trace those propagation chains. The question of what an adversary with equivalent capability would do with that ability is not a comfortable one.


Trust Propagation Is the Foundational Problem

Pull the camera back from the security-specific framing, and the pattern generalises.

Every complex system is built on assumptions about the trustworthiness of the components beneath it. Those assumptions were priced when the threat model was "humans with limited time and working memory attempting to subvert a system defended by other humans with limited time and working memory." That's the regime every audit framework, every compliance standard, every institutional oversight mechanism was designed for. The friction that made forgery expensive, impersonation detectable, and large-scale manipulation slow enough to catch — that friction is going to zero.

This is where quantum computing intersects, and the intersection is more immediate than most people's mental model accounts for. The standard framing — Shor's algorithm breaks RSA and ECC once sufficiently large quantum computers exist — is accurate but it's the slow version of the threat. The more immediate problem is the combination of three things arriving on overlapping timescales: quantum computing becoming available as a cloud service, lowering the barrier from nation-state to well-funded actor; AI-assisted cryptanalysis surfacing implementation weaknesses in theoretically sound primitives — side channels, weak RNG, protocol composition errors, key management failures; and Mythos-class capability traversing dependency graphs to identify every place a vulnerable cryptographic primitive is load-bearing across a stack.

The harvest-now-decrypt-later posture has been operational for years. Nation-state actors have been collecting encrypted traffic with the explicit intention of decrypting it when the key becomes available. That data exists. It's sitting in storage somewhere, waiting. Perfect Forward Secrecy was the right architectural response to this threat — compromise of the long-term key doesn't retroactively expose sessions that used ephemeral keys — but PFS was never universally deployed. TLS 1.2 with RSA key exchange, legacy VPN configurations, enterprise kit that was certified in 2015 and never touched since: a significant fraction of the historical traffic that's been harvested was encrypted without it.

The forward-looking problem is that PFS alone isn't sufficient anyway. The ephemeral keys need to be post-quantum resistant, otherwise you have perfect forward secrecy against classical attackers and none at all against a quantum-equipped one. NIST finalised the first post-quantum cryptography standards in 2024 — CRYSTALS-Kyber for key encapsulation, CRYSTALS-Dilithium for signatures[3] — so the primitives exist. Deploying them across production infrastructure is a different question entirely, and the answer to that question is mostly "procurement cycles and legacy replacement schedules," which is to say: slowly.

The cipher is usually the strongest link. The surrounding infrastructure almost never is.


The Export Control Delusion

The obvious policy response to "AI capability is dangerous" is to attempt to control who can develop it, which in practice means attempting to control access to the compute required to train frontier models. The US export restrictions on high-end GPUs to China are the primary expression of this approach, and they're based on a nuclear enrichment analogy: control the enrichment infrastructure, control the bomb.

The analogy fails in several specific ways that matter.

Fissile material is atoms. It has mass, detectable signatures, and requires specialised handling infrastructure at every point in the supply chain. The control regime is hard to implement but the thing being controlled is at least tractable — you're looking for physical objects moving through inspectable channels. High-end GPUs are mathematics instantiated in silicon, shipped in boxes that are indistinguishable from legitimate commercial hardware, through freight networks with thousands of nodes. The Supermicro case[4] — executives using shell companies and proxy buyers to route Nvidia cards to China — isn't a sophisticated operation. It's standard import fraud. The margins on grey-market chips are large enough to fund serious evasion infrastructure, and the enforcement surface is vast enough that perfect interdiction is not a realistic goal.

The deeper problem is that compute is one input into a multi-input process where the other inputs flow freely. Architecture knowledge comes out of research papers. Training methodology is increasingly public. Model weights leak. The research community is international and the literature doesn't check export compliance before citations propagate. Even granting that chip restrictions work perfectly — and they demonstrably don't — you've only interdicted one factor in a production function with several others you're not controlling.

The unintended consequence worth noting: Deepseek.[5] Export restrictions may have accelerated the development of training approaches that achieve comparable results with substantially less compute. Efficiency under constraint is a well-understood phenomenon in engineering; applying artificial resource scarcity to a problem and then being surprised when the constrained party gets better at doing more with less is a pattern with a long history. The policy was trying to maintain a capability gap. It may have closed one while opening another.

Buying some time is better than buying none, and I'm not arguing for abandoning export controls entirely — the alternative of doing nothing is worse. But "months bought" and "years required" are not the same number, and the gap between them is where the real exposure lives.


Concentration, and What PCB Fabrication Actually Teaches Us

The CNC lathe analogy for AI's impact on labour — which Nate's piece uses well — works up to a point and breaks in an important place. The point where it breaks is the distribution question, and the PCB fabrication story is more instructive on this than the lathe.

Before NC routing and automated optical inspection, PCB manufacturing was genuinely distributed. Single and double-layer boards could be produced in small shops with modest capital investment; the barrier to entry was low enough that the industry was broad. NC fab changed the complexity ceiling — as I argued above in the context of Mythos — but it also changed the industry structure, and the two effects weren't separable. The capital cost of the equipment was high. The expertise to run it reliably was scarce and took time to develop. And crucially, the work that the new tooling unlocked — multi-layer, fine-pitch, BGA — was qualitatively different from what small shops had been doing, which meant it didn't compete with them directly. It made their existing capabilities look like a different, lower tier of the market. Small shops either capitalised the upgrade, found a niche in low-complexity commodity boards, or closed. The high-value work concentrated around players who could afford the equipment and develop the operational depth to run it. That concentration wasn't incidental to the technology — it was structural to how the capability gains were distributed.

Intelligence arbitrage has more extreme returns to scale than either the CNC lathe or the production line, because the thing being scaled is capability rather than physical production. A better model trained on more data with more compute produces better output, attracts more users, generates more revenue, funds more compute, and widens the capability gap — a feedback loop with no obvious natural bound. The Polymarket data makes the distributional consequence concrete: 94–95% of wallets lose money[1:2], consistently feeding the small fraction of participants who've built systems that can actually navigate the environment. Democratised access to the tools does not democratise the outcomes. It never did.

The institutional layer sits underneath all of this, and it's the slowest-moving piece, which makes it the critical constraint. Regulatory frameworks operate on timescales of years to decades. The capability curve is operating on timescales of months. The gap between those timescales produces increasing systemic stress — not from malice, but from categorical mismatch. Things happen for which existing frameworks have no vocabulary, no precedent, and no assigned regulator. The response, as ever, lags the problem.


Project Glasswing is Anthropic explicitly acknowledging the asymmetry: give blue teams a structured head-start before the capability proliferates, because once it does, the window where "only defenders have this" is a controlled policy decision rather than a technical impossibility — and that window will not be long. The Glasswing coalition has weeks, perhaps a few months, to harden infrastructure against an attack surface that a Mythos-class model can traverse in ways no previous tooling could.

The organisations not in that coalition now know exactly what they're not doing. What they do about it is, as ever, a procurement decision.



  1. Nate Jones, "$313 Became $438,000 in 30 Days," Nate's Newsletter — the arbitrage taxonomy this piece builds on, and the source for the Polymarket bot story, the 12.3-to-2.7-second arbitrage-window compression figures, and the 94–95% wallet-loss figure. https://natesnewsletter.substack.com/p/313-became-438000-in-30-days-youre (video: https://www.youtube.com/watch?v=BiqG3it0gY0). ↩︎ ↩︎ ↩︎

  2. Anthropic, "Project Glasswing" — the coalition giving partners early access to a Claude Mythos preview to find and patch vulnerabilities in critical software before the capability proliferates. https://www.anthropic.com/project/glasswing (see also the initial update: https://www.anthropic.com/research/glasswing-initial-update). ↩︎

  3. NIST finalised the first post-quantum cryptography standards on 14 August 2024 — FIPS 203 (ML-KEM, derived from CRYSTALS-Kyber) for key encapsulation and FIPS 204 (ML-DSA, from CRYSTALS-Dilithium) for signatures. https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards ↩︎

  4. CNBC reported that Super Micro employees were charged with smuggling Nvidia AI chips to China via shell companies, fake servers, and forged paperwork, in violation of the Export Control Reform Act. https://www.cnbc.com/2026/03/19/us-tech-execs-smuggled-nvidia-chips-to-china-prosecutors-say.html ↩︎

  5. The argument that US hardware export controls acted as a selection pressure pushing DeepSeek toward algorithmic efficiency (multi-head latent attention, mixture-of-experts routing, FP8 training), reaching comparable results with far less compute. RAND, "The Rise of DeepSeek: What the Headlines Miss." https://www.rand.org/pubs/commentary/2025/01/the-rise-of-deepseek-what-the-headlines-miss.html ↩︎