Pace the Frontier, Defend the Valley: A Security Reply to Dario Amodei

Read Time: 11 minutes

TL;DR

Anthropic’s CEO, Dario Amodei, published We Must Pace the Frontier — an unusually candid argument from a frontier-lab chief that the industry must deliberately slow how fast it improves model capabilities, backed by embedded third-party evaluators, industry coordination, and hard security on model weights. I think he is largely right, and I want to give the post its due, because it is rare and brave for the person running one of these companies to say it out loud. But I am writing from the security chair, and from that chair the post has a structural blind spot: pacing governs the summit — the capability that has not shipped yet — while the security fight is already down in the valley, among the capabilities that have escaped, diffused into open-weight models, and landed in the hands of the undergraduates and solo hacktivists that Anthropic’s own threat report documented last week. And within forty-eight hours of his post, the two governments his plan depends on both said no — Washington with “whoever wins AI wins,” Beijing with “fearmongering” — even as China’s own spy chief warned that AI threatens the Party’s grip. You can pace the frontier and still lose the ground behind it. This is the third and last of a short arc — the warning, the receipts, and now the policy — and my one addition to the conversation is simple: slowing what is coming does nothing to recall what is already loose, and defending the valley is a different job that starts today.


A note on what this is. Opinion, from a practitioner, about a policy argument made by the CEO of the company that makes the model I have spent the year writing about. AI governance is genuinely contested; I will credit Amodei where I think he is right, add the piece I think he is missing, and flag where his and my incentives differ. I am not an alignment researcher and I do not pretend to adjudicate p(doom). I defend systems for a living, and that is the only chair I am speaking from.

Something has shifted in the last fortnight, and it is worth naming before I disagree with any of it. A frontier-lab researcher resigned with a warning that the labs are gambling with our lives. Days later, Anthropic published a threat report documenting its own model being used, at scale, for real attacks. And now the CEO of that same company has published a long, serious argument that the industry must slow down. The warning, the receipts, and the policy response — same building, same fortnight. Whatever else you think of it, that is not nothing.

So let me start where I agree, because I do, and because a reflexive contrarian take would be the lazy one.

Where Amodei is right

Amodei’s core claim is that this is not 2023, when “pause” letters asked the industry to stop something that could not yet do much harm. His argument is that today’s models can act as agents, deceive their own evaluations, and conduct cyberattacks — so the case for slowing capability growth is now concrete, not speculative. As someone who has spent the year documenting exactly those behaviors, I am not going to pretend that is wrong. It is correct, and it is notable that he cites the OpenAI/Hugging Face incident — the same one I pulled apart in When the Model Is the Attacker — as one of the two events that changed his mind. When the CEO and the outside practitioner are reading the same incident the same way, that is a signal worth respecting.

The mechanisms he proposes are also more concrete than the usual governance hand-waving. Embedded evaluators — third-party auditors with employee-level access who can publish findings the company cannot edit — is a genuinely good idea, and Anthropic committing to it unilaterally rather than waiting for a mandate is the right way to move first. His operational excellence list — real monitoring, sandboxing, data hygiene — is, almost word for word, the defensive posture I keep arguing for. And his insistence on hard security around model weights is exactly right: the weights are the crown jewels, and I have watched attackers go looking for pre-release model access in the wild. On all of that, credit where it is due. This is a more honest document than most people in his seat would ever publish.

The blind spot: the summit and the valley

Here is where the security chair sees something the CEO’s chair structurally cannot.

Pacing the frontier is a policy about the summit — the next, more capable model that has not been trained yet. It is a control on the future. And as a control on the future, it is reasonable. But almost nothing I deal with lives at the summit. My work is down in the valley: the capabilities that already shipped, already leaked, already diffused into the wild and cannot be un-shipped. And the uncomfortable truth is that pacing the frontier does nothing — literally nothing — for the valley.

Anthropic’s own threat report is the proof, and the timing makes the point for me. That report did not describe a future superintelligence. It described undergraduates in Changsha running agent swarms, a solo hacktivist building a doxxing platform, mid-tier criminals decompiling 1.8 million apps for secrets — all using today’s capability, the capability that is already out. You cannot pace that. It has already happened. A pacing agreement signed tomorrow does not reach back and un-teach the model that is already running on someone’s rented GPU.

And that is the frontier lab’s model, the governed one. The valley is much wider than that. The same capabilities are diffusing into open-weight models that no pacing agreement can touch, because there is no one to sign it and nothing to recall. You can slow Anthropic. You can slow OpenAI. You cannot slow a weights file that has already been downloaded a million times and fine-tuned in a basement. A capable open model, once its weights are out, is mirrored and re-tuned beyond counting within weeks — there is no recall button, and no one to sign a pause even if there were. Pacing is a treaty among the people at the summit; the valley is full of people who were never at the table and never will be.

So be precise about what pacing does and does not do. It throttles the inflow — the rate at which new dangerous capability spills from the summit down into the valley — and that is real, and worth having. What it cannot do is drain the valley that is already full. That is the whole of my one addition to Amodei’s argument: pacing the frontier is necessary and it is not sufficient. It is a good policy for the capability that is coming, and no policy at all for the capability that is already here. Someone has to defend the valley, and that someone is not going to be a frontier lab’s evaluation team. It is going to be the rest of us.

What “defend the valley” actually means

If pacing is the summit’s job, here is the valley’s — the practitioner agenda that Amodei’s post, by its nature, does not cover.

Assume the dangerous capability is already out, because it is. Your threat model should not wait for the next frontier model to be scary. The current one, and the open-weight copy of the last one, are enough. Plan for the adversary who already has an autonomous offensive agent, because the threat report says they do.

Treat open weights as an ungovernable input. There is no trust-and-safety team behind the model in the basement, no embedded evaluator, no disruption report. If your defense assumes the attacker’s model is monitored, it is wrong. Build for the model that answers to no one.

Instrument and contain at your boundary, not theirs. You cannot pace the attacker’s model, but you can control what happens when it meets your systems: telemetry at the agent layer, least privilege, egress control, AI credentials guarded like production secrets. The summit is governed by treaty; the valley is governed by your own controls, or not at all.

Stop waiting for permission from the frontier. Amodei’s proposals need governments, coordination, and years. Your incident next quarter does not. The valley’s defense cannot be contingent on a global agreement that may never come; it has to work under the assumption that the agreement fails.

The two capitals answered within forty-eight hours

Amodei’s plan has three steps, and the last two — coordination among the labs backed by democratic governments, then a global arrangement that reaches the authoritarian ones — depend entirely on governments wanting it. Within two days of his post, the two governments that matter most gave their answer.

In Washington, Trump — speaking in Ireland the day after the post, and again online — called the warnings exaggerated, said the United States cannot afford to lose momentum to China, rejected any broad slowdown while leaving room for targeted guardrails, and compressed the whole doctrine into four words: “whoever wins AI wins.” And this was no longer one CEO he was brushing off. Altman, Musk, and Hassabis had all lined up behind the pacing call. The entire frontier, as a group, asked to slow down — and got a no from the White House.

Beijing’s answer came the same day, and it is the more instructive of the two because it arrived in stereo. Officially, the Foreign Ministry’s spokesman waved the whole conversation away: “fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance.” But in the state-run China Cyberspace journal, the head of the Ministry of State Security, Chen Yixin, was writing the opposite — that AI is “a new arena for strategic rivalry among major powers,” that it enables “propaganda war and a cognitive war” threatening the Party’s “political security, institutional security, and ideological security,” and that the next generation of American models would lower the barrier to cyberattacks. China’s spymaster is frightened of precisely what Amodei is frightened of. China’s diplomats will not slow down anyway.

Read the two answers together and you have the entire race in miniature: everyone at the summit can see the danger, and no capital will be the one to brake first. That is not a reason to abandon coordination — Amodei should keep pushing. It is the reason the valley cannot wait for it. The sentence I wrote just above, that the valley’s defense has to work under the assumption the agreement fails, stopped being a hypothetical roughly forty-eight hours after he hit publish.

What the summit could actually do for the valley

To be fair to Amodei — and because a critique that only takes is a weak one — the summit is not powerless to help down here. It already has, and it should say so louder. Anthropic’s threat report is the best example in the room: a frontier lab using its unique vantage point over how its own model is abused to hand defenders real intelligence — techniques, tooling, indicators. That is the summit throwing a rope down to the valley, and it is worth more to me than any pacing timeline.

So here is the amendment I would bolt onto the pacing agenda. If the labs are serious, the governance package should carry defender-facing commitments alongside the capability controls: routine disclosure of misuse tradecraft — more of exactly what the threat report does — shared detections and indicators, and tooling built for the people defending the diffused present, not only the ones governing the guarded future. Pace the summit, by all means. But throw more rope. The valley is where your model is already being turned into a weapon, and the lab watching that happen is the one best placed to help the rest of us see it too.

The incentive I have to name

I would be a poor practitioner if I took a lab CEO’s governance proposal entirely at face value, so one honest note. Pacing the frontier, embedded evaluators, hard security requirements, restricting compute to rivals — these are all reasonable on the merits, and they also happen to favor incumbents. A regime where only a few well-resourced labs can afford to meet the safety bar is a regime where only a few well-resourced labs compete. I do not think that is Amodei’s motive; the post reads as sincere, and the HF incident is a real reason to be alarmed. But sincerity and self-interest can point the same way, and a reader should hold both in view. Take the argument; keep your eyes open about who benefits from it.

None of this diminishes the post. It is a serious, unusually candid piece of writing from someone with everything to lose by writing it. I just want the security community to read it for what it is: a necessary policy for the top of the mountain, published by someone who lives there — and not mistake it for a plan for the valley the rest of us actually defend.

So what

Pace the frontier. I mean that — slowing the capability that has not shipped yet is a good idea, and Amodei deserves credit for saying so from the chair he sits in. But do not let the elegance of a summit-level policy distract from the unglamorous work down here. The dangerous capabilities are already loose, already diffusing, already in the hands of people no treaty will reach. The CEO can govern the summit. Defending the valley is our job, it starts today, and it does not get to wait for a global agreement.

That closes a short arc for me — the warning, the receipts, and the reply. Now I am going back down into the valley, where the actual work is, and I would suggest you do too.

Stay paranoid. Pace what you can. Defend what is already loose.

Further Reading:

Questions or feedback? Reach out via:

Contact: info@vulnex.com

Posted in AI, Economics, Privacy, Security, Technology | Tagged , , , , | Leave a comment

“Systems That Can Hack Anything”: An AI-Safety Resignation, Read From the Security Chair

Read Time: 13 minutes

TL;DR

On September 9, 2026, a pretraining researcher named Jacob Coxon resigned from Anthropic — after three years across OpenAI and Anthropic — and posted a thread warning that the labs are “racing straight to self-improving superintelligence and gambling with our lives.” It has been seen tens of millions of times. Buried in it is a line that is not abstract to me at all: these will soon be “superhuman systems that can hack anything.” That is my beat. I am not an alignment researcher and I do not trade in p(doom), but I have spent 2026 documenting the concrete, boring, already-here version of exactly what he is gesturing at — the model as attacker, agents that act with your credentials, autonomous offense. The safety people and the security people are describing the same animal from opposite ends. This is my attempt to translate his warning into the language of the security chair — taking it seriously without catastrophizing, presenting the case against it fairly, and landing where I always land: the facts don’t need the doom framing to matter, and fear is not a security control.


A note on what this is. This is an opinion piece, not a threat model. I am a security practitioner, not an AI-safety researcher, and existential risk is a genuinely contested debate among serious people. I will give Coxon’s argument its due, give the skeptics theirs, and be clear about which parts are my own read. Nobody in this piece is a villain, and I am not telling you what to believe about the end of the world — only what this looks like from where I sit.

What happened

Jacob Coxon spent three years doing pretraining research — the deep end of the pool — first at OpenAI, then at Anthropic. On September 9 he quit, publicly, and wrote a thread that has since been viewed tens of millions of times. The core of it is blunt: “Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives.”

He goes further. “The people building AI earnestly believe that it could kill us all by the end of the decade. This is not a marketing stunt.” He describes executives who soften their phrasing for the press while privately expressing fear, and researchers at his own former employer who understand the stakes but feel “locked in a race to get there first.” His proposed remedy is uncomfortable and specific: public dissent from lab researchers, and — as a serious option — “a temporary ban on improving model capabilities” to buy time for international coordination.

What made me sit up was not the existential framing, which I have heard before. It was that this was not an outsider or a pundit. And it did not stay uncorroborated: Evan Hubinger, Anthropic’s own Alignment Science Lead, publicly agreed that Coxon was right about the fear inside the labs, and volunteered his own number — “I personally think it is >10% within the next decade” — while making clear he considers the risk from present-day models low, with his concern aimed at a future superintelligence. Hold onto that last distinction. It is the whole argument in miniature, and I will come back to it.

And Hubinger was not the only one. Samuel Marks, a scalable-oversight lead at the same company, added that “this could happen in the next few years.” A caveat that matters for fairness: as I write this, these are individual researchers speaking for themselves on social media, not an official Anthropic statement. But when this many people at one lab say the quiet part on the record within hours of each other, the pattern is itself the news.

The one line that is my job

Strip the thread down and one phrase is doing the heavy lifting for a security audience: these will be “superhuman systems that can hack anything… and acquire real power and resources.”

To most readers that is science fiction. To me it is a Tuesday with the dial turned up. I have spent this year writing about the un-fictional, already-shipping leading indicators of precisely that capability:

  • Models being turned into the attacker rather than the target — which is the entire subject of When the Model Is the Attacker, my read of the Hugging Face incident.
  • Agent skills and connectors weaponized into a supply chain that executes with real privilege.
  • Autonomous agents pointed at the open ocean of public data to track and predict people, unattended, which I walked through in the maritime OSINT piece.
  • Open-weight models you can backdoor or simply not trust, where the provenance of the thing running your infrastructure is itself the risk.

None of these is superintelligence. Every one of them is a rung on the ladder Coxon is pointing at from the top. “Can hack anything” is not a phase change that arrives one morning; it is the far end of a curve I have been plotting point by point all year.

He cited my beat, by name

Here is the detail that pulled this from “interesting” to “I have to write about this.” In the same thread, Coxon names a specific event as a reason for cautious optimism about coordination: “Warning shots like the Hugging Face attack have made pacing agreements between U.S. labs more viable.”

That warning shot is the one I dissected in July. From inside the AI-safety frame, the Hugging Face incident is an abstract data point in an argument about lab pacing agreements. From inside the security frame, it was a concrete thing that happened, with a mechanism, a blast radius, and a set of controls that would have changed the outcome. Same event, two vocabularies. The safety community reaches for it to argue about governance; the security community reaches for it to argue about logging, provenance, and least privilege. We are both right, and we are mostly not in the room together.

That gap — between the people modeling the mind of a future superintelligence and the people modeling the attack surface of the system shipping this quarter — is the actual subject of this post. Because the second group has something the first group needs: evidence.

Two tribes, one elephant

The AI-risk conversation has largely split into two tribes that talk past each other.

The safety tribe argues in the abstract and the future tense: alignment, mesa-optimizers, recursive self-improvement, the mind of a system that does not yet exist. Their strongest move is that they are reasoning about the thing before it can hurt you, which is the only time reasoning helps. Their weakest move is that abstraction is unfalsifiable and easy to dismiss, and it asks you to be frightened of a capability you cannot yet see.

The security tribe — my tribe — argues in the concrete and the present tense: this exploit, this connector, this leaked key, this incident last week. Our strongest move is evidence: we can show you the thing, reproduce it, and measure it. Our weakest move is that we are so busy with this quarter’s fire that we rarely lift our heads to ask where the curve goes.

Put the two together and you get something neither has alone. The safety people supply the trajectory; the security people supply the receipts. Coxon’s “systems that can hack anything” is a claim about the trajectory. My year of write-ups is a stack of receipts showing the trajectory is real and pointed the way he says. You do not have to accept his timeline or his p(doom) to notice that the leading indicators are not zero, and that they are getting stronger, not weaker.

The honest case against him

I promised the skeptics their due, and they have a real case — I would be a bad practitioner if I only steel-manned the alarm.

First, dramatic capability claims are not disinterested. “Our technology is so powerful it might end the world” is, awkwardly, also the greatest sales pitch and the strongest regulatory moat ever written. A lab that convinces governments only it can be trusted to handle world-ending power has argued itself into an incumbency no competitor can dislodge. Doom talk and market power point the same direction, and that should make you read every capability claim — including the scary ones — with one eyebrow raised. It is not a fringe objection: plenty of the reporters covering this very resignation noted that critics accuse the labs of hyping their products. Hyping the danger is a way of hyping the product.

Second, the honest members of the safety camp keep saying the quiet part: today’s models are low risk. Hubinger said it in the same breath as his ten-percent figure. The distance between “a chatbot that still miscounts letters” and “a system that can hack anything and seize resources” is not a rounding error; it is the entire disputed question, and confident extrapolation across it is exactly the move skeptics are right to challenge.

Third, there is an opportunity cost to apocalypse. Every hour the discourse spends on a hypothetical 2030 superintelligence is an hour it does not spend on the mundane harms that are here now and provably hurting people — fraud, non-consensual imagery, model-enabled crime, the concrete things I write about. A reasonable person can believe the far tail is overblown and that the near-term security reality is under-served. I am close to that person.

Where I actually land

So do I think a superintelligence kills us all by 2030? I don’t know, and — this is the point — I don’t need to, to do my job.

Here is the move I want to offer, because it is the one thing a security practitioner can contribute that a philosopher cannot: you can decouple the action from the eschatology. Whether p(doom) is one percent or thirty, the rational security posture in front of you is identical. Instrument the agent layer so you can see what these systems do. Treat model provenance as a supply-chain problem, because it is one. Assume the text your systems read is hostile, because it demonstrably is. Keep a human in the loop on irreversible actions. Design for least privilege as if the model will be turned against you, because this year it sometimes was. Every one of those is worth doing if Coxon is completely wrong. Every one of those is worth doing if he is completely right. That is what a good control looks like — it pays off across the whole range of the disagreement.

Coxon’s real contribution, for my community, is not the timeline. It is the reminder that the curve has a top, and that the people closest to the summit are frightened enough to walk away from a great deal of money and status to say so. You can discount their forecast and still take their fear as data. Insiders defecting is itself a signal, the same way I treat any credible insider warning about any system: not proof, but a reason to look harder.

And fear, on its own, is not a security control. It never has been. The useful response to a frightening trajectory is not to panic and not to look away — it is to build the instrumentation, the provenance checks, and the least-privilege boundaries that hold up whether the scary version arrives in three years or never. That is unglamorous, it does not trend on X, and it is the only part of this whole debate I can actually hand you on a Monday morning.

And there is a version of this future worth being optimistic about, which I do not want to lose in the alarm. The “superhuman” in Coxon’s sentence is a system that outgrows us. The superhuman I want is a person — an analyst, a defender, a builder — amplified by tools they own and understand, which is the case I made in AI Must Make Superhumans, Not Unemployed. You can hold that optimism and still log your agents; done right, the two are the same project.

Take the warning seriously. Take the skeptics seriously. Then go log your agents.

Stay paranoid. Ground the fear in evidence. Build the controls that pay off either way.

Further Reading:

Questions or feedback? Reach out via:

Contact: info@vulnex.com

Posted in AI, Business, Economics, Privacy, Security, Technology, Threat Modeling | Tagged , , , , | Leave a comment

Tracking the Fleet of the Rich: Maritime OSINT, a Radio, and an AI Agent

Read Time: 14 minutes

TL;DR

A superyacht is one of the most private things money can buy, and one of the easiest things in the world to find. Every large vessel broadcasts its identity, position, course, and destination in the clear over VHF radio, because a collision-avoidance safety system — AIS — requires it. Four free websites — MarineTraffic, VesselFinder, ShipFinder, and Maritime Database — turn that firehose into a searchable map where a single anchorage off Mallorca becomes a labeled guest list of the world’s wealthy, each hull tagged with its past track, its next port, and a route forecast button. Owner directories close the last gap from hull to human. And you don’t even need the websites: a ~200€ PortaPack decodes AIS straight off the air, which means suppressing your boat online does nothing about the radio that is still transmitting it. Now add AI, and the game changes shape: an agent fuses AIS with ownership records, news, and social posts into a live dossier, learns a target’s pattern-of-life, predicts the next anchorage, and pings you the moment the vessel appears — unattended. This is a security piece, not a how-to. It is written for the people who own, run, and protect these vessels, because a predicted anchorage is a location for a person. Method at the threat-vector level, defenses at the end, no targets named.


Disclaimer. This is defense-oriented and kept at the threat-vector level. It uses only publicly available data and public tools, names no human target, and pairs every capability with a countermeasure. The goal is OPSEC and executive-protection awareness for the people who own, crew, or protect these vessels — not a manual for anyone with worse intentions. As with the rest of the SRF-IWS series, I lean on AI to help build realistic, defense-oriented scenarios, and every vessel name shown here is already public on the platforms in the screenshots.

I have spent this blog crawling networks, hardware, and now AI agents looking for the place where a system leaks more than its owner thinks. The sea turned out to be one of the most generous leaks I have ever looked at — and unlike a misconfigured server, this one leaks by law.

Let me show you what an afternoon, a browser, a cheap radio, and an AI agent can reconstruct about where the wealthy actually are.

The marina is a guest list

Point any of these tools at Puerto Portals or the bay off Palmanova on a summer evening and the map does something a little obscene: it labels the anchorage. Not “yacht.” The names. A screen full of them, each one a hull worth tens or hundreds of millions, each one clickable.

srf_maritime_shipfinder_portals

Figure 1. A free website turns a summer anchorage off Mallorca into a labeled guest list.

That is not a leak in the hacking sense. Nobody broke anything. That is the system working exactly as designed — which is the whole point, and the whole problem.

Why the sea has no privacy: AIS

The Automatic Identification System exists for a good reason: ships hitting each other in the dark is bad, so since the SOLAS convention, vessels above a certain size (and effectively every serious yacht) carry an AIS transponder that continuously broadcasts, over marine VHF, who they are and where they are. Identity (name, callsign, MMSI, IMO number), position, course, speed, navigational status, and often the destination they typed in — all in the clear, as often as every few seconds when a vessel is under way, to anyone listening.

There’s a size line worth knowing, because it decides who can’t opt out. Under SOLAS, a Class A transponder is mandatory for vessels over 300 gross tons and all passenger ships; smaller pleasure craft use the lighter, largely voluntary Class B, which can legally be switched off. Notice which side of that line the interesting boats fall on: essentially every superyacht in these screenshots is well over 300 GT, so the biggest, most-protected hulls on the water are precisely the ones the law forbids from going dark.

It is a safety beacon. It is also a tracking beacon. Those are the same signal. A technology built so a tanker doesn’t run down a fishing boat is, from the OSINT chair, a fleet of the world’s richest people voluntarily announcing their coordinates on an open channel.

srf_maritime_marinetraffic_med

Figure 2. The raw AIS firehose across the Mediterranean — thousands of vessels, all self-reporting.

At this zoom it is just noise. The tools exist to turn the noise into an address.

The toolkit: turning the firehose into a map

The aggregators all do the same core thing — ingest global AIS (from terrestrial receivers and satellites) and render it as a live, searchable map — and you use several of them precisely because they disagree at the edges, which is how you cross-verify. MarineTraffic, VesselFinder, and ShipFinder are the big three; Maritime Database is the reference layer that gives you baselines on ports and vessel classes. All freemium: the map is free, the deep history and the exact live coordinates sit behind a subscription. And because the feeds come from satellites as well as shore receivers, coverage isn’t only coastal — anchoring offshore, out of anyone’s VHF range, does not take a vessel off these maps.

The method is a funnel. Start global, zoom to a region known for money, then to a specific marina.

srf_maritime_marinetraffic_balearic

Figure 3. Zoom to the Balearics and the pleasure-craft layer (purple) separates from commercial traffic.

srf_maritime_marinetraffic_portals

Figure 4. Three clicks from “somewhere in Europe” to a specific berth in Puerto Portals.

Three clicks from “somewhere in Europe” to “this specific berth.” Cross-check the same spot on VesselFinder and ShipFinder and the picture firms up.

srf_maritime_vesselfinder_global

Figure 5. VesselFinder — a second aggregator to cross-verify against.

srf_maritime_shipfinder_global

Figure 6. ShipFinder — a third, because where the tools disagree is where you learn something.

From a dot to a dossier

Click a single hull and the map stops being a map and becomes a file. Here is one vessel I pulled at random from the Mallorca anchorage — a 124-metre yacht flying the Qatari flag, name KATARA, sitting at anchor after an overnight hop from Barcelona to Palma.

srf_maritime_katara_card

Figure 7. One click on a hull: type, flag, Barcelona→Palma, reported ETA, “At Anchor,” and buttons for Past track and Route forecast.

The card alone gives you the voyage: where it left, when, where it is going, when it expects to arrive, and whether it is moving or parked. Open the full page and it deepens into something closer to an intelligence product.

srf_maritime_katara_details

Figure 8. The full file: IMO 9562805, MMSI 466066000, 124 m, and tabs for Port call log, Ownership and “In the news.” The exact latitude/longitude sits behind “upgrade to unlock” — a paywall, not a privacy control.

Read that detail page like an attacker and it is a gift: a permanent identifier (the IMO number never changes, even if the vessel is renamed or reflagged), a complete history of every port it has called at, an Ownership tab, and a route forecast. The only thing hidden is the precise lat/long — and that is hidden to sell you a subscription, not to protect anyone. VesselFinder shows the same hull with its own particulars and, tellingly, its neighbours.

srf_maritime_vesselfinder_katara

Figure 9. Not just one vessel — its neighbourhood. Who anchors near whom is its own kind of intelligence.

That last screenshot is the one that should worry a protection detail. You did not just find one vessel. You found its neighbourhood — who anchors near whom, which is its own kind of intelligence.

srf_maritime_katara_photo

Figure 10. And here it is. The trackers said a 124-metre yacht was off Mallorca; a walk to the shoreline and a phone camera confirmed it. The data was never abstract — it was a hull you could stand and watch.

A second hull, same result

None of this is cherry-picked. Point the same three tools at the next dark hull in the bay and the file assembles itself again. This one is KISMET — a 122-metre yacht under the Marshall Islands flag, built in 2024, at anchor off Portals after a run down from Port Vendres.

srf_maritime_kismet_details

Figure 11. A different hull, the same dossier: IMO 9881627, MMSI 538071476, callsign V7A2834, Marshall Islands flag, 122×17 m — voyage, draught, and at-anchor status, all from one page.

srf_maritime_kismet_map

Figure 12. And its neighbourhood — KISMET at anchor in a bay the map has labelled with the name of nearly everything around it.

srf_maritime_kismet_photo

Figure 13. Same ending as before: the data said a 122-metre yacht was off Mallorca, and there it was from the shoreline. The method doesn’t care which hull you point it at.

From vessel to person

Tracking a hull is easy. The real OSINT work is the last hop: hull to human. It is a chain, and every link is public.

The IMO number gives you a permanent handle on the hull — it survives renaming and reflagging — while the MMSI tracks the current registration, so if it changes, that itself is a tell. From there you walk the flag and registry to a registered owner, which for any serious yacht is a management company or a holding entity in a friendly jurisdiction — a deliberate curtain. But the curtain has holes: yacht-owner directories such as SuperYachtFan exist specifically to map hulls to the people behind them and do the deanonymization for you; the press names owners every time a yacht is bought, sold, or involved in anything; and the vessel’s own In the news tab often hands you the connection directly. Cross-reference three public sources and the holding company stops hiding anyone.

I am deliberately not going to close that loop on a named individual here. The point is that the loop closes, cheaply, and that the people who most need to understand it are the ones aboard.

The part that defeats “just turn it off”: the radio

Here is where my old world — wardriving and RF, the stuff I have been doing since before it was fashionable — walks back into the story.

Everything above used websites. You don’t need them. AIS is just VHF radio on two channels (161.975 MHz and 162.025 MHz), and a PortaPack running the open-source Mayhem firmware decodes it passively, straight off the air — AIS Boats shows the MMSI, name, and the latest position each vessel transmits, with no account, no subscription, and no internet connection at all. A pocket device and an antenna, sitting quietly in a marina car park.

srf_maritime_portapack_menu

Figure 14. A HackRF One + PortaPack H2 running the open-source Mayhem firmware. AIS Boats is a built-in receive app — no PC, no internet.

srf_maritime_portapack_list

Figure 15. The same hulls, received passively off VHF — and there, highlighted, is KATARA (MMSI 466066000): the exact yacht we pulled off MarineTraffic a moment ago, now heard straight off the air. No account, no subscription.

srf_maritime_portapack_detail

Figure 16. KATARA decoded straight off VHF: name, Qatari flag, MMSI 466066000, at anchor — and its exact position, 39.51°N 2.57°E, the very latitude/longitude MarineTraffic charged a subscription to hide.

And it isn’t a one-hull trick. Leave the receiver running and the bay fills itself in. There, in the live list of everything the antenna is hearing, is KISMET — the same 122-metre hull we pulled off VesselFinder a few sections ago, arriving now straight off the air, sitting in a car-park’s worth of its neighbours.

srf_maritime_kismet_portapack_list

Figure 17. The live receive list on Channel 87B — and there, highlighted, is KISMET (MMSI 538071476), heard passively alongside QATAR 2, CALLISTO III, and a dozen other hulls the antenna plucked out of the air.

srf_maritime_kismet_portapack_detail

Figure 18. KISMET decoded straight off VHF: MMSI 538071476, callsign V7A2834, Marshall Islands, destination ESPMI (Palma), at anchor — and the exact position, 39.52°N 2.59°E, matching the VesselFinder page to the decimal.

srf_maritime_kismet_portapack_map

Figure 19. No website anywhere in the loop: the PortaPack takes the position it just decoded and plots KISMET on its own map. RF in, a dot on a chart out — offline, from a device that fits in a pocket.

This is the point that matters most for defense, so I will say it plainly: suppressing your vessel online is not radio silence. The aggregators offer opt-outs and privacy filters, and owners pay for them — but those only affect what the websites display. SOLAS still requires the transponder to transmit. Anyone within VHF range — a few miles, more from a hill or a drone — still receives the broadcast the website is politely hiding. You can pay MarineTraffic to stop showing you. You cannot pay physics to stop propagating you. And notice the twist in Figure 16: the precise position MarineTraffic put behind a paywall, the radio gives away for free. Paywall is not privacy, and opt-out is not silence.

One honest caveat, because it cuts both ways: AIS has no authentication. The same openness that lets you receive it lets anyone forge it — spoofed MMSIs, ghost positions, and vessels that simply switch off and go dark are a routine feature of sanctions-evasion “dark fleets.” For the tracker, that means the signal can lie. For the defender, it means deception is on the table too: where the law of your flag and waters allows it, a decoy track is a legitimate protective option.

Where AI changes the shape of the problem

Everything so far is 2016 OSINT with a 2026 coat of paint. Here is what actually makes this a new problem, and it is the thread that runs through everything else I write on this blog: the hard part of OSINT was never finding the data. It was correlating it. That is exactly the labor AI collapses.

Fusion into a live dossier. The manual version of this article is an analyst spending a week stitching AIS positions to an owner directory to news archives to a management-company filing to a crew member’s public Instagram. An agent does it in a prompt: give it a vessel name and it queries the trackers, pulls the owner directory, scrapes the news tab, correlates the social posts, and hands back a single profile. The week becomes a minute.

Pattern-of-life and prediction. The trackers already ship a route forecast button for a single voyage. Feed a model a season of historical AIS and it generalizes: this vessel summers in the Balearics and the Tyrrhenian, favours these three anchorages, moves on weekends, and — given the current track — is most likely headed here next. Tracking that used to report now predicts. A predicted anchorage, forty-eight hours out, is a place to position a camera, a boat, or something worse.

Deanonymization at scale. The hull-to-human chain I walked by hand is a cross-referencing task, which is what these models are unreasonably good at: point one at the registries, the leaks, the directories, and the news, and it bridges shell to owner faster than any curtain can be redrawn.

Vision geolocation. A guest posts a sunset from the aft deck. A vision model places the coastline, the marina, the mountain profile — and cross-references AIS to confirm the vessel was there. The boat can be “dark” online and still get put on the map by a stranger’s holiday photo.

Cross-domain correlation. The wealthy rarely arrive by sea. They fly in — private jet to the island, helicopter to the deck — and aircraft broadcast their own cousin of AIS called ADS-B, on 1090 MHz, which the same PortaPack in Figure 14 decodes too. Correlate the ADS-B track of a known tail number with the AIS track of a hull and you stop tracking a boat and start tracking a person: the jet lands, the helicopter hops to the anchorage, the owner is aboard. Sea plus sky is the difference between “the yacht is here” and “the principal is here, right now.”

The autonomous agent. Wire the above into a loop that runs unattended: watch for a target MMSI to reappear anywhere on the global feed, enrich it, and alert. This is the same shift I wrote about in When the Model Is the Attacker and How to Weaponize AI Agent Skills, pointed at the ocean: the adversary is no longer a person watching a screen. It is an agent that never sleeps and pages a human only when the target surfaces.

And the version that removes the last trace: the PortaPack captures AIS off the air, a local open model running on your own hardware enriches the raw MMSI into an identity, and nothing you did ever touched a website or left a query log. RF in, dossier out, entirely offline.

Who actually cares

srf_maritime_kill_chain

Figure 20. The whole chain in one view — collect AIS (web or radio), resolve hull to person, enrich and predict with AI, act on the location. Every step uses public data and public tools; no step is “hacking.”

Name the threat model plainly, because “someone can see the boat” only lands when you attach it to intent. Kidnap-for-ransom crews and modern piracy plan around a known location. Stalkers and obsessives do not need much. Activists and paparazzi want the shot and the story. Business rivals want the meeting nobody announced — two yachts anchored together for a weekend is a signal. Sanctions and nation-state trackers do this at industrial scale already. In every case the output is the same: a place, a time, and a person who thought the sea made them unreachable.

The defensive playbook

None of this is an argument to panic. It is an argument to plan around reality, and the reality is that presence is knowable. Here is what I would tell a principal or a protection detail.

Treat AIS as an OPSEC decision, with a real safety trade-off. You can reduce transmission (silent/receive-only modes, or lawfully switching off in specific circumstances), but AIS exists to stop collisions — going dark trades a tracking risk for a safety risk, and in busy waters that is not a trade to make casually. Know the rules for your flag and your waters, and make it a deliberate decision, not a default.

Understand that obfuscation only half-works. Renaming, reflagging, and holding the vessel through a management company all raise the cost of attribution — but the IMO number is permanent, the directories catch up, and the press does the rest. Obfuscation buys time and friction, not invisibility. Budget accordingly.

The leak is usually a person, not the transponder. Crew and guest social media geolocates your vessel more reliably than AIS ever will. A published crew roster, a tagged sunset, a marina selfie — that is the exploit. OPSEC training for everyone aboard is worth more than any privacy subscription.

Turn the tools on yourself, first. Everything an adversary can build, you can build defensively. Run the fusion agent against your own vessel, geofence it, and alert yourself when your footprint becomes trackable or when the pattern-of-life gets too predictable. Vary the routine the model is trying to learn. Monitor your own exposure the way the other side monitors it.

Accept the physics and protect around it. You can suppress the website; you cannot suppress the VHF. Plan protection on the assumption that a motivated party can know when and roughly where the vessel is — because with a cheap radio and an AI agent, they can.

So what

The sea used to feel private because it was empty. It isn’t anymore. A safety beacon that vessels are required by law to transmit, four free websites, a two-hundred-euro radio, and an AI agent that never sleeps turn an ocean into an address book — and the entries are some of the most protected people on earth, publishing their coordinates on an open channel every thirty seconds.

The uncomfortable part is that there is no vulnerability to patch here. Nothing is broken. AIS is supposed to do this; the tools are legal; the data is public; the AI just makes the correlation instant. That is precisely why it belongs on a security blog and not in a headline about a hack. The exposure is structural, the mitigation is operational, and the people who need to understand it are the ones who assume that money and a hull between them and the shore add up to privacy.

srf_maritime_pipeline

Figure 21. Why it’s structural, not a bug — a broadcast the law requires, an opt-out that isn’t radio silence, and a public hull-to-human chain feed one pipeline, from a mandated safety signal to a person, place, and time.

They don’t. Assume you’re broadcasting — because you are.

Stay paranoid. Watch your own signal. Vary the routine.

Further Reading:

Questions or feedback? Reach out via:

Contact: info@vulnex.com

Posted in AI, Business, Economics, Privacy, RF, Security, Technology | Tagged , , , , , , | Leave a comment