Agentic AI
,
Artificial Intelligence & Machine Learning
,
CyberEdBoard

Cybersecurity Advisor Chris Eng on Need to Accurately Measure Frontier Model Risks

Tom Field (SecurityEditor) •
June 29, 2026    

Chris Eng, cybersecurity advisor and consultant

Federal export controls forced Anthropic to cut off access to its Fable and Mythos models with roughly 90 minutes’ notice and minimal transparency. The real problem wasn’t the decision itself, but how it was made – without published data, clear methodology or scientific rigor, Chris Eng, a cybersecurity advisor and consultant.

See Also: Edge Transformation: Top 5 SASE Predictions and Trends

Eng is one of more than 100 prominent cybersecurity leaders, researchers, academics and former government officials, who signed an open letter to U.S. Commerce Secretary Howard Lutnick and National Cyber Director Sean Cairncross, saying that restricting access to Anthropic’s models would weaken defenders by denying them advanced AI tools for vulnerability discovery, secure code review, malware analysis and incident response.

The export control-related shutdown stemmed from a research paper claiming the models could be subverted. But the vulnerability amounted to asking a model to find and fix code flaws, a core defensive use case. Eng said the same behavior is replicated across GPT-5.5, Sonnet and open-weight models, so removing one company’s tools accomplishes little while putting it in a commercial disadvantage.

What’s needed instead is structured, published benchmarks that measure how well each model resists jailbreaks against explicit, measurable criteria, he said (see: Restore Fable and Mythos Access, Cybersecurity Leaders Urge).

“It reminded me of previous export restriction type things that we’ve seen in the past around cybersecurity where somebody just gets worked up over the danger of something without thinking about the side effects,” he said.

In this CyberEdBoard-sponsored video interview with ISMG’s Tom Field, Eng also discussed:

How AI compresses the time from vulnerability disclosure to active exploitation;
Why legacy code remediation still depends on human developers as a backstop;
What rising token costs mean for CISO threat modeling and resilience.

What made Fable 5 different? And why did it become a defining moment in the conversation around AI safety? Download this report unpacking one of the most consequential events in AI governance.

Download the Fable 5 Directive Report
About the Speaker

Eng advises cybersecurity companies on product strategy, research direction and market alignment. With more than 25 years of experience, he specializes in application security and software security research. He previously led research at Veracode and held leadership roles at CA Technologies, Symantec and @stake.