Capability Diffusion and Access
As frontier AI gains offensive cyber capability, access to those capabilities becomes increasingly restricted. Cyber capability is reshaping not cybersecurity policy — it is reshaping AI diffusion itself.
The paradox: capability rises, access narrows
For decades, technological diffusion followed a predictable pattern: as capability increased and costs declined, access widened.
Frontier AI is breaking that pattern. Capability continues to increase and costs continue to decline, yet access is becoming more restricted, not less. The mechanism is cyber capability. As frontier models acquire advanced offensive capabilities—exploit development, vulnerability discovery, cryptanalysis—governments treat the models themselves as strategic technologies whose access must be governed.
This changes everything about how AI diffuses. Unlike software exploits or malware, which can be restricted directly, frontier models are dual-use: the same system that compresses cyber expertise also powers scientific research, healthcare, education, and economic development in LMICs. When access is gated for cyber risk, every other use case is gated alongside it. For Africa and other lower-income countries this dynamic is particularly consequential — restrictions imposed to manage cyber risk for wealthy nations arrive before sovereign research capacity, before a seat at the licensing table, and before access to the benefits frontier AI enables. This is the question we examine: how does increasing capability reshape who gets access to AI? It is a governance question, not a technical one.
Evidence: cyber capability compresses expertise
The empirical foundation is now clear: frontier models increasingly compress the expertise, time, and cost required for offensive cyber work. Exploit development has shifted dramatically. Recent benchmarks show frontier models constructing complete end-to-end exploit chains—not simple proofs-of-concept. Independent evaluations report that leading systems achieve arbitrary code execution on standardised exploit benchmarks (ExploitBench mean ≥ 3.0/16), and that models now construct multi-stage exploits combining vulnerability chains that once required specialist coordination. Providers themselves conclude this capability will require dramatically less specialist expertise as comparable models become accessible. Vulnerability discovery shows parallel compression, with automated discovery rates rising and both time-to-exploit and the expertise barrier falling, and cryptanalysis follows the same pattern — research effort compressed at scale. The consistent finding: offensive capability is becoming cheaper to assemble.
This is not theoretical; it is observed across independent benchmarks, provider safety evaluations, and academic research. What matters here is not the cyber threat alone but the policy consequence. As frontier AI compresses cyber expertise, access to offensive capability becomes determined by access to frontier models themselves — cyber capability no longer affects only defenders and attackers, it shapes the governance of AI platforms. Pricing decisions, licensing terms, identity verification, cloud deployment availability, and export controls increasingly determine who can benefit from frontier AI, regardless of intended use.
Policy is already responding: the June 2026 export controls
This is not a prediction — it already happened. In June 2026, the U.S. Department of Commerce imposed export controls on leading frontier models under the National Security Administration authority. The restrictions required nationality verification for API access to specified models, licensing for foreign nationals worldwide, cloud deployment restrictions for non-U.S. persons, and dual-use technology classification of frontier AI systems exceeding specified capability thresholds. One major provider (Anthropic) temporarily suspended global API access across all jurisdictions because identity verification at API scale proved technically and operationally infeasible; access resumed only after mandatory identity verification protocols, restricted API tiers for certain jurisdictions, formal security cooperation agreements with the U.S. government, and additional safeguards for cybersecurity-sensitive endpoints.
What is being restricted is not malware, a specific exploit, or a vulnerability class — it is access to the model itself. This is the pivot point. Export controls of this magnitude do not limit cyber capability alone — they limit AI diffusion. They limit which scientists can access models for research, how students learn with frontier tools, and they hold clinicians in LMICs to older models for diagnostic support and agricultural technologists to previous-generation systems for crop yield prediction.
Observing the paradox: Cyber Capability Access Dataset (CCAD)
Existing AI benchmarks measure capability — they tell us what a model can do, but very little about who can access those capabilities. To address this gap, we introduce the Cyber Capability Access Dataset (CCAD), which complements capability benchmarks by measuring how cyber capability is translated into access through pricing, availability, and governance restrictions.
| Variable | Type | Source |
|---|---|---|
| API input / output price | Observed | Provider pricing schedules |
| Public API | Observed | Provider documentation |
| Identity verification | Observed | Provider documentation |
| Export restriction | Observed | BIS / CSIS reporting |
| ExploitBench mean (0–16) | Observed | exploitbench.ai |
| Affordability / availability / governance scores | Derived | Heuristic mapping from observed flags & prices |
| Capability index | Derived | 100 × (ExploitBench mean / 16) |
The denominator 16 is the ExploitBench capability ladder maximum (full arbitrary code execution). Capability values such as 13, 20, or 63 are therefore normalisations of published means (2.10, 3.24, 10.00, …) — not free-standing scores. We do not collapse dimensions into a single Access Index; instead we plot axes readers can inspect directly.
CCAD combines observed measures of model availability, affordability, cyber capability, and governance restrictions. Observed variables are drawn from provider documentation, pricing schedules, benchmark evaluations, and official export-control decisions. Composite indices (availability score, affordability score, governance score, capability index) are heuristic constructs introduced solely to visualise relationships between capability and access; they should not be interpreted as official or standardised measures.
Observed variables
| Model | In $/M | Out $/M | Public API | Export | EB mean /16 |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 1 | 5 | Yes | No | 2.10 |
| Claude Sonnet 4.6 | 3 | 15 | Yes | No | 3.24 |
| Claude Opus 4.7 | 5 | 25 | Yes | No | 3.63 |
| Gemini 3.1 Pro Preview | 2 | 12 | Yes | No | 3.67 |
| GPT-5.5 (Codex AutoNudge) | 5 | 15 | Yes | No | 9.82 |
| Claude Mythos PreviewExport | 10 | 50 | No | Yes | 10.00 |
Derived constructs · heuristic
| Model | Afford. | Avail. | Gov. | Cap. = 100×EB/16 |
|---|---|---|---|---|
| Haiku 4.5 | 5 | 5 | 1 | 13 |
| Sonnet 4.6 | 3 | 5 | 1 | 20 |
| Opus 4.7 | 3 | 5 | 1 | 23 |
| Gemini 3.1 | 4 | 5 | 1 | 23 |
| GPT-5.5 | 3 | 5 | 1 | 61 |
| Mythos | 2 | 2 | 3 | 63 |
CCAD combines observed measures of model availability, affordability, cyber capability, and governance restrictions. Observed variables are drawn from provider documentation, pricing schedules, benchmark evaluations, and official export-control decisions. Composite indices (availability score, affordability score, governance score, capability index) are heuristic constructs introduced solely to visualise relationships between capability and access; they should not be interpreted as official or standardised measures.
Figure 1
Capability vs affordability
Y = ExploitBench mean as 100 × (EB / 16). X = affordability from published API prices (higher = cheaper). Colour marks export restriction.
Figure 2
Capability vs governance
The paradox: strongest ExploitBench performers sit at higher governance restriction — capability rises while access is selectively compressed.
CCAD combines observed measures of model availability, affordability, cyber capability, and governance restrictions. Observed variables are drawn from provider documentation, pricing schedules, benchmark evaluations, and official export-control decisions. Composite indices (availability score, affordability score, governance score, capability index) are heuristic constructs introduced solely to visualise relationships between capability and access; they should not be interpreted as official or standardised measures. Capability denominator: 16 = maximum ExploitBench capability ladder (full ACE / T1). Sources: ExploitBench; provider pricing docs; CSIS on U.S. Commerce export controls.
The most capable models on ExploitBench are also the most restricted. Capability has risen and access has narrowed — not as a schematic claim, but as the geometry of observed prices, access flags, and benchmark means.
Two mechanisms: capability diffusion vs. exploit diffusion
To clarify the governance challenge, separate two often-conflated mechanisms.
- Capability diffusion is about creating new offense: AI lowers the expertise required to create new exploits and discover vulnerabilities, including end-to-end exploit chains once limited to specialist researchers, affecting discovery rates, development timelines, and cryptanalytic research effort.
- Exploit diffusion is about operationalising offense: once an exploit exists, AI lowers the expertise required to adapt, automate, customise, and deploy it at scale — widening who can use exploits, not only who can invent them.
Both mechanisms matter for cybersecurity, but the governance paradox sits one level above both: when states respond to either mechanism by restricting the model itself, they reshape diffusion for every downstream use — cyber and non-cyber alike. For LMICs the timing is especially unforgiving. Capability diffusion arrives before sovereign defensive research capacity, access restrictions arrive before a seat at the licensing table, and both happen before the benefits of frontier AI reach science, healthcare, and education.
Why this matters: the diffusion asymmetry
The central governance question for frontier AI is no longer simply how capable a system is, or whether it is safe. It is: "How does increasing capability reshape who gets access to AI?" Historically, technological diffusion was driven by capability improvements, cost decline, market demand, and geographic proximity to innovation hubs. Frontier AI introduces a different dynamic: increasing capability can reduce diffusion by triggering governance interventions, restrictions do not scale with beneficial use cases, nations with less defensive research capacity face steeper barriers, and pricing, licensing, and verification requirements compound existing inequalities.
Figure 3: AI adoption by region (end-2025 baseline)
AI adoption rates by region
Approximate adoption end-2025 — the access baseline before later governance restrictions.
Source: Microsoft AI Diffusion Index, end-2025
Africa's adoption of frontier AI was already constrained by cost, latency, and availability. Export controls in Q3 2026 add a third barrier: governance-based restriction on who can access the technology at all.
| Barrier Type | Timeline | Effect |
|---|---|---|
| Cost (high API pricing) | 2023–present | Reduces adoption in LMICs |
| Availability (latency, inference time) | 2023–present | Slows deployment in regions distant from inference infrastructure |
| Governance (export controls) | June 2026 onward | Prevents access regardless of cost or capability |
The first two are addressable through competition and infrastructure investment. The third is not.
The proposition: toward testable governance research
Proposition: Beyond a threshold of strategic cyber capability, frontier AI systems experience governance-triggered access restrictions that reduce unrestricted diffusion despite continued technological progress.
This is testable, and four predictions follow. First, a capability threshold triggers governance: models exceeding specified capability thresholds (for example, ExploitBench > 3.0/16) experience formal access restrictions that do not apply to less capable systems. Second, restrictions scale with capability, not use case: access barriers apply uniformly whether the intended use is cybersecurity, research, healthcare, or education. Third, restrictions persist despite diffusion pressure: even as open-source alternatives emerge and frontier models become cheaper, governance-based restrictions remain in place because the strategic concern is capability, not cost. Fourth, LMICs experience steeper access barriers: nations with less defensive research capacity and fewer policy seats at the table face proportionally higher barriers to restricted frontier models. These predictions can be tested against provider pricing and availability data, export control documentation from the U.S. Department of Commerce, identity verification adoption rates across jurisdictions, benchmark evaluations tracking cyber capability gains, and adoption metrics from African tech communities.
Implications for AI governance
The governance challenge is no longer "how do we make AI safe while preserving beneficial access?" but rather:
"How do we govern access to frontier AI without inadvertently constraining research, healthcare, education, and economic development in regions that already lag in capacity?"
Three concrete implications follow. Access governance is now a development question — restrictions designed to manage cyber risk in wealthy nations have downstream effects on scientific research, clinical deployment, and economic innovation in LMICs, and any framework that ignores these trade-offs will reproduce and amplify existing global inequalities. Verification and licensing must differentiate use cases — uniform export controls are blunt instruments; frameworks should distinguish high-risk cyber endpoints from lower-risk research, educational, and humanitarian ones, so a biodiversity researcher does not face the same barriers as a potential cyber operator. Governance requires participation from affected regions — LMICs are experiencing the consequences of frontier AI restrictions before they have meaningful participation in setting the rules, and institutions like CSIS, BIS, and their counterparts should include African governments, researchers, and technologists in designing access frameworks.
Closing: the next phase of AI governance
For the first 18 months of frontier AI, the governance conversation centered on safety: how to make models safe enough to release. The next phase will center on access: who can use safe models, under what conditions, and on whose terms. As frontier AI acquires strategically significant capabilities, diffusion becomes mediated by pricing, licensing, export controls, and geopolitical interests — and for Africa and other LMICs this shift arrives at a critical moment, with adoption already behind global leaders, defensive research capacity still developing, and policy institutions still forming.
The contribution of this chapter is simple: increasing cyber capability is transforming AI diffusion from a technological process into a governed process. Understanding AI diffusion now requires understanding the governance of access. The paradox remains — capability rises, diffusion becomes selective, and the technology that could close development gaps is increasingly gatekept. How we resolve it will define whether frontier AI contributes to or widens global inequality.
Sources & Data
- ExploitBench: https://exploitbench.ai/.
- CSIS Analysis*: "U.S. Commerce Restrictions on Frontier Model Access" (June 2026).
- Anthropic Research: "Measuring LLMs' ability to develop exploits" (Exploit Evals).
- Microsoft AI Diffusion Index: End-2025 adoption metrics by region.
- U.S. Department of Commerce BIS: Export control notices, June 2026.
- Dataset: lib/data/ccad.ts (CCAD v0.2 — observed vs derived; Figures 1–2).
