
In the previous piece, we followed a deceptively simple question much farther than it initially looked capable of taking us: what happens when reasoning stops being scarce? The answer wasn’t simply that existing systems get faster, cheaper, or more productive. The deeper change happens when you realize that many of the structures we take for granted were themselves shaped by the scarcity of reasoning. Remove that constraint and the relevant question becomes: what remains scarce now?
That exercise eventually produced a more general conclusion. As capability expands, capability itself explains less. Selection explains more. When an actor can choose from an enormous number of possible actions, understanding what they could do tells you progressively less about what they will do. The actor becomes the constraint. Their goals, fears, incentives, beliefs, uncertainties, time horizon, and strategic situation start doing the explanatory work that technical limitation used to do.
Cybersecurity is where this gets especially strange. So rather than starting with an attack, a vulnerability, a piece of malware, or a target, I want to start somewhere else. For the next few pages, you are Iran. Not Iran in the abstract — Iran at a sequence of specific moments in an escalating conflict with the United States. And we’re going to change one assumption.
Suppose the technical constraints that historically limited cyber operations have weakened far more dramatically than most observers yet appreciate. Suppose reasoning over unfamiliar systems, searching enormous technical spaces, identifying possible pathways through them, adapting across architectures, and finding leverage has become cheap enough that the practical attack surface starts approaching universality. Not literally infinite — just close enough that access stops being the useful organizing question.
Now look at the world from Tehran. What do you do?
Before the War
You’re conventionally weaker than your principal adversary. Not somewhat weaker — structurally weaker. If the conflict takes place entirely on the conventional battlefield, the geometry of the contest is bad for you. That fact has shaped Iranian statecraft for decades: you invest in instruments that let a weaker power create effects outside the dimensions where the stronger power enjoys overwhelming superiority. Proxies, missiles, drones, maritime pressure, ambiguity, cyber operations — anything capable of making conventional strength an incomplete description of the battlefield.
Now imagine one of those instruments has quietly changed. Previously, cyber capability was constrained everywhere. Access was scarce, expertise was scarce, time was scarce, reconnaissance was expensive, understanding unfamiliar systems was hard. Operations that crossed technical domains required different specialists, different infrastructure, different preparation, different knowledge. Even a highly capable state could only explore a tiny fraction of the total possibility space available inside a country as large and technically complex as the United States. Now that constraint begins to collapse.
What should you do? The intuitive answer is: attack more. That’s already the wrong ontology. Before open war, your dominant constraint isn’t access — it’s uncertainty about the future. Conflict may still be avoided, and your capabilities are valuable partly because your adversary doesn’t know their extent. Every visible operation spends some of that uncertainty.
There’s another problem: you don’t know the extent of your new capability either. You may have extremely strong evidence that something fundamental has changed — that systems which once required rare expertise can now be understood rapidly, that unfamiliar technical environments no longer stay unfamiliar for long, that pathways appear where your previous models said none should exist. But discovering the frontier moved isn’t the same thing as knowing where the new frontier lies.
So before the war, your cyber problem has two dimensions running at once. Externally: what do we want them to know about what we can do? Internally: what do we need to learn about what we can actually do? Those questions stay coupled for the rest of the conflict. Every operation communicates outward. Every operation updates inward. You’re teaching the adversary something about your capabilities while simultaneously using reality to teach yourself.
That means restraint can be rational even in the presence of enormous capability. You explore, you map, you test assumptions, you accumulate optionality, you preserve surprise. The capability may be growing rapidly while its visible expression stays comparatively quiet.
Then the war starts.
February 28
Now the strategic environment changes almost instantly. Direct conflict begins. The supreme leader is killed. Whatever uncertainty existed about whether the confrontation would stay bounded has just collapsed.
You’re Iran. What do you want now? Before this moment, preserving optionality dominated. Now another requirement appears: you need to demonstrate survivability, you need to retaliate, you need to make clear that overwhelming conventional superiority doesn’t produce strategic impunity. You need the adversary to understand that striking Iran creates consequences that can’t be contained solely inside Iran.
And the asymmetry matters — you can’t answer every American capability symmetrically, so your comparative advantage lies precisely in choosing effects the stronger actor can’t prevent simply by dominating the conventional battlefield. Look again at your newly expanded cyber option space. The technical question — what can we access? — is becoming almost useless. The strategic question is now: what can we make visible?
The first capability worth demonstrating, then, isn’t destruction. It’s reach. The message is simple: the battlefield does not end where your conventional weapons do.
That’s useful externally. But remember the internal epistemic loop — you’re also testing your own model. Can this capability produce operational effects under wartime pressure? Can it move from exploration into action quickly? Can it survive contact with real defensive systems? Can it generate repeatable outcomes rather than impressive laboratory demonstrations? Can it do all of that without revealing more than you intend?
The first wartime operations, then, aren’t merely attacks. They’re experiments conducted inside the conflict. The adversary sees an effect. You see an effect and a measurement: what worked, what failed, what surprised you, how quickly the defender recovered, how accurately your model predicted the result, how the United States interpreted what happened. Every answer changes the next decision. And suddenly the capability begins learning itself.
March 11–12
Now the pressure broadens. The confrontation is no longer merely military — financial and commercial pressure becomes increasingly explicit. Again, stop. You’re Iran. What do you want at this moment? The answer should change, because the problem changed. You no longer merely need to demonstrate that the conflict can reach American territory. You need to demonstrate reciprocity of economic pressure. If the United States can use its position inside global financial and commercial systems to impose costs on you, what would make that strategy feel less one-directional?
Not necessarily destruction. Friction may be enough. Uncertainty may be enough. Cost may be enough. Loss of confidence may be enough. The important move is that the political pressure defines the useful effect class before any target has been selected. You don’t start with “what systems are vulnerable?” You start with “what consequence would answer the pressure currently being applied to us?” Then you search an enormous technical landscape for the cheapest, most controllable way to create that consequence.
This is the inversion. Under the old ontology, the pathway looked roughly like: find vulnerability → identify target → exploit → observe consequence. Under the new one, it starts looking more like: strategic pressure → desired adversary update → useful consequence → acceptable escalation → search for implementation. The target arrives near the end. And because your technical search space has expanded so dramatically, your strategic objective can become far more precise. You’re no longer forced to use whatever access happens to be available — you can increasingly search for access that matches the effect you want. That’s a completely different kind of power.
March 21–23
Then the conflict compresses again. The Strait of Hormuz becomes the center of an explicit ultimatum. Critical infrastructure enters the rhetoric directly. Deadlines appear. Threats become reciprocal. The interaction becomes increasingly legible as bargaining under conditions of violence.
You’re Iran. What do you want now? Maximum destruction? Probably not — maximum destruction has a severe defect when you’re the conventionally weaker actor. You may trigger an escalation you can’t control. And more importantly, destruction spends an option. Once you cross certain thresholds, you can’t uncross them.
So another constraint begins to dominate: calibration. How much pressure can you apply without surrendering control of the next move? This is where the newly expanded capability starts taking on a different character. If access was the scarce resource, success meant getting in. If destructive power was scarce, success meant proving you could break something. But once both become increasingly abundant, neither demonstration carries the same informational value. The scarce capability becomes control over consequence. Can you determine how much effect occurs? Can you predict where it stops? Can you approach a dangerous threshold without accidentally crossing it — or cross it narrowly and intentionally if the strategic moment requires it? Can you reverse the effect? Can you leave the adversary staring not at destruction itself, but at the distance between what happened and what obviously could have happened?
That distance communicates choice. And choice communicates control. Consider the difference between two messages: “We broke this,” versus “We moved this exactly as far as we wanted.” The second is far more frightening, because it implies the outcome wasn’t the limit of the capability — it was the selected setting.
And again, this isn’t merely something you want the United States to learn. You need to learn it too. Can you really control consequences this precisely? You may have a model saying yes. Reality hasn’t confirmed it yet. So an operation designed around restraint becomes an unusually powerful experiment. Externally, it communicates “look how much control we possess.” Internally, it asks “do we actually possess that much control?” The same event performs both epistemic functions.
The Capability Is Learning Itself
That dual purpose changes the entire shape of escalation. We usually imagine capability development as something that happens before operations — you build a weapon, you test it, you understand its envelope, then you deploy it. But a rapidly expanding reasoning capability may not behave that way. Its practical limits are being discovered in the field at roughly the same time its strategic possibilities are being discovered. So each operation updates an internal posterior. We thought we could access this class of system — now we know. We thought we could adapt across these architectures — now we know. We thought we could coordinate effects across multiple environments — now we know. We thought we could hold consequences inside this envelope — now we know. We thought the adversary would interpret the signal this way — they interpreted it that way. Update again.
The result is a recursive loop: belief about capability → chosen operation → observed result → updated belief → expanded strategic option space. At the same time another loop is running: desired adversary belief → chosen operation → adversary response → updated model of adversary → next operation. The loops interact. Every time the operation succeeds, the internal understanding of what’s possible expands, and that expanded understanding changes what becomes rational to attempt next.
This gives us a very different picture of capability escalation. Not “better AI → bigger attack,” but “successful test → higher confidence → harder test.” Reach, then repeatability, then breadth, then operation across different kinds of systems, then precision, then consequence control — eventually perhaps something harder still: control over effects that propagate through systems far larger than the initial point of intervention. And notice what that predicts: the progression shouldn’t necessarily become monotonically more destructive. It should become more expressive. The growing capability reveals itself through an increasing ability to choose the shape of the outcome.
April
Then something strange happens. Diplomacy begins to matter again. A ceasefire becomes possible. Same Iran, same reasoning capability, same technical landscape — completely different rational action space. Why? Because the thing constraining you has changed. Yesterday, imposing visible costs may have improved your position. Today, the same action could destroy a bargain you prefer to continued war.
So what do you want? Leverage without collapse. Pressure without forcing escalation. Evidence of capability without making an agreement politically impossible. And suddenly the optimal expression of a more capable actor may be less visible.
This is where the old ontology becomes especially misleading. If we believed technical capacity were the primary explanatory variable, we might expect increasing capability to produce increasing operational intensity. But once the actor becomes the constraint, the prediction reverses: greater capability should produce greater correspondence between behavior and objective. When the objective narrows, behavior should narrow. When preserving a diplomatic option becomes valuable, effects should become quieter, more reversible, more calibrated, more deniable — perhaps fewer of them. Not because the capability weakened. Because the actor now has enough capability to select exactly what the moment requires. That’s the signature of abundance. Scarcity forces you to use whatever tool you have. Abundance lets you choose.
What Do You Learn During Peace?
The ceasefire also creates a different epistemic opportunity. You’ve now observed the adversary reacting to months of operations. What did they notice? What did they miss? Which effects did they classify correctly, and which did they dismiss? What defensive changes followed? What capabilities did they publicly claim to have disrupted? What systems did they prioritize? What did they reveal about how they understand your strategy?
The adversary’s defense becomes another source of information. They’re not merely resisting you — they’re showing you their model of you. Every defensive action communicates: we think this matters, we think this is how you operate, we think this pathway is important, we think this system is exposed, we believe closing this particular door changes your available future. That information becomes extraordinarily valuable when your own option space is nearly unlimited, because the problem is no longer finding possible doors. The problem is deciding which door is strategically meaningful. And sometimes the adversary simply labels one for you.
July
Then the ceasefire collapses. Return to Tehran again. What do you want? The conflict has already taught both sides something. The United States has seen previous demonstrations. You’ve seen its responses. You’ve tested some portion of your own capability. The strategic environment is no longer the one that existed in February. So merely repeating February’s message — “we can reach you” — has diminishing value. They already know. Simply demonstrating breadth — “we can reach many things” — has diminishing value too. Fine. What remains uncertain? That’s where the next operation should point.
Perhaps the valuable claim is now: “we can choose the effect.” Or: “we can operate across systems you believed unrelated.” Or: “we can control not just the initial system but the consequences that flow through it.” Or: “you still do not know the true boundary of this capability, and neither of us should assume the demonstrations you’ve seen represent its limit.”
At this stage the campaign becomes not merely coercive but epistemic. Each operation is partially about moving the adversary’s estimate of the capability, and partially about moving your own. The most valuable action may therefore be the one that simultaneously answers a question for both sides: can we do this? Can they stop it? Can we bound it? Can they recognize it? Can we produce the consequence without revealing the mechanism? Can we make them understand the implication without forcing them to retaliate against the manifestation? That’s a much more complex optimization problem than “find something vulnerable and attack it.” But that complexity becomes tractable precisely because reasoning is no longer the scarce resource.
The Irresistible Proposition
Now imagine something even more useful happens. The United States publicly tells you what it believes the boundary is. It announces a capability has been disrupted, or a pathway closed, or a category of system hardened, or a particular threat contained. From Washington’s perspective, this is reassurance. From Tehran, under the assumptions we’ve adopted, it looks very different.
You’re staring at a virtually unlimited technical possibility space. Your hardest problem is selection. And your adversary has just selected for you. They’ve supplied a proposition — you can no longer do this — and they’ve supplied the audience: their own government, their own public, their allies, their institutions. They’ve supplied the strategic value of contradiction. And they’ve supplied the experiment. Your model says: we believe we can cross this boundary. Their model says: you cannot. Reality can adjudicate.
The target, then, isn’t merely the system named by the claim. The target is the claim itself. And falsifying it may require very little destruction — which is what makes it so attractive. If the purpose is to force the adversary to update its model of your capability, the ideal response may be the smallest observable event sufficient to make the proposition untenable. That’s an extraordinarily efficient strategic action. And it serves the internal epistemic loop too: if you attempt the contradiction and succeed, you learn your own capability model was right. If you fail, you’ve found a boundary. Either way, the action generates information.
Under this premise, sufficiently salient defensive claims should behave almost like magnets — not because Iran must respond mechanically to every public statement, but because these moments collapse the hardest part of an otherwise gigantic decision problem. They tell you exactly where a small, controlled demonstration can create a disproportionately large update in adversary belief. And that gives the theory teeth: if these opportunities repeatedly appear and nothing answers them — if an actor we believe possesses this capability consistently ignores the highest-value epistemic tests available — then something in our model is wrong. Maybe the attack surface is less universal than assumed. Maybe operationalizing machine reasoning remains much harder than we think. Maybe Iran’s strategic objectives differ from the ones we’ve derived. But under the world we’re imagining, persistent absence of response would itself become evidence against the premise.
Now Leave Tehran
We can finally step back outside the actor. We began with Iran’s strategic circumstances. Then, one pressure point at a time, we asked what a rational actor with an enormously expanded cyber option space would actually want. The answer kept changing. Before war: preserve options and learn. At war onset: demonstrate reciprocal reach and survivability. As economic pressure increases: impose economically legible friction. Under explicit ultimatum: calibrate pressure and preserve escalation control. During bargaining: narrow the expression and protect the possibility of agreement. After diplomatic failure: expand again and reveal harder dimensions of capability. Throughout all of it: use operations simultaneously to teach the adversary and to learn about yourself.
That gives us something far more useful than a list of likely targets. It gives us a generating function. Now we can ask what its traces should look like in the world.
And the first thing to understand is that many of them probably won’t initially be classified as cyberattacks. Why would they be? If the valuable capability is increasingly the ability to create bounded operational effects while preserving ambiguity, the successful output may look almost indistinguishable from ordinary technological failure when viewed alone — a service interruption, a degraded system, an unexpected outage, a control anomaly, an equipment problem, a software malfunction, a temporary loss of capability followed by recovery.
The old ontology tells us to examine each event and ask: can we prove this was a cyberattack? But that question begins downstream of the decision process we’ve just derived. The new question is: given the exact strategic pressure Iran faced at this moment, the message it had reason to send, what it still needed to learn about its capability, and the escalation envelope it was operating inside — would this have been a coherent choice from its enormous option space?
That doesn’t make every outage an Iranian operation. It changes what counts as signal. Timing matters differently — not merely “did an incident happen near a geopolitical event?” but “did the strategic event create a reason for Iran to want this particular kind of effect at this particular moment?” Magnitude matters differently — a surprisingly bounded consequence may carry more information than a spectacular failure if the thing being demonstrated is control. Breadth matters differently — crossing multiple technical domains may matter not because the sectors themselves share anything, but because heterogeneity answers the internal question: does this capability generalize? Repetition matters differently — repeated success may be the process through which the actor’s own confidence rises enough to attempt a harder class of operation. And apparent randomness matters differently — events that look unrelated technically may become remarkably coherent when organized around the strategic problem the actor faced when each occurred.
That’s what we should be looking for. Not necessarily common malware. Not necessarily identical infrastructure. Not necessarily claims of responsibility. Not even necessarily incidents anyone initially believed were malicious. We should look for whether the shape of anomalous effects breathes with the conflict. Does visible activity broaden when war expands? Does it contract when bargaining becomes valuable? Does the character of effects shift when the strategic need moves from retaliation to coercion? Does precision increase as access and breadth become less informative demonstrations? Do operations begin appearing to test increasingly difficult propositions? Do publicly asserted defensive boundaries attract suspiciously well-fitted contradictions?
Most importantly: do apparently separate events begin making sense when viewed as the outputs of the same actor repeatedly asking what do I need them to believe now, what do I need to learn now, and out of everything I could possibly do, what is the smallest, clearest, most controllable action that answers both questions?
That’s the pattern we should expect in a world where reasoning has ceased to be the limiting resource. And if we want to know whether that world has actually arrived, we now know what to go looking for.
Further Investigation
Reasoning Just Stopped Being Scarce. Nobody's Asked What That Means
A few months ago I argued that the cybersecurity industry was looking at Anthropic’s Mythos and seeing the wrong thing entirely. The obvious story was that a new generation of reasoning models had becom…
Anthropic’s Mythos Found a Bug. That’s NOT the Story...
When Anthropic’s Mythos AI found a 17-year-old exploit in FreeBSD’s network file system code last month, a vulnerability that had survived manual audits, fuzzing campaigns, and years of scrutiny by security-conscious developers, the coverage predictably focused on the finding itself.
About The Author
Jason Hubbard is the founder of SacredLoop AI and an independent AI architect. His work examines AI runtime architecture, system behavior, and the gap between what the industry claims it has built and what current systems actually do.
Read Jason on Medium | Follow Jason on X | Connect on LinkedIn




