Sources and method
How this research was produced, what it drew on, where the source base is strong, and where it is thin.
Sources are cited inline on every page, where they belong. This page is about method and provenance: how the research was assembled, what its source base looks like, and where the reader should apply extra skepticism.
#How this was produced
Fourteen parallel research passes were run across distinct domains — offensive companies, defensive code security, SOC vendors, benchmarks, open source, open-weight models, post-training methodology, frontier-lab access policy, EU and US regulation, AIxCC, AI cyber labs, buyers and pricing, funding and talent, threat landscape, and training data. Each pass produced a detailed research note; those notes total roughly 100,000 words and sit alongside the site in the project folder.
Two adversarial verification passes were then run against the highest-stakes claims from those notes, with instructions to confirm from primary sources or declare a claim unfound. Those passes are the reason Verification ledger exists, and they materially changed the content: several confidently-stated claims turned out to be false, including a fabricated accusation against a named company and a government institute that does not exist.
The site pages were then written from the corrected notes, with the corrections applied as binding overrides.
A material process caveat. Several research passes ran after the session's web-search budget was exhausted and fell back on directly fetching guessed URLs. That method finds real primary sources when the guess is right and produces confident-sounding nothing when it is wrong. It is the most likely origin of the fabrications the verification pass caught, and the reason claims without an inline URL in this hub should be treated as unconfirmed.
#What the source base looks like
Strong. Primary documents were reachable and were used directly for: frontier-lab policy documents and model cards (Anthropic's RSP, OpenAI's Preparedness Framework and system cards, Google's Frontier Safety Framework and the Gemini 3 Pro model card), UK AISI's published cyber benchmarking, arXiv papers for benchmarks and post-training methods, GitHub repositories for open-source projects and licenses, Hugging Face model and dataset cards, company blogs for funding announcements, and DARPA and team sources for AIxCC.
Adequate. Company funding data, product descriptions, and pricing — largely from company sites and press coverage, with the usual caveat that press-reported deal values are not primary sources. Market sizing from analyst firms, used with explicit warnings about incompatible definitions (Who buys, and what they pay).
Thin, and flagged as such throughout.
| Area | Why it is thin |
|---|---|
| M&A deal values | Confirmed as events; dollar figures could not be pulled from primary sources |
| German legislative status (§202c, NIS2UmsuCG) | Official German sources were unreachable during the research window (Germany: §202c and the Berlin question) |
| Compensation benchmarks | No live survey source was reachable (Talent: the actual constraint) |
| Private valuations for non-public companies | Press-reported only (Who funds this and at what price) |
| Practitioner sentiment and false-positive rates | Survey sources gated; several claimed statistics did not survive verification (Who buys, and what they pay) |
| Internal architectures of commercial products | Mostly undisclosed by design (XBOW) |
#Reading conventions used throughout
- Inline links point at the specific source for a claim. A claim without one is either general knowledge or unconfirmed.
[unverified]marks a claim that a verification pass could not confirm from a primary source. It does not mean false; it means unsupported.[estimate]marks a figure derived by reasoning rather than reported, with the assumptions stated nearby.- Confidence badges on each page describe the evidence base, not the strength of the opinion. A
contestedpage may still carry a firm verdict — Is frontier-lab gating a real wedge? and What AI is actually doing to the threat landscape both do. - Dated phrasing ("as of Aug 2026") is used for anything fast-moving. Undated present tense in this hub should be read as "at the time of writing," which is 29 August 2026.
#The primary research notes
The full underlying notes are bundled with the project as research-notes-bundle.tgz in the project root. They are more detailed than the site pages, contain material that did not make the cut, and also contain the errors the verification pass caught — they have not been corrected. Read them as raw input, not as a second opinion.
| Note | Topic |
|---|---|
| 01 | Offensive AI security companies |
| 02 | Defensive code security and SOC companies |
| 03 | Benchmarks and evaluations |
| 04 | Open-source ecosystem |
| 05 | Open-weight models and datasets |
| 06 | Post-training methodology and cost |
| 07 | Frontier-lab access policy |
| 08 | EU and US regulation |
| 09 | DARPA AIxCC |
| 10 | AI cyber labs as a category |
| 11 | Buyers, budgets and pricing |
| 12 | Funding, investors and talent |
| 13 | Threat landscape |
| 14 | Training and evaluation data |
| 90, 91 | Adversarial verification passes |
#What would strengthen this materially
In rough order of value per hour spent, and expanded in Open questions and the research backlog:
- Primary-source confirmation of German legislative status from counsel, not from press coverage.
- Direct conversations with three or four practitioners in the buyer segment, which would replace most of the weakest evidence in Who buys, and what they pay in an afternoon.
- Re-running the verification passes with a live search budget on the [unverified] claims, particularly the M&A figures and the funding data in Who funds this and at what price.
- Independent reproduction of any benchmark number quoted here, starting with the ones used to justify a strategic conclusion.
#What this means for us
- Treat this hub as a well-organized starting point with known defects, not as diligence. The defects are documented in Verification ledger rather than hidden.
- The single highest-leverage improvement is talking to people. Desk research has been taken about as far as it usefully goes on the demand side.
- When a page's conclusion depends on a thin source, that dependency is stated on the page. If a conclusion matters enough to bet on, trace it back to its citation before betting.