Saudi Airpower Comes Attached
7 stories · ~7 min read

Listen
If You Only Read One Thing
Saudi Arabia can buy more military independence by becoming more dependent on American suppliers. The proposed F-35 sale makes that bargain explicit; Hacktron’s account of accessing OpenAI reveals how connected services can create dependence nobody intended. Both stories turn on what accompanies the product: maintenance and permissions can determine its strategic value long after the purchase or login is complete.
Saudi Arabia Buys a Long Relationship
Washington’s proposed F-35 sale would bind Saudi airpower more closely to American industry for years. The strategic prize is the continuing relationship behind the aircraft: training, maintenance, parts and upgrades keep the supplier involved after delivery.
On September 17, the State Department approved a potential package covering 48 F-35s, 49 engines and supporting equipment, estimated at $24.3 billion. Breaking Defense’s account identifies Lockheed Martin and RTX’s Pratt & Whitney as the aircraft and engine suppliers. Prices and quantities remain negotiable, and Congress has a review period. An authorization is not booked revenue.
The timing matters. September 12’s briefing examined the disruption of Saudi Arabia’s alternative oil-export route. This proposal advances a different response: acquire capability tied to Washington. Unlike September 16’s replenishment story, the demand here comes from a new foreign customer, not replacing American inventories. Neither route supplies an immediate answer to attacks already occurring.
Think of the purchase as joining an operating system for airpower. Buying the machine starts a stream of complementary purchases and training decisions. Replacing the supplier later means replacing much of that surrounding system, too. This is dependence after delivery: the customer gains capability while the supplier gains a relationship that is expensive to unwind.
The strongest objection is that deeper integration also creates exposure for the seller. Representative Raja Krishnamoorthi opposed the sale, citing reported intelligence concerns about Chinese access to sensitive technology through Saudi relationships. His statement establishes congressional opposition; it does not independently prove that technology has leaked. Washington would be accepting a continuing security-management obligation alongside the commercial opportunity.
My medium-confidence investment read favors Lockheed and RTX over three to five years, conditional on an executed agreement. Approved suppliers can capture both production and continuing support demand. This extends the pattern in which political eligibility determines who can sell scarce capability. But demand alone does not guarantee attractive margins: GAO found that all 110 F-35s delivered in 2024 were late, averaging 238 days behind schedule. That historical record is a warning about execution, not a current delivery forecast.
Cancellation would kill the Saudi-specific read; costly delivery problems could defeat its margin logic. The decisive next document is an executed agreement specifying aircraft quantities and delivery commitments.
OpenAI’s Forum Reached the Factory
OpenAI’s newly public intrusion story exposes a business risk in connecting useful services: an ordinary support forum can become a route into internal code repositories. Better models make attacking that route cheaper, but identity and permissions determine how far access travels.
Widely covered on September 17–18, Hacktron’s account displays September 13 and dates the intrusion to July 25. The researchers say they chained a vulnerable image-processing component with an OpenAI sign-in flaw. They then used an affected employee’s connected Codex account to create a harmless pull request in OpenAI’s internal repository. They say they avoided reading sensitive code and reported the access through OpenAI’s bug-bounty program. Demonstrated access is not proven theft.
The economic mechanism is connected authority. A company gives a service permission to act in another system so employees can work without repeatedly signing in or copying information. If that authority survives an account compromise, the attacker inherits the convenience. Here, the valuable asset was the employee account’s existing connection to GitHub.
This is materially different from yesterday’s disclosure analysis, which examined OpenAI’s selection of model-behavior incidents. Today’s evidence comes from outside researchers demonstrating a specific access path. The commercial question shifts from what the lab reports to what the enterprise has authorized its connected products to do.
The cost claim needs care. Hacktron puts token spending below $3,000 for a broader two-month research project involving several companies, not for this intrusion alone. Skilled researchers still guided the work. Those limits weaken the claim that anyone can now compromise a frontier lab; they do not weaken the incentive to automate more of the skilled team’s work.
Over the next 12–24 months, I have medium confidence that this favors security suppliers able to enforce permissions across connected applications. An alert arriving after a valuable action is a weaker product than a control that can prevent it. That fits the standing pattern of value moving toward identity and authoritative access as execution becomes cheaper. It also creates a competitive opening for application vendors to bundle those controls, limiting the pricing power of independent security firms.
The researchers report rapid remediation, so this is not evidence that the same route remains open. The commercial thesis would weaken if customers obtain effective controls within existing subscriptions without additional spending. The concrete operating test is whether a compromised low-trust service can still exercise a connected account’s repository-write permission in a published follow-up assessment.
The Contrarian Take
Everyone says: More powerful AI makes the security advantage belong to whoever has the best model.
Here’s why that’s incomplete: Hacktron’s evidence puts considerable weight on the permissions already attached to the compromised account. Improving an attacker’s reasoning increases the chance of finding a route; it does not itself determine what the destination allows. A defender that restricts inherited authority can limit damage even while losing the model race. The economic competition therefore includes the mundane control layer that decides which actions are possible, with no guarantee that the frontier-model vendor captures that spending.
Under the Radar
-
Britain is ending a balance-sheet era. The Bank of England held its rate at 3.75% by a 6–3 vote, but unanimously agreed to unwind its remaining £368 billion monetary-policy gilt portfolio by the end of 2034. The minutes specify annual sales of £20 billion alongside maturities. The less obvious consequence is a continuing transfer of government-bond ownership back to private investors. A rate hold does not mean the central bank is preserving its role as a large bondholder.
-
AWS is competing for the first deployment. Amazon’s September 16 onboarding redesign lets most new customers start without a credit card and connects a coding agent to a project through one prompt. Paid projects can pause when they reach a chosen monthly limit. The strategic move is to reduce the configuration burden that lets simpler hosting providers win early customers. Amazon is trying to retain the eventual infrastructure bill while making the initial relationship feel smaller.
Quick Takes
Japan’s cheap funding gets less cheap. The Bank of Japan raised its policy rate by a quarter point to 1.25% on September 18. Beyond the local inflation story, higher yen funding costs reduce the attraction of borrowing in Japan to finance investments elsewhere. That is pressure on a financing strategy, not proof of a sudden unwind; the decision was widely expected. (Source)
Anthropic supplies a number for the automation debate. Claude “leads” 26% of measured AI research and development work, Anthropic says, while no measured subset is fully autonomous. The index weights task categories using estimated person-time. That gives the frontier-pacing debate a proposed monitoring variable, advancing Sunday’s oversight proposal. It does not establish that 26% of scientific progress came from AI. (Source)
The copyright case reaches substitution evidence. Ars reports that newly unsealed arguments from the news plaintiffs cite OpenAI and Microsoft communications about AI products replacing publisher visits. The economic issue is whether a distributor consumes its suppliers’ work while weakening their revenue. Those arguments could affect licensing bargaining power, but a party’s brief and selected internal statements do not constitute a court finding. (Source)
The Thread
The important commitments often sit beside the product being purchased. Saudi Arabia’s aircraft would bring a continuing supplier relationship; OpenAI’s connected account carried authority into a separate business system. Call it the accompanying contract. One is deliberately negotiated and the other is encoded in permissions, but both determine consequences that the headline product description leaves out. The useful distinction is whether those continuing obligations and powers are visible before the relationship expands.
AWS offers a third application. Its simpler entry path aims to turn a small project into a lasting infrastructure customer. The stated spending cap makes one continuing obligation visible: what happens when the project consumes its budget. Ease of entry becomes commercially durable only if the customer can understand the obligations that accumulate afterward. Otherwise, the same integration that attracts a customer can become the reason to limit the relationship.
Predictions
- I predict: By December 31, Anthropic will publish another dated R&D Automation Index observation using the same task basket, or explicitly document a change to that basket. Its stated plan for repeat measurement and frozen task taxonomy makes this a testable commitment. (Confidence: medium; Check by: 2026-12-31)
Coming Next Week
The next question in the defense buildout is how much of an announced order becomes profitable delivery. We’ll follow the contract terms, production capacity and support commitments that separate a larger market from better returns.
2026-09-18 · 03:20 AM ET
Tomorrow morning in your inbox.
Subscribe for free. 10-minute read, every weekday.