[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83963-en":3,"doc-seo-83963-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83963,687197207639,"Asher","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","The Oracle’s Gambit: A Game-Theoretic Framework for Responsible AI Release","Responsible vulnerability disclosure normally gives defenders a head start by timing when weaknesses become public, but rapidly improving AI capabilities compress the advantage for both defenders and adversaries. When both sides draw from the same AI model, the critical question shifts from whether to release to how to schedule release. The work models the lab release decision as a bilevel Stackelberg game controlling each side’s capability over time, showing welfare depends on capability gaps rather than shared capability levels, with implications for dual-use model sequencing.","arXiv :2607 .05442v 1 [ cs .GT] 3 Jul 2026  \nThe Oracle’s Gambit: A Game-Theoretic Framework for Responsible AI Release  \nChristoph R. Landolt 1 , Tobias Lorenz 1 , Marta Kwiatkowska2 , Mario Fritz 1  \n1 CISPA Helmholtz Center for Information Security  \n2 Department of Computer Science, University of Oxford  \n[christoph.landolt@cispa.de](christoph.landolt@cispa.de)  \nAbstract. Responsible vulnerability disclosure can secure the defender’s head start by controlling when a vulnerability becomes public. However, this status quo is now challenged by increases in capability of AI models, which benefits both defenders and adversaries. When both sides draw their capability from the same AI model, the defender’s head start depends on the lab’s decision to release the model, and the question becomes not whether to release but how. Existing safety frameworks govern only the deploy-or-withhold threshold and leave the timing of release unmodeled. We cast this decision as a bilevel Stackelberg game in which alab commits to a window that sets each side’s capability over time in a downstream contest between defender and adversary. Defender welfare turns on the capability gap, not the shared level. Handing one model to both sides can trap the defender in a Red Queen’s race, whereas a pre-release to the defender alone creates a protective gap, and the lab’s optimal window balances this welfare gain against the opportunity cost of delaying release. For dual-use models, the lever is the sequencing of access, not the deployment threshold.  \nKeywords: Responsible AI release · Stackelberg security games · Vulnerability disclosure · Stochastic games · Frontier AI safety.  \n1 Introduction  \nWhen a zero-day vulnerability surfaces, the adversary’s path to damage is short: discover the flaw, weaponize it, strike. The defender’s path to safety is longer: discover the same flaw, build a patch, test it, ship it, and wait for the fleet of systems to install it, a rollout that remains slow, costly, and bottlenecked by enduser adoption. This pipeline asymmetry means that, without some compensating defender advantage, the adversary finishes first.  \nResponsible disclosure is the established mechanism for providing that advantage to the defender. Arora et al. [4] formalized the canonical model: a coordinator decides how long to withhold a vulnerability before public disclosure, while the software vendor decides when to ship a patch. The welfare-optimal policy is an interior deadline, long enough for the vendor to patch but short enough to incentivize action, and the 90-day window (with a possible 30-day extension)  \n2 C. R. Landolt et al.  \nbecame the industry norm. The framework succeeds under three conditions: the flaw is not yet independently known to adversaries, patching is faster than independent rediscovery, and reverse-engineering a shipped patch into a working exploit takes long enough for the fleet to update. Together, these conditions mean that responsible disclosure creates a temporary information advantage for the defender, allowing them to ship a patch before exploitation is likely.  \nEach of these conditions is now under pressure from a common source: AI agents can discover the same vulnerability independently and cheaply across actors, dissolving the information advantage that coordinated disclosure was designed to create [17] . Reverse-engineering time from patch to exploit has collapsed from days or weeks to hours [10,16] . And the time to weaponize a known flaw has dropped in tandem, as frontier models have demonstrated the ability to exploit real one-day vulnerabilities autonomously [17,38,40,41] .  \nThese dynamics shift the disclosure decision upstream, to the laboratories that build frontier models and decide how to release them. OpenAI’s Preparedness Framework [28], Anthropic’s Responsible Scaling Policy [3], and Google DeepMind’s Frontier Safety Framework [14] each define capability thresholds at which deployment requires additional safe","cbCaiqNaz11Tdp2K","https://ap.wps.com/l/cbCaiqNaz11Tdp2K","pdf",941421,2,1,20,"English","en",105,"# Introduction\n## Background: Responsible disclosure and deadline norms\n## Pressure from AI capabilities on disclosure advantage\n## Upstream release decisions in frontier safety frameworks\n## Proposed model: bilevel Stackelberg game and capability gaps\n## Central result overview","[{\"question\":\"Why does responsible vulnerability disclosure need to be reconsidered in the age of frontier AI?\",\"answer\":\"AI models can discover, weaponize, and enable exploitation faster and across multiple actors, collapsing the information advantage responsible disclosure was designed to create.\"},{\"question\":\"What new decision does the framework focus on beyond the deploy-or-withhold threshold?\",\"answer\":\"It targets how to responsibly release a model after it clears a deployment threshold, emphasizing the timing and sequencing of access rather than a binary deployment choice.\"},{\"question\":\"In the proposed game-theoretic model, what determines defender welfare?\",\"answer\":\"Defender welfare depends on the capability gap between defender and adversary over time, not on the shared or symmetric level of capability.\"}]",1784191693,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"the-oracles-gambit-a-game-theoretic-framework-for-responsible-ai-release","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/the-oracles-gambit-a-game-theoretic-framework-for-responsible-ai-release/83963/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why does responsible vulnerability disclosure need to be reconsidered in the age of frontier AI?","Question",{"text":75,"@type":76},"AI models can discover, weaponize, and enable exploitation faster and across multiple actors, collapsing the information advantage responsible disclosure was designed to create.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What new decision does the framework focus on beyond the deploy-or-withhold threshold?",{"text":80,"@type":76},"It targets how to responsibly release a model after it clears a deployment threshold, emphasizing the timing and sequencing of access rather than a binary deployment choice.",{"name":82,"@type":73,"acceptedAnswer":83},"In the proposed game-theoretic model, what determines defender welfare?",{"text":84,"@type":76},"Defender welfare depends on the capability gap between defender and adversary over time, not on the shared or symmetric level of capability.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,126,129,133],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":29,"slug":113},6,"Technology","technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":22,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":22,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":106,"slug":136},19,"General","general"]