AI security has acquired another color, because apparently the industry looked at red, blue, purple, green, orange, and white and decided the paint aisle still had inventory. The useful bit is not the color. It is the operating model. Dark Reading reports that Anthropic invited more than 50 organizations to participate in Project Glasswing to preview Claude Mythos, while the same reporting describes engineers building both defensive and offensive AI security tools. That is the part builders should care about, because a checklist can confirm a policy exists, but it cannot tell you whether your agent chain folds like a lawn chair when the prompt arrives wearing a fake mustache. ## Dark Reading frames yellow teams as engineering work Dark Reading's Nate Nelson reported on July 13, 2026 that in some companies, engineers are building defense and attack tools to test AI's promise for cybersecurity and its threat. That is a subtle but important difference from treating AI security as a quarterly governance ritual performed over stale bagels. The yellow team idea, as presented by Dark Reading, sits close to the implementation layer: model behavior, tool use, automation, and the strange little gaps where systems do exactly what you asked and absolutely not what you meant. Dark Reading also describes a small number of engineering teams developing defenses that organizations will need against AI enabled attackers. Translation, the defensive team has to understand the attacker workflow well enough to build against it, not just admire it from a risk register. Threat intel belongs on Sam's desk, but the AI and ML lesson is blunt: if your product uses models to take actions, summarize data, call tools, or triage alerts, your security testing has to touch those workflows directly. Otherwise you are testing the brochure, not the machine. ## ITLawCo shows why the color wheel is not just corporate finger painting ITLawCo's Nathan Ross Adams wrote on 18/11/2024 that the cybersecurity color wheel includes red, blue, purple, yellow, green, orange, and white teams as parts of an organization's security strategy. The takeaway is not that every company needs a Crayola based reorg by Friday. It is that different security exercises carry different roles, permissions, and responsibilities, especially when the exercise involves building tools that resemble the thing you are trying to defend against. ITLawCo also warns that simulations, tests, and training exercises can carry legal consequences and require legal oversight, robust contracts, and clear delineation of responsibilities. That matters for yellow teams because building offensive AI tooling for defensive learning is productive only when the scope is explicit. A practical yellow team should have a written boundary around what systems it may test, what data it may touch, what logs it must retain, and when escalation happens. The vibe should be lab notebook, not raccoon with root access. ## Axios and arXiv explain the pressure behind the move Axios wrote that it is getting harder to keep up with new AI models, pricing wars, and important advancements, and pointed to American labs releasing systems such as Meta's Muse Spark 1.1 and OpenAI's GPT-5.6 family. That release tempo is not a security footnote. Every new model family, pricing change, and capability bump can shift what is cheap enough to automate, what is reliable enough to operationalize, and what attackers or defenders might attempt next. The research firehose is not slowing down either. arXiv's Artificial Intelligence listing for Monday, 13 July 2026 showed 177 entries overall and 27 new submissions. Most teams will not read all of that before lunch unless lunch is a cry for help. Yellow teams are a response to that reality: instead of waiting for perfect doctrine, builders can create repeatable tests around the actual AI paths they use, then update those tests as models, tools, and assumptions change. ## TalTech reminds us automation has a memory A 2021 doctoral thesis from Tallinn University of Technology by Mauno Pihelgas was titled Automating Defences against Cyber Operations in Computer Networks. The thesis was accepted for the degree of Doctor of Philosophy in Computer Science on 10 June 2021, according to the document. That does not make today's yellow team practice a direct descendant of any one academic project, but it does show that automating cyber defense is not a brand new fever dream discovered by a vendor keynote. The new wrinkle is that AI systems are now part of both the defensive machinery and the possible attack surface. For builders, the practical move is to create a loop: model the attacker workflow, implement the defensive control, run the test, log the failure, and feed the result back into engineering. Keep legal scope close, keep product owners in the room, and keep the tests boring enough to run often. Security that only works as a heroic demo is just theater with better hoodies. Project Glasswing's signal is that yellow teams may become a serious AI security discipline because they force organizations to build their way into understanding. Watch for whether this becomes a durable practice with shared methods, or just another org chart sticker. Either way, the lesson for AI builders is immediate: do not wait for compliance to discover your failure mode after your users do. Build the weird little attack lab now, before the weird little attack lab builds itself. ## Sources - Dark Reading: Yellow Teams and AI Security
- The cybersecurity colour wheel
- Automating Defences against Cyber Operations in Computer Networks
- Artificial Intelligence arXiv
- Axios C-Suite: 4 big AI moves - Axios
Sources
- Axios C-Suite: 4 big AI moves - Axios
- 'Yellow Teams' Are Defining the Future of AI Security - Dark Reading
- Exploring the Diverse Roles Within Cybersecurity Teams
- The cybersecurity colour wheel
- Understanding Cybersecurity Teams: Red, Blue, Green, White ...
- Automating Defences against Cyber Operations in Computer ...
- Artificial Intelligence - arXiv
- ArXiv AI Paper Trends: 6.5× More Papers in Seven Years | MoClaw Blog
- arXiv Computer Science (@arxiv_cs@qoto.org) - Qoto Mastodon
- arXiv Computer Science (@arxiv_cs@qoto.org) - Qoto Mastodon
- arXiv Computer Science (@arxiv_cs@qoto.org) - Qoto Mastodon