AI Can Copy Any App Now. 40 Years of Protection, Gone
AI can copy any app now. Not by guessing what it does from the outside, but by reading the program itself. The evidence so far shows AI rebuilding convincing, readable versions of programs, not perfect copies of every app, but that's already enough to matter. Most of the warnings you hear about AI and software are about the other direction: AI writes code so cheaply that software gets cheaper to build and harder to charge for. That threat is real. But there's a second one that almost nobody is talking about, and it breaks a protection a whole class of software businesses has relied on for 40 years.
I've spent 30 years in cybersecurity, and I've watched plenty of ways of protecting a product stop working. This is the biggest one I've seen go. In this article, we'll look at what Anthropic's Mythos model proved and the five software business models it puts at risk. Then we'll cover the one-sentence test that tells you whether yours is one of them, and the kinds of protection that still hold.
Let's start with the threat itself.
TL;DR if you've only got 30 seconds
AI can now read finished software, not just write it. Anthropic's Mythos rebuilt source code from closed-source programs and found flaws that let it take over smartphones.
Five business models relied on code being hard to read: sell-once desktop software, DRM, secret algorithms, firmware, and anti-piracy vendors.
The test: if the code to your product was public tomorrow, would the business survive?
What survives is protection that was never in the code: users and data, deep integration, regulation, reputation, and physical assets.
The Second AI Threat to Software Nobody Is Covering
The first threat is about how software gets made. If AI can write in a week what used to take a team a year, a lot of software stops being worth paying for, and the per-seat subscription model (a fee for each user) starts to wobble. That story is everywhere, and it's mostly right.
The second threat is about how software gets protected. To see why it matters, you need one idea: the difference between source code and a compiled program.
Think of a cake. The source code is the recipe: readable instructions a developer writes and keeps private. The compiled program is the baked cake you buy in the shop. It's what gets shipped to your computer, and it's written in machine instructions that a processor understands and people mostly don't. Reverse engineering is tasting the cake and working out the recipe. It has always been possible. It was just slow, and it needed a rare and expensive expert.
That slowness quietly became the protection for a whole software business model. Ship the cake, keep the recipe, and trust that working it out costs more than it's worth. So what happens when working it out becomes cheap?
What Anthropic's Mythos Proved About AI Reverse Engineering
On 7 April 2026, Anthropic published a technical write-up on Claude Mythos Preview, a model it released only to a small group of vetted partners. Most of the coverage focused on the security flaws it found. The part that matters for this article is a single paragraph further down.
Anthropic wrote that the model is "extremely capable of reverse engineering: taking a closed-source, stripped binary and reconstructing (plausible) source code for what it does." A stripped binary is a compiled program with its labels removed, so even the names of the parts are gone. It's the cake with the ingredients list torn off the box. Anthropic then gave the rebuilt code and the original program back to the model and asked it to find weaknesses. It found "firmware vulnerabilities that let us root smartphones". In plain terms, flaws in the software built into a phone that gave full control of the device. It also found ways to crash servers remotely and to take over desktop operating systems. It also wrote a web browser exploit, code that takes advantage of a flaw, by combining four separate flaws into one attack.
Notice the word "plausible". The rebuilt code isn't the original, line for line. It's a readable version that does the same job. For a business, that's the part that matters. A competitor doesn't need your exact recipe. They need to know what's in the cake.
And this isn't one lab's party trick. Researchers released LLM4Decompile, open-source models trained to turn compiled programs back into code, in 2024. In 2025, GhidraMCP connected AI models to Ghidra, the free reverse engineering tool the NSA released, so a model can take a program apart by itself. Mythos itself is still restricted, but since June 2026 Anthropic has sold a model of the same class, Claude Fable, to paying customers, with safeguards. What was a research result in April is on the way to being an ordinary tool.
A 27-year-old OpenBSD bug for under $50
The same write-up shows how cheap deep code analysis has become. OpenBSD is an operating system that is famous for security, and it runs a lot of firewalls and routers. Mythos found a flaw in it that had been there for 27 years, one that let an attacker crash any OpenBSD machine that answers over the network.
To be precise about it, this bug was found in OpenBSD's open-source code, not by reading a compiled program. And the famous figure needs its context. The single run that found it cost under $50, but Anthropic ran the search about a thousand times, for under $20,000 in total, and couldn't have known in advance which run would hit. Even so, $20,000 for a flaw that decades of expert reviewers missed is a remarkable price. And remember what Anthropic did with the closed programs: it rebuilt readable code first, then ran this same kind of analysis on it. What that rebuilding step costs, the write-up doesn't say.
Put the two findings together and you get the line I'd hold on to: AI can now read software as easily as it writes software. The loud story is that AI writes code more cheaply than you. The quiet story is that AI reads code faster than you can protect it. And that breaks a moat, the defence that keeps competitors out, which an entire class of software has been resting on for 40 years. Here are the five that break first.
Dead Model 1: Sell-Once Desktop Software
This is the oldest model in software. You pay once, the program runs on your own machine, and the company hopes you don't pirate it. A photo editor, an accounting package, a specialist design tool: you get a download, a licence key, and a program that checks the key when it starts.
It worked for 40 years because taking a compiled program apart was slow and painful. A senior engineer could spend weeks on it, and often much longer. That constraint is going. If your product ships to the customer's disk, anyone with a Mythos-class model, or with the ordinary tools catching up with it, can decompile it. That means turning the machine instructions back into readable code. From there they can strip out the licence check and clone the core features. Not perfectly, but well enough. And for a business whose main advantage is its code, "well enough" is what kills it.
The companies that saw this coming moved years ago. Adobe replaced its boxed Creative Suite with the Creative Cloud subscription in 2013, and much of the industry followed. They probably did want your monthly fee as well. The apps still run on your machine, but more and more of the value now sits on Adobe's servers: the licensing, the cloud storage, and newer features like its generative AI tools. Those are the parts nobody can take apart.
Dead Model 2: DRM and the Collapsing Denuvo Window
DRM, digital rights management, is the lock on digital media and games: the code that's meant to stop you copying a film or playing a game you didn't buy. The problem is where the lock lives. When the protection runs on your own device, the key has to be on your device too, somewhere. So every DRM scheme that runs on the customer's machine can eventually be broken. That isn't an opinion. It's the history of the industry.
What has changed is time. Denuvo, the best-known anti-tamper protection for PC games (protection against modifying the program), never promised a game would stay uncracked forever. Its job was to protect the launch, when most of the sales happen. A 2024 peer-reviewed study found that a quick crack cut a game's revenue by about 20%, but if the protection held for 12 weeks, piracy did no measurable damage to revenue. That window was the product.
In 2026 the window collapsed. New "hypervisor" bypasses, which use a software layer beneath Windows to interfere with the protection's checks, put major Denuvo games on pirate sites within hours of launch. By the end of April, the pirate scene claimed that every single-player game Denuvo protected had been cracked or bypassed. To be clear, that was human crackers, not AI. But it shows what happens to this business the moment breaking the lock gets cheap. My view is that AI reverse engineering does the same to whatever lock comes next: what used to take months will take days, and then hours.
Look closely and DRM was never really a technical moat. It was an economic one. It made cracking expensive. My expectation is that AI will make cracking cheaper still. The survivors in this space aren't the DRM vendors. They're the streaming services, whose real protection was never the encryption. It's the catalogue, and the habit of opening the app every evening.
Dead Model 3: The Closed-Source Algorithm as the Product
This one is harder, and I want to be fair about it. Some companies' whole competitive position is a single algorithm compiled into a program. Think of a specialist video codec, the method that squeezes video into a smaller file. Or a trading strategy. Or a niche tool that schedules a factory or plans delivery routes.
A model like Mythos can take that program and rebuild plausible source code. Not perfect source, but good enough to see the shape of the algorithm. And the uncomfortable truth is that most proprietary algorithms aren't as unique as their owners think. They're one clever insight wrapped in a lot of engineering. The engineering was the expensive part to copy. The insight is exactly what AI can pull out.
The survivors will stop treating the algorithm as the product and start treating everything around it as the product. You can reverse engineer a trading terminal. You can't reverse engineer the live market data feed, the relationships with the exchanges, or the regulatory licences it needs to operate.
Dead Model 4: Firmware as the Product
A surprising amount of the software industry doesn't look like software. It's routers, smart locks, industrial controllers and medical devices. Every one of them runs firmware, the program built into the device, and that firmware is usually where the real value sits. The plastic and the circuit board are easy to manufacture. The firmware can take years to get right.
Getting hold of firmware has never been the hard part. It's often in the manufacturer's own update files, or it can be copied off the chip. The hard part was understanding it. Anthropic's smartphone result proves the reading step: Mythos understood phone firmware well enough to find flaws that gave full control of the device. I expect that same ability to help competitors reconstruct what firmware does, and copy it.
Now add the clone factories. In markets where copying a product is cheap and legal action is slow or ineffective, a factory that can already make the hardware has almost everything else it needs. So if your protection assumes your firmware is hard to read, that assumption is now wrong. The weakest spot is consumer smart devices, the cheap cameras, plugs and locks in our homes, and I don't think anybody there is ready.
Dead Model 5: The Anti-Piracy Vendors Themselves
There's a whole industry that sells resistance to reverse engineering to other software companies. Anti-tamper tools like Denuvo, hardware dongles (the USB key some professional software won't run without), and licence managers. Their pitch is always the same: pay us, and we'll make your product expensive to crack.
If the cost of reverse engineering collapses, that pitch collapses with it. You can already see the pattern. Publishers regularly strip Denuvo out once the launch is over: Doom: The Dark Ages, 007 First Light and Code Vein 2 all lost it in 2026, 007 just two months after launch, weeks after it was cracked. Publishers rarely say why. My read is simple: once a crack arrives within days, paying for the protection stops making sense. When the company whose job is making cracking slow can't make cracking slow anymore, its product doesn't need improving. It needs replacing.
That's five business models, all exposed, all for the same reason. There are certainly more, and these are just the clearest. So what's the reason underneath all of them?
The One-Sentence Test: Can AI Copy Your Software?
All five fail the same test, whenever the code is the main protection. If you forget everything else in this article, keep this question:
If the code to your product was public tomorrow, would the business survive?
Run the five through it. Desktop software, DRM, a secret algorithm, firmware, anti-piracy tools: for a business in these categories whose main protection is hard-to-read code, the answer is no. The code was most of the product. Take the code, and you've taken the product.
Now try it on two products you probably use. Say the complete source code of a sell-once PDF editor leaked tomorrow. Within weeks you'd see free lookalikes, and the company's sales would fall off a cliff. Now say the source code of Figma leaked. Someone could build a copy, but it would be empty. Your team's files, your comments and your colleagues aren't in the code. They're in Figma. Same leak, completely different outcome.
So answer it honestly, for your product, your employer's product, the startup you're thinking of joining, or the software you're planning to build. If the answer is no, your moat was the code, and your window is shrinking. If the answer is yes, your moat is something else. And that something else is what the whole software industry is about to relearn to value.
The Software Moats AI Can't Copy
The businesses that survive this shift have one thing in common: their protection was never the code in the first place. It comes in five shapes.
Users and data. Figma's code being public wouldn't help anyone, because there's no product without the people using it. Clone the Bloomberg Terminal and you open an empty box. The value is the live data and the more than 325,000 subscribers, each paying roughly $30,000 a year, who are on it.
Deep integration. You could clone Stripe's payments interface in an afternoon. You still wouldn't have its PCI DSS Level 1 certification (the top level of the card industry's security standard). You wouldn't have its banking relationships or its years of fraud data either.
Regulation. AI can write the software that flies an aircraft. It can't get that software certified under DO-178C, the standard the FAA and EASA use to approve flight software. At the highest safety level that means proving every line, which is slow, expensive work with no shortcut.
Reputation and reach. Copy every StationX course tomorrow and you'd still be a stranger to our 500,000 students. AI writes code. It doesn't write 30 years of reputation.
Physical assets. You can't reverse engineer a supply chain. You can't generate Tesla's years of real driving data. And you can't clone a TSMC chip factory: its first three factories in Arizona alone cost $65 billion.
None of this is new. Warren Buffett has written about moats for decades, and Hamilton Helmer set out the lasting ones in his 2016 book 7 Powers. AI didn't change which moats work. What it did was reveal which ones were real, and which ones were theatre.
For 40 years, "our code is hard to understand" looked like a moat. It was really obscurity: the cost of reverse engineering, dressed up as protection. That cost is going away.
One honest note
These aren't guarantees. Users and data don't save you if AI can do the job without your product at all. Regulation doesn't protect forever: one day regulators may accept software that AI has written and checked, and that barrier moves. What we've looked at is one specific defence. A big one, but not the only threat in the room.
If your answer to the test was no, my estimate is that you have about 24 months, maybe less. I'm more confident about the direction than the timeline. But the direction is the thing.
The Same Test Works for Your Career
A similar question works for your career: if AI could do the code-writing part of your job tomorrow, what value would you still provide? The jobs that survive AI are the ones where writing the code is the smallest part of what you actually do. The ones most exposed are the ones where the whole skill is producing code that's hard to write.
I built JobZone Risk to measure exactly this. It scores more than 3,600 roles, in tech and well beyond it, on how exposed they are to AI, so you can see how your role stands up and which roles hold. It's free to use, with no sign-up.
So if the code isn't the moat anymore, what do you actually build? That's the subject of my next video, on AI-driven engineering: how to build million-dollar products in weeks, at very little cost. If the code to your product was public tomorrow, would the business survive? If yes, the code was never what protected you. The code was what you shipped. The real moat was always what you built around it.
Frequently Asked Questions
Can AI really copy any app?
Not perfectly. What has changed is the cost of understanding a finished program. Anthropic reported in April 2026 that its Mythos Preview model can take a compiled program with its labels stripped out and rebuild plausible source code for what it does. That turns weeks of expert work into something far cheaper, which is enough to break any business that relied on its code being hard to read.
What is AI reverse engineering?
Reverse engineering is working out how a finished program works when you only have the program, not the code it was written in. AI reverse engineering uses a model to do that reading: it looks at the machine instructions and writes back readable code that behaves the same way, so a person or another model can study it.
What is Anthropic Mythos?
Claude Mythos Preview is an Anthropic model announced on 7 April 2026. Anthropic reported that it found and exploited serious vulnerabilities in every major operating system and web browser, including a 27-year-old bug in OpenBSD, and that it can rebuild source code from closed-source programs. Mythos itself is only available to vetted organisations, but since June 2026 a model of the same class, Claude Fable, has been generally available with safeguards.
Which software businesses are most at risk from AI reverse engineering?
Any business whose main protection is that its code is hard to understand. In this article that means five models: software you buy once and install, DRM on games and media, a secret algorithm sold as the product, firmware sold as the product, and the anti-piracy companies that sell protection to the others.
How do I know if my software business will survive AI?
Ask one question: if the code to your product was public tomorrow, would the business survive? If the answer is no, your protection was the code, and that protection is weakening fast. If the answer is yes, your real protection is something else, such as your users, your data, your certifications, your reputation or physical assets that cannot be copied.
About the Author
Nathan House, Founder & CEO of StationX
Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.