Claude Mythos: cyber AI under global scrutiny
4 months ago
- UK and US regulators are urgently assessing risks from Claude Mythos.
- Anthropic claims it found 'thousands' of vulnerabilities, but most are not publicly verifiable.
- The model could drastically reduce the cost of vulnerability discovery.
- The issue is becoming systemic, not just technical.
Since early April, a new type of weak signal has emerged in the tech ecosystem. It does not come from benchmarks or funding announcements, but from coordinated reactions by financial regulators to an artificial intelligence model. According to Reuters, UK authorities including the Bank of England and the Financial Conduct Authority have launched urgent discussions with banks and the National Cyber Security Centre to assess the risks posed by Claude Mythos Preview.
The fact that these discussions are happening before any public release marks a shift. Reuters also reports that similar warnings were issued in the United States, involving the Treasury and major Wall Street banks. Cyber AI is no longer just a technical issue: it is becoming a systemic risk topic.
A capability that is hard to verify but credible
Reuters reports that Anthropic claims Claude Mythos Preview identified 'thousands of vulnerabilities' across widely used systems, including operating systems and browsers. The company states that more than 99% of these vulnerabilities remain unpatched, which limits detailed disclosure.
In internal testing, the model reportedly generated 181 working exploits compared to just 2 in the previous generation. On a dataset of 7000 open-source targets, it produced 595 critical crashes and 10 full control-flow takeovers. These figures are not yet independently reproduced, but their internal consistency and the reaction of regulators suggest they are taken seriously.
Another notable example reinforces credibility: according to Business Insider, the model identified a 27-year-old bug in OpenBSD. Such discoveries are rare even for experienced human teams.
A quote that reframes the risk
In the Reuters report, a key point is clearly stated: discussions focus on 'potential vulnerabilities in critical IT systems highlighted by the model'. This wording is important. It links technical capability directly to critical infrastructure risk.
Another important detail: Reuters notes that the information 'could not be immediately verified' and that Anthropic 'did not respond to requests for comment'. This introduces structural uncertainty.
Real promise: helping defenders
Despite concerns, the defensive potential is significant. Reuters reports that Anthropic launched 'Project Glasswing', allowing around 40 critical organizations to use the model in a controlled environment. The goal is to accelerate vulnerability detection and patching.
In a context where security teams are overwhelmed, an AI that automates vulnerability research could significantly reduce remediation delays. This is often overlooked: cybersecurity is limited less by tools than by human capacity to manage complexity.
An economic shift: cost of attack
The core issue is economic. If AI drastically reduces the cost of finding vulnerabilities, it changes the balance between attackers and defenders. A vulnerability that once required weeks of work could be discovered in hours.
According to Business Insider, even non-experts could generate working exploits using the model. This suggests partial democratization of offensive capability.
This explains the rapid reaction from regulators: lowering the marginal cost of attacks can create systemic risks in interconnected sectors like finance.
Bias, communication and strategy
A critical reading must consider source incentives. Anthropic benefits from positioning itself as a responsible actor. Restricting access while highlighting capabilities strengthens credibility with regulators and investors.
According to The Guardian, some experts question whether this is also a strategic communication effort to shape perception around advanced AI.
This does not invalidate the claims, but it requires caution: the capability appears plausible, but its exact scale remains partially opaque.
An uncertain but structuring risk
No major incident linked to Claude Mythos has been publicly documented so far. Risks remain largely prospective. However, the fact that multiple governments and banks are reacting before wide release is itself a significant signal.
The most likely impact is gradual: faster audits, stronger regulatory requirements, adoption of defensive AI tools, but also more complex threats.
The key question remains open: can patching keep up with discovery? If not, technological progress could paradoxically reduce overall security despite better tools.
FAQ
Is Claude Mythos publicly available?
No, it is restricted to selected organizations under Project Glasswing.
Are the capabilities independently verified?
Partially. Most data comes from Anthropic and is not yet fully reproducible publicly.
Why are regulators reacting so quickly?
Because these capabilities could impact critical infrastructure like financial systems and reduce the cost of cyberattacks.