Claude Mythos Sparks AI Security Debate
Anthropic recently claimed its new AI model, Claude Mythos, surpasses human performance in certain hacking and cybersecurity activities. This announcement has stirred talks among regulators, lawmakers, and banks about potential threats to online services. A select group of technology leaders gained early access to the model under Project Glasswing, an initiative aimed at building defenses against such advanced AI tools.
Details on Claude Mythos
Claude Mythos forms part of Anthropic's Claude AI system, which includes an assistant and a range of models competing with OpenAI's ChatGPT and Google's Gemini. Anthropic unveiled Mythos Preview in early April. Red-team researchers, who probe AI responses to specific challenges, described it as exceptionally adept at computer security work in their report.
The model identifies long-hidden flaws in outdated code and exploits them with ease. Instead of releasing it broadly to Claude users, Anthropic provided access to 12 major tech firms through Project Glasswing. The company called this a push to protect vital software worldwide.
Participants include Amazon Web Services for cloud services, hardware makers Apple, Microsoft, and Google, plus chip producers Nvidia and Broadcom. Crowdstrike, hit by a faulty update causing a worldwide disruption in July 2024, joined as well. Anthropic extended access to over 40 groups handling essential software.
Growing Concerns Over Capabilities
Anthropic reported that tests showed Mythos excelling in cybersecurity and hacking, beating human experts. "Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser," the firm stated on 7 April. "Given the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely."
The AI spots urgent flaws in legacy systems with minimal supervision. It flagged one issue lingering for 27 years and offered exploitation methods.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
Finance officials voiced worries about risks to banking networks. Canadian Finance Minister François-Philippe Champagne shared with the BBC that Mythos came up at an International Monetary Fund meeting in Washington DC this week. "Certainly it is serious enough to warrant the attention of all the finance ministers," he said, labeling it an "unknown unknown".
Bank of England Governor Andrew Bailey told the BBC, "we are having to look very carefully now what this latest AI development could mean for the risk of cyber crime." The European Union confirmed ongoing talks with Anthropic regarding these issues.
Expert Views and Balanced Perspective
Ciaran Martin, ex-chief of the UK's National Cyber Security Centre, spoke to the BBC this week. He said Mythos uncovering critical flaws faster than prior AIs has alarmed many. "The second thing is that even with existing weaknesses that we know about, but organisations might not have patched against, might not be well defended against, it's just a really good hacker," he added.
Few outside experts have tested it independently, leading some to question the results. The UK's AI Safety Institute assessed it as potent mainly against weak targets. "We cannot say for sure whether Mythos Preview would be able to attack well-defended systems," its researchers noted. Strong defenses should block it, in principle.
AI anxieties persist with each new release, often tied to bold promises of change. Sector marketing frequently plays on these emotions. Details on Mythos remain limited, leaving uncertainty about true threat levels versus buzz.
The National Cyber Security Centre urges calm and emphasis on core defenses. Basic breaches succeed without advanced AI. "For some this is an apocalyptic event, for others it seems to be a lot of hype," Martin told the BBC. Still, he sees potential: "In the medium-term, there's an opportunity to use these tools to fix a lot of the underlying vulnerabilities in the internet."
Anthropic, founded in 2021 by former OpenAI executives including CEO Dario Amodei, prioritizes AI safety. Its Claude models emphasize helpful, honest responses with safeguards against harm.

