Arcanum Technical Director, Lawrie Abercrombie, discusses growing concerns surrounding the capabilities of Claude’s Mythos AI model in the hands of threat actors.
A wave of headlines over the past week has focused on Anthropic’s new Claude Mythos AI, almost all of them leading with the same claim: it is simply too powerful to release into the world.
Until now, the story of AI progress has been fairly predictable. Every few months, we get another version of an AI assistant that promises faster emails, better slide decks or marginally improved coding help. Incremental upgrades, not fundamental change.
Anthropic claims Mythos is different. It is not positioned as an assistant, but as an operator. Based on what has been publicly disclosed, Mythos can autonomously discover and exploit software vulnerabilities at scale, across widely used operating systems and libraries, without step-by-step human direction.
At first glance, that sounds alarming. Used maliciously, models like Mythos could significantly compress the time, skill and effort required to compromise targets. The more dramatic claims suggest it could create asymmetric power, allowing one actor with access to a frontier model to outpace thousands of defenders.
Those same articles usually add, much later, that in the right hands the same capability could improve global cyber defence faster and more comprehensively than anything deployed today.
The obvious question is whether this represents a genuine step change or just very effective marketing.
A growing number of respected voices argue the latter. Gary Marcus has described Mythos as incrementally better rather than revolutionary, pointing out that demo conditions matter and that similar outcomes can already be achieved using combinations of existing tools. Mike Bullock from Palo Alto Networks has made a similar point: Mythos may concentrate and accelerate capability, but it does not invent an entirely new class of attack. Framed this way, the “too dangerous to release” narrative looks less like a warning and more like positioning.
But whether Mythos AI itself is overhyped slightly misses the point.
As Beatrice Nolan reported in an article published on Yahoo, publicly available AI models can already perform sophisticated cyberattack tasks that once required significant expertise. Aisle, an AI security company, has confirmed this by testing smaller, cheaper models against the same types of vulnerabilities highlighted in Anthropic’s announcement and achieving similar analytical results.
AI lowering the barrier for attackers is not a future problem introduced by Mythos; it is a current reality.
What is often overlooked is that AI is already being deployed just as aggressively on the defensive side. NinjaOne launched a platform in March 2026 that integrates real‑time AI vulnerability detection with autonomous patching across Windows and Linux environments. Google’s CodeMender has been independently validated as an AI agent capable of proactively rewriting insecure code patterns and reactively patching new bugs, albeit with human approval before release.
In other words, the AI cyber arms race is already under way.
This has led some commentators to frame AI in cyber security primarily as a governance challenge: who approves its use, who is accountable when it fails and where the guardrails should sit.
Governance matters, but it does not change a fundamental asymmetry. Hostile Nation states and criminal groups do not debate acceptable use policies or wait for ethical consensus. They will adopt any capability that gives them advantage. And they will do it quickly.
In that context, restraint is not a competitive strategy.
The decisive factor in the cyber conflicts that play out daily is not who has the best policy framework or the strongest judgement about when to deploy AI. It is who deploys these capabilities first, integrates them fastest and learns from them quickest.
AI models like Mythos AI may or may not represent a dramatic leap. But they underline a reality that organisations can no longer avoid: the only way to stay ahead in cyber warfare is to put these tools into use early, responsibly but decisively. And then accept that relevance now belongs to those who move faster than their adversaries.
From Mythos AI to Managing Cyber Risk: Get in touch with Arcanum
Looking to improve your organisation’s risk posture in the face of a cyber arms race? We can help. For more information get in touch.
Lawrie Abercrombie is Arcanum’s Chief Consultant. He is a Chartered Cyber Security professional and a Fellow and Board Member of the Chartered Institute of Information Security.