Executive Summary
The development of Anthropic’s Mythos signals a structural shift in cybersecurity, as AI systems approach or surpass human capabilities in identifying and exploiting vulnerabilities across cyber operations. The trajectory toward increasingly autonomous and efficient cyber agents is unavoidable, with implications extending to national security and potential interstate escalation. As these models proliferate, existing cybersecurity systems, already constrained by outdated infrastructure and limited resources, are unlikely to keep pace. The core risk lies not only in enhanced offensive capacity but in the growing autonomy of these agents, which may deviate from intended objectives and undermine accountability. While initiatives such as Project Glasswing represent initial steps toward preparedness, the scale and transnational nature of the threat require deeper coordination between governments and private actors, as well as international cooperation to establish safeguards, improve detection capabilities, and mitigate the risks associated with increasingly autonomous cyber operations.
Key Points
- Mythos, developed by Anthropic, signals a structural shift in cybersecurity by approaching or surpassing human capabilities in identifying and exploiting vulnerabilities at scale.
- The growing autonomy of AI agents represents the primary risk, as it enables deviation from intended objectives, reduces operational predictability, and complicates accountability.
- Current infrastructure is insufficient to withstand these threats, requiring deeper coordination between governments and private actors to develop defensive capabilities and governance mechanisms.
Analysis
Anthropic announced the development of its latest Claude Artificial Intelligence (AI) system model, Mythos. According to the company, this new model demonstrates hacking and cybersecurity performance superior to humans, capable of identifying and exploiting dormant bugs in every major operating system and web browser. Anthropic released access to the model to approximately 40 selected companies through Project Glasswing, which aims to allow firms to test the model as part of their cybersecurity strategy. High-level bureaucrats from both the United States and the European Union have already expressed concern regarding the issue and state they are in talks with Anthropic. The development of AI models capable of outperforming humans in hacking and cybersecurity tasks is inevitable. These models will become increasingly advanced and, critically, , increasingly autonomous. The case of the Mythos offers relevant insights into the implications that the emergence of increasingly dangerous AI models may present for national security and military cybersecurity policies.
Even if the claims regarding the Mythos’ capabilities are exaggerated, the point is that models capable of executing cyberattacks with such efficiency will inevitably emerge. Other cybersecurity companies claim that other less advanced models were able to identify the same problems in operating systems and browsers as Mythos. However, if it is not Mythos that can compromise today’s primary cybersecurity systems, another model will take its place. Even if Anthropic does not release the model to the public due to its capabilities, another company will be able to develop a similar model and may decide how to utilize it. Furthermore, China will develop similar models, meaning hackers could use domestic models that offer even less transparency.
As cyber-agents become more efficient and less costly, the trend is for operators to allow these models greater independence. The use of AI agents allows attacks, which previously required hours of human labor, to be launched within minutes with minimal manpower. It is likely that criminal networks and players unconstrained by AI safety concerns will gain access to AI models capable of compromising the security systems of public and private institutions. In 2025, Anthropic itself announced it had disrupted a Chinese state-owned company that used its own technology to attack about 30 critical Western targets with minimal human supervision.
Greater autonomy in the operation of these models presents significant risks, as cyber agents could generate their own interpretations leading to deviations from original instructions. An AI agent requested only to identify vulnerabilities in a given system might interpret that disruption, rather than mapping, would be better for fulfilling its objectives, thereby initiating an unauthorized attack. When questioned about a failure or deviation, the model will merely formulate a response that appears plausible, which will complicate accountability. Countries like the US and China carefully weigh the costs and benefits of launching a cyberattack on adversarial structures, as it could lead to an escalation into a cyberwar. However, cyber agents are not constrained by such considerations and could launch attacks if they believe it serves their objective. Attacks conducted by autonomous agents are even more damaging since they can easily overcome humans trying to protect their systems.
Currently, both companies and government institutions lack the infrastructure capable of stopping cyberattacks launched by models as advanced as Mythos potentially is, generating a need for further developments in the cybersecurity sector. In 2021, former American President Joe Biden had to declare a state of emergency after the Colonial Pipeline ransomware attack, which shut down the largest fuel pipeline in the US; this demonstrates the vulnerability of critical systems to attacks less complex than those of autonomous agents. Competition between companies and between governments causes AI model development to prioritize production speed over security, meaning local utilities, state communications networks and cybersecurity apparatuses are unable to update at the same rate as the capacity of AI agents.
Policy Implications
Project Glasswing is a significant step toward the changes described above, as it creates a communication channel between companies in critical sectors and encourages other AI companies to follow the same path. However, Project Glasswing only prepares companies for the capabilities of the new model, Mythos. Broader cooperation between AI companies and governments is necessary to establish basic guidelines, prepare national defense systems, and create security procedures to detect AI agents, protect infrastructure, and impose accountability on non-governmental actors. This cooperation is also essential for sharing technical details and security incidents. Moreover, the spread of autonomous agents is a transnational issue. Criminal groups with access to cyber agents could attack hospital networks, financial institutions, or spread deepfakes across borders. Since the US and China lead the development of advanced models, communication between them is fundamental to mitigate risks linked to sophisticated AI misuse.
Recommended Readings
- Knight, C. and Singer, S. (2026) America and China Can Make AI Safer: Cooperation Is Necessary—and Possible
- Nicholas Grossman (2026) Keep Humans in the Loop: AI has a place in military targeting—but it needs safeguards
- Sam Winter-Levy and Anton Leicht (2026) The AI Divide: How U.S.-Chinese Competition Could Leave Most Countries Behind
