The Guardian view on Anthropic’s Claude Mythos: when AI finds every flaw, who controls the internet? | Editorial

Anthropic’s Claude Mythos can automatically discover and exploit software vulnerabilities, turning them into a systemic threat. The model is kept behind a closed partnership program, but its existence has spurred debate over private firms’ power over internet security and the need for international…

Anthropic, a Silicon Valley AI startup, unveiled its newest model, Claude Mythos, this month. The company announced that the model would not be released to the public, citing the risk that it could turn computers into crime scenes by automatically locating and exploiting previously unknown “zero‑day” vulnerabilities. In effect, Mythos could write code, gain privileged access and chain together weaknesses to seize control of major operating systems and web browsers.

The implications are profound. Imagine a burglar who can target any building, unlock every door, and empty every safe without human intervention. That is the level of autonomy Mythos brings to cyber‑attacks. Anthropic has therefore launched Project Glasswing, a partnership program that names 40 American organisations to help patch the vulnerabilities before malicious actors can use them. The only non‑US partner is the British AI Security Institute, which is allowed to test the model’s frontier capabilities.

How Mythos Works and Why It Matters

Unlike traditional hacking, which requires specialised skills and significant time, Mythos can discover cyber vulnerabilities quickly, cheaply and at scale. Mozilla’s own tests of the model on the Firefox browser revealed ten times more flaws than previous scans, all of which were subsequently fixed. Crucially, none of the defects were ones that a human developer could not spot; the difference lies in speed and volume.

Anthropic has long positioned itself as an ethical alternative to other AI firms, refusing to allow its technology to be used for mass surveillance or autonomous weapons. In February, the Pentagon had labelled the company a “security risk” and cut it off from lucrative contracts, opting instead for OpenAI. Yet the U.S. government has recently welcomed Anthropic back, signalling a shift from treating AI firms as contractors to partners. This move raises deeper questions about whether private companies should wield such powerful tools that can influence critical infrastructure.

International Coordination and the Future of the Internet

Without a global framework for cybersecurity coordination, the risk is that the internet could fragment into a series of competing, self‑patching systems. Each nation or alliance might trust only its own security partners, creating a web of isolated “secure” networks that no longer function as a shared commons. The stakes are high: whoever controls the most advanced AI models will gain a strategic edge over both allies and adversaries.

British ministers have warned that AI is making cyber‑attacks “much easier and faster,” and many businesses are not yet prepared. Banks across Europe are expected to test Mythos soon, following the UK’s cautious approach. Reports of unauthorised access to the model have surfaced this week, raising the question of whether any private entity can be trusted with such capabilities.

Is Mythos a New Threat?

While Mythos does not create a brand‑new type of cyber‑threat, it transforms latent software weaknesses into systemic risks. The model’s ability to chain vulnerabilities together means that a single exploit could cascade across multiple systems, amplifying damage. However, researchers have shown that smaller, cheaper models can achieve similar results when deployed at scale, suggesting that the perceived breakthrough may reflect a broader shift in the field rather than a singular leap.

Anthropic’s public narrative has been shaped as much by its PR as by the technology itself. The company’s image was dented by a $1.5bn piracy settlement last year, yet it continues to promote Claude as an ethical chatbot. The real question is how advanced Mythos truly is and whether its deployment should be limited to a handful of vetted partners.

Next Steps and Unresolved Questions

Anthropic’s partnership with Project Glasswing is still in its early stages, and it remains unclear how many vulnerabilities will be discovered before the model is fully tested. The U.S. government’s decision to re‑engage with the company signals a willingness to collaborate, but it also underscores the tension between national security interests and the need for open, global cybersecurity standards.

As the model’s capabilities become clearer, the debate will likely intensify over the appropriate balance between innovation, regulation, and international cooperation. Until a comprehensive framework is established, the internet risks becoming a patchwork of isolated, self‑contained systems, each guarded by its own set of private security partners.

In the meantime, businesses and governments must prepare for a future where AI can automate the discovery and exploitation of software flaws at unprecedented speed. The question is not whether AI will change cyber‑security, but how society will manage the power it brings.

Why it matters

The emergence of AI models like Claude Mythos signals a shift in cyber‑security, where private firms could control the tools that identify and exploit vulnerabilities, potentially reshaping global internet governance.

Key points

  • Claude Mythos can autonomously find and exploit zero‑day vulnerabilities
  • Project Glasswing partners with 40 U.S. organisations to patch flaws
  • The U.S. government is re‑engaging with Anthropic as a partner
  • AI can discover vulnerabilities faster and at scale than humans
  • Without global coordination, the internet could fragment into isolated secure networks

Frequently asked questions

What is Claude Mythos?

Claude Mythos is an advanced AI model developed by Anthropic that can automatically discover and exploit software vulnerabilities, potentially taking control of operating systems and browsers.

Why is Anthropic keeping Mythos private?

Anthropic believes that releasing the model publicly could turn computers into crime scenes, as it can autonomously find and exploit zero‑day flaws.

What is Project Glasswing?

Project Glasswing is Anthropic’s partnership program that involves 40 American organisations working to patch vulnerabilities before they can be exploited.

Will the U.S. government use Mythos?

The U.S. government has recently welcomed Anthropic back as a partner, indicating a shift from contractor to partner status, but it is unclear how the model will be used.

Reporting drawn from

More from Technology

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com