The UK's AI Security Institute (AISI) evaluated Anthropic's experimental Claude Mythos Preview in April and found that the model could, in test environments, autonomously attack small, weakly defended enterprise systems once network access was obtained. However, the institute stressed that the simulations lacked active defenders and common defensive tooling, and the model was not penalised for triggering alerts. As a result, AISI said it could not conclude whether Mythos Preview would succeed against well-defended systems. ComputerWeekly reported these findings.
Security experts interviewed by ComputerWeekly said the evaluation marks a shift. Rik Ferguson of Forescout noted that before Mythos, no AI model had completed a 32-step simulated corporate attack chain end-to-end; Mythos Preview did so in three out of ten runs, while GPT 5.5 did so in two. He said the capability gap between the two frontier models is narrower than public coverage suggests, but the governance gap is wider.
Chris Atkinson of PA Consulting said the controlled test conditions mean organisations cannot assume the model would overcome active defences. Yet he and others argue that frontier AI now compresses the time between vulnerability discovery, weaponisation and the need for defensive action.
Aditya K Sood of Aryaka said a single adversary can now automate reconnaissance, generate exploit variants, analyse source code, weaponise misconfigurations and adapt social engineering at machine speed. He warned CISOs are no longer dealing only with AI adoption risk but with AI-amplified adversaries that iterate faster than traditional defence cycles.
Atkinson said most vulnerability management processes are built for a manageable number of disclosures, governed by risk assessments and change windows. In the near term, AI will dramatically increase the rate at which vulnerabilities are found, potentially producing hundreds of new vulnerabilities across legacy systems within weeks, exceeding existing change capacity. He argued security failures will increasingly stem not from lack of awareness but from an inability to act quickly on known issues. Frontier AI raises the cost of failing to deliver cyber fundamentals at speed.
Atkinson recommended that CISOs adapt strategies to support patch deployment at speed and scale, especially for internet-facing systems and identity and access management. This requires accurate asset and dependency management, streamlined change governance, and clear ownership of risk decisions when trade-offs are needed. Without these, even the best detection tools or AI-assisted defences will struggle.
Ferguson advised shifting focus toward operational survivability: preserving visibility, constraining attacker manoeuvre space, limiting blast radius and maintaining continuity under stress. Organisations that have already done foundational work on asset inventory, segmentation and exposure-based prioritisation will be able to patch at pace without disruption.
Ferguson said current AI models are capable of exploiting pattern bugs—injection flaws, leaked secrets, known bad dependencies and chaining findings across systems—but remain weakest where correctness depends on intent, such as business logic and authorisation flaws. He also warned that AI coding tools could widen that gap. "Vibe coding" leads to higher development tempo, more dependencies and more confident shipping, expanding the total attack surface even if per-code defect rates stay constant.
Sood said CISOs should assume a critical vulnerability may be weaponised within 24 hours of disclosure, or sooner. He recommended rapid-response security models with pre-positioned playbooks, AI-assisted prioritisation and resilient architectures. His advice to IT leaders: move from planning for known attack patterns to planning for the attacker that frontier models enable.
Ferguson predicted that as models like Mythos become more widely available, disclosed vulnerabilities will spike, and security tool providers will face the question of whether discovery translates into remediation or just a bigger backlog. Without hard blocks for exploitable high-impact issues and firm deadlines, the surge could become the new normal. He said human judgement remains irreplaceable: Vedere Labs already uses Claude Opus 4.6 in research and has reported several zero-days found through that process, aiming to turn faster research into better protection.
ComputerWeekly's feature concludes that advanced AI models capable of coordinating complex cyber attacks are now a reality, and the tech sector is in an arms race. For IT chiefs, Claude Mythos Preview is a wake-up call.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

