Anthropic’s new AI flagged thousands of security flaws in weeks. The company says the model is too dangerous to give to customers.
What Anthropic announced
Anthropic on Tuesday unveiled a preview of Mythos, a new iteration of its Claude platform, and then, unusually, paused plans to hand it to customers. The company said Mythos was "strikingly capable" at coding tasks — especially those tied to security — and that in just weeks it had identified thousands of vulnerabilities across major operating systems and web browsers. Because the model was also markedly better at exploiting those weaknesses when prompted, Anthropic decided not to roll it out to general users.
That's a blunt move — most tech firms rush to ship improvements, but Anthropic held back this model.
Why the firm held back
Anthropic framed the decision around safety. The company warned that the same advances that make Mythos useful for programmers also make it a potent tool for people with malicious intent. If a user asks the model to find and then weaponise a flaw, Anthropic says Mythos is more able than its predecessors to produce detailed, actionable steps.
Thing is, that dual use is what keeps security researchers awake. The model’s knack for spotting long-unseen bugs — some reportedly present for decades — shows it can surface real, forgotten weaknesses. And once a weakness is known, any machine that can turn knowledge into exploit code becomes a potential weapon.
Who’s behind Anthropic?
Anthropic was founded in 2021 by Dario Amodei and a group of engineers who left OpenAI. Among them was his sister, Daniela Amodei. The split followed a wave of changes at OpenAI, including a $1 billion investment from Microsoft that shifted the firm’s structure and priorities. Dario Amodei has cast Anthropic as an outfit focused on AI safety and research, even as the company built its own large language model, Claude.
Anthropic has leaned into enterprise clients rather than chasing mass-market consumer apps. That business model seems to have paid off: the company raised a substantial round of funding in February, with investors putting roughly $30 billion into the firm and valuing it at about $380 billion, according to the company’s public comments.
Tensions with OpenAI
The Mythos announcement lands amid fresh friction between Anthropic and OpenAI. Anthropic has at times targeted OpenAI in its public messaging — including a Super Bowl spot that mocked the rival for introducing ads. Sam Altman, chief executive of OpenAI, answered with a short essay on X accusing Anthropic of "dishonest and deceptive doublespeak." The exchange highlighted how competitive — and personal — the race for AI leadership has become.
The rivalry matters beyond corporate reputations. When two well-funded firms push capabilities forward quickly, it makes people wonder about oversight and the pace at which potentially dangerous tools reach the public.
What this means for industry and cybersecurity
Mythos demonstrates that the same advances that build useful tools can also create new threats. For companies that build software, a model that spots decades-old bugs could speed patching and reduce risks. For those same firms, however, a model that can write exploit code creates fresh pressure to harden systems and rethink threat models.
Security teams must plan for attackers using AI to speed up finding and building exploits, not just traditional threat actors. That may force organisations to rejig security budgets, move staff around, and change how they prioritise patching.
There’s also an economic side to this. Firms that rely on AI services — from cloud providers to software vendors — may see slower rollouts of powerful models as companies take extra time to vet safety. That could delay efficiency gains businesses hope to get from next-generation tools. It could also increase demand for specialist security auditing services and for models explicitly designed with constraints to limit misuse.
How it touches Europe and Ireland
Anthropic’s customers are mainly businesses, and many European firms are already testing or deploying large language models for coding, customer service and document work. A pause on Mythos therefore matters to European tech buyers weighing different suppliers. Anthropic's pause might push customers to demand clearer safety guarantees and misuse-risk documentation from vendors.
For Ireland, where cloud services and tech multinationals play a big economic role, the episode adds another layer to conversations about digital risk. Irish technology firms and startups that depend on advanced AI for development work could face a choice: wait for a more constrained release, switch providers, or run certain workloads in-house. Any of those options has budget and skills implications.
Irish regulators have been watching AI developments for some time. The Mythos news will give new urgency to debates over how to handle dual-use AI and what kind of standards buyers should demand. It’s a test case: a major AI firm putting containment ahead of competitive advantage.
Policy and political implications
Policymakers will take note; this will shape regulatory conversations about AI risk. Governments that worry about AI misuse now have an example of a private firm proactively restricting access. That could change the tone of regulatory discussions, from calls for harsher limits to arguments for industry-led risk management.
It will probably increase calls for firm, specific rules on risky AI capabilities. If models can find and turn vulnerabilities into working exploits, then national cyber-defence strategies may need to account for AI-augmented attack capabilities. Defence departments, law enforcement and industry partners in Europe will be watching to see whether similar models appear elsewhere and how quickly they spread.
Industry reaction and next steps
Anthropic has signalled it will continue to study Mythos, refine safeguards and limit access while it assesses risk. That path mirrors measures some other firms have taken when confronted with worrisome capabilities — delaying broad release and offering preview access to selected partners under strict terms.
The company hasn’t said when, or even if, Mythos will be made widely available. Instead, Anthropic is trying to buy time to build guardrails.
That’s a tough call for investors and customers who want the latest tools now. But it’s also a statement about how the firm sees its role in a fast-moving field.
Point is: the decision changes the commercial conversation. Customers that had expected a more capable Claude variant will have to adjust plans, while competitors will be judged on how quickly, and how safely, they close any capability gap.
Bottom line: Mythos is real, powerful, and currently boxed in while Anthropic figures out the risks.
Related Articles
Anthropic said Mythos was "strikingly capable" at coding, found thousands of vulnerabilities and won't be released to general users for now.
This article was created with AI assistance.