This week, the head of the UK’s National Cyber Security Centre stood up at one of the country’s most significant cyber security conferences and told the room, and by extension, every organisation in the UK, to act with “ten times urgency.”
Richard Horne wasn’t announcing a new threat. He was describing one that already exists, accelerating faster than most businesses have registered. At the centre of it is Claude Mythos, a new AI model built by Anthropic that the company considers too capable to release publicly. The NCSC chief called it a warning shot. The question is whether businesses are listening.
What Claude Mythos Is, and Why Anthropic Didn’t Release It
Anthropic builds some of the world’s most advanced AI systems. Mythos, its latest model, is different from anything the company has released before, not because of what it can create, but because of what it can find.
According to Anthropic, Mythos is significantly better at discovering and exploiting security vulnerabilities than any previous AI model. It can do the work of a large security team, at speed, across systems that would take human analysts weeks to assess. That capability is genuinely useful for organisations trying to find and fix their own weaknesses. It is also, in the wrong hands, genuinely dangerous.
So Anthropic made the unusual decision not to release it publicly. Instead, Mythos has been shared with a carefully selected group of technology and financial companies, as well as the UK’s AI Security Institute, which independently tested it and confirmed Anthropic’s assessment of its capabilities.
That decision, a company choosing not to release its own product because it poses too great a risk, is itself worth noting. It signals something has changed in how AI developers are thinking about the technology they’re building.
The Incident That Raised the Stakes Further
On 22 April, the BBC reported that Anthropic is investigating a claim that a small group of people gained access to Mythos without proper authorisation, through a third-party vendor environment. Anthropic confirmed it is investigating the report and says it has no evidence that its own systems were compromised. There is no suggestion that the access was used for malicious purposes.
But the incident, even if it turns out to be limited, illustrates something important. The risk with powerful AI tools isn’t only about what the model itself can do. It’s about whether the organisations and vendors surrounding it maintain the access controls required to keep it contained.
The person involved reportedly already had legitimate access to Anthropic’s systems through contractor work, and is understood to have shared that access with others. That’s a supply chain and credential management problem, not a hack. And it’s exactly the kind of exposure that affects businesses of every size.
What the NCSC’s Chief Actually Said
Horne’s message at CyberUK was not one of panic. It was one of pragmatism, delivered with considerable urgency.
His core argument: AI models like Mythos are not inventing new forms of attack. They are finding existing vulnerabilities in unpatched software, outdated systems, and legacy infrastructure, at a scale and speed that wasn’t previously possible. Organisations that have been slow to apply updates, slow to retire old technology, or slow to address known weaknesses are now exposed in a way they weren’t six months ago.
He was direct about what that means for patching timelines. Applying critical security updates used to be a “day” discipline. Horne said that the window is now compressing to minutes. The gap between a vulnerability being identified and it being actively exploited is shrinking rapidly, and AI is the reason.
He also placed this in a wider context: a “perfect storm” of rapid technological disruption and rising geopolitical tension, with cyber security sitting at the intersection of both. Nation-state threats from Russia and China were named explicitly at the same conference. The Security Minister called on AI firms to work with the government to protect critical networks. The tone throughout was serious.
What This Means for Your Business
The NCSC’s warnings tend to be framed around critical national infrastructure and large enterprises. But the fundamentals Horne described, unpatched systems, obsolete technology, weak access controls, are not enterprise-only problems. They are exactly the issues that affect growing businesses running a mix of old and new technology, or teams where IT maintenance has drifted down the priority list.
If your business relies on software that isn’t being updated promptly, devices running operating systems approaching end of support, or vendor relationships where access permissions haven’t been reviewed recently, the Mythos story is directly relevant to you.
A few things worth acting on now:
- Patch without delay. AI is compressing the window between vulnerability disclosure and exploitation. Treating updates as something to schedule for next week is no longer a reasonable position.
- Review third-party access. The Mythos incident was a vendor access control failure. Know which external parties have access to your systems, what level of access they have, and when those permissions were last reviewed.
- Retire legacy technology. Horne named this explicitly. Old systems that can’t be patched or updated are a fixed target. If you’re running them, you’re carrying a risk that can’t be mitigated by any other means.
- Don’t confuse compliance with readiness. Meeting a framework’s requirements is a baseline, not a guarantee. Cyber Essentials addresses the most common attack vectors, but it needs to be current, not a certificate on the wall from two years ago.
- Make sure your incident response plan reflects third-party risk. If a vendor or contractor with access to your systems is compromised, what happens next? If you don’t have an answer, that’s the gap to close first.
The Basics, Done Properly
Horne’s underlying message, the one that gets lost when headlines focus on the capabilities of AI models, is that the fundamentals of cybersecurity still matter more than anything else. Not because the threat landscape hasn’t changed, but because AI is making it faster and easier to identify where those fundamentals have been neglected.
Businesses that keep their systems up to date, control access carefully, and have a clear plan for when something goes wrong are in a materially stronger position than those that don’t. That has always been true. The difference now is how quickly the gap between the two gets exploited.
If you’re not confident your current security posture reflects the pace at which things are moving, that’s the right moment to get a clearer picture.
FAQs
What is Claude Mythos, and why didn't Anthropic release it publicly?
Claude Mythos is an AI model built by Anthropic that is significantly more capable than previous models at finding and exploiting security vulnerabilities. Anthropic judged it too powerful to release publicly, sharing it instead with a small group of vetted organisations, including the UK’s AI Security Institute, which confirmed its capabilities. The decision not to release it was made on security grounds rather than commercial ones.
What was the unauthorised access incident involving Mythos?
Anthropic is investigating a report that a small group gained access to Mythos through a third-party vendor environment without proper authorisation. The access is believed to have occurred through the misuse of existing contractor permissions rather than a technical breach. Anthropic says it has no evidence of malicious use or that its own systems were compromised. The incident highlights the importance of vendor access controls and third-party risk management.
What should UK businesses do in response to AI-accelerated cyber threats?
The NCSC’s advice is to focus on the fundamentals with renewed urgency: apply security patches promptly, retire or isolate legacy systems that can’t be updated, review third-party access permissions, and ensure incident response plans account for supply chain risk. Cyber Essentials certification remains a sound baseline, but it needs to be maintained and current to be meaningful.



















































