In the last two weeks, I’ve had the same conversation in three different settings: boardrooms, executive briefings, and a couple of BBQs.

Anthropic’s Mythos model claims to have uncovered significant security vulnerabilities across real systems. The reaction has been consistent: this is a civilisation-level moment, and the right move is to get access – to the model, to the programs around it, and to the partners and organisations who already have it.

The underlying sentiment that something has changed isn’t wrong. The conclusion is.

What Mythos claims to show, translated out of the technical framing, is that its AI can independently, autonomously and systematically search for - and attack - new security vulnerabilities in complex systems that existing threat detection approaches can’t. This is not positioned as faster scanning of known weaknesses, but rather the ability to discover ones that have escaped the attention of humans and machines so far. The technical reality and discussion is, of course, much more complicated and nuanced. Whether Mythos does this as dramatically as claimed, we won’t know until independent results come in.

This capability is not unique to Mythos, or to any frontier model. Small, older, open-source models can do the same thing. The barrier to entry for AI-assisted vulnerability discovery and attack has not just lowered, it has effectively collapsed.

Existing cyber risk frameworks were designed for a different world: linear scanning of known attack patterns and areas, patch cycles measured in days and weeks, perimeter defences that assumed attack was slow, expensive, and required deep expertise. That model is no longer an accurate description of the threat.

What this means in practice is that the threat is no longer concentrated at organisations large or prominent enough to justify the investment a sophisticated attack once required. When the tools become freely available (or close to it), the question of who is at risk changes fundamentally. Any organisation running complex systems and holding sensitive data is now in scope.

The foundations matter more now, not less: understanding what data you hold and where, defence in depth implemented genuinely rather than referenced in a policy document, clear data classification and privacy disciplines, and the right combination of human expertise and technology to protect what matters most.

The way to think about Mythos (and the models from other frontier labs that will no doubt be announced soon) is not vendor access. It is a clear-eyed assessment of whether those foundations are genuinely in place.

Mythos may or may not be the capability leap it claims to be. Independent verification will tell us more. But the discussion it should be triggering – in boardrooms, in executive teams, and yes, at BBQs – is not “how do we get access?” It is “are we actually prepared?”

If you’re working through it, I’d be glad to think it through with you.