Experts Express Doubts About Anthropic’s Latest AI Model

0
26

Key Takeaways

  • Anthropic’s Claude Mythos Preview can discover and exploit cybersecurity vulnerabilities across major operating systems and browsers in seconds, collapsing the traditional timeline from months to near‑instant.
  • U.S. financial regulators (Treasury, Federal Reserve) convened senior bank CEOs to stress the systemic risk posed if such AI capabilities fall into malicious hands.
  • While some experts view the model’s danger as overstated marketing, independent tests show similar vulnerability‑finding ability exists in low‑cost, open‑weight models, indicating a “jagged” frontier of AI cybersecurity skill rather than a smooth scale‑up.
  • Anthropic granted early access to the Mythos preview to a consortium of >40 technology and critical‑infrastructure firms (Project Glasswing), giving defenders a head‑start to patch legacy code before public disclosure.
  • Banks are advised to embed AI system assessments into existing risk‑management frameworks, adopt human‑in‑the‑loop validation, and follow standards such as NIST’s new Cyber AI Profile to mitigate both model‑specific and supply‑chain risks.

Introduction and Regulatory Response
A week after Anthropic announced that its new Claude Mythos Preview model was “too dangerous for the general public,” the initial alarm began to settle among U.S. financial institutions. The model’s arrival does not signal an imminent collapse of the financial system, but it marks an escalation in the ongoing cyber arms race between banks and threat actors. Recognizing the heightened stakes, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell summoned the chief executives of Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs to an urgent meeting. White House National Economic Adviser Kevin Hassett confirmed the session aimed to ensure bank leaders understood the systemic cyber risks posed by the model and took appropriate defensive precautions.

Claude Mythos Preview Capabilities
Anthropic claims the Mythos Preview can identify and exploit weaknesses across every major operating system and web browser, effectively compressing the vulnerability‑discovery timeline from months or years to mere seconds. Outside experts, such as former U.K. National Cyber Security Centre head Ciaran Martin, corroborate that the model enables attackers to find and weaponize flaws in seconds, minutes, or hours rather than days. Martin also notes a silver lining: the same speed offers defenders a “real opportunity” to uncover and remediate hidden internet bugs before they are widely abused.

Expert Skepticism and Marketing Hype
Not all observers share Anthropic’s apocalyptic framing. Alex Stamos of the AI safety startup Corridor dismissed the company’s warnings as a “marketing schtick,” likening the announcement to “if the Manhattan Project announced the nuclear bomb within a cute little Calvin and Hobbes cartoon.” Tech investor Ramez Naam characterized the release on social media as a “relatively normal LLM release, advancing capabilities but not bending the curve.” These critiques suggest that while Mythos is impressive, its peril may be amplified for publicity rather than representing an unprecedented leap in AI‑driven cyber threat capability.

Independent Testing Findings
Cybersecurity firm Aisle conducted independent tests using small, cheap, open‑weight models to replicate the vulnerabilities Anthropic showcased with Mythos. The results indicated that the cheaper alternatives “recovered much of the same analysis,” undermining the notion that Mythos’s prowess is solely a function of its size or proprietary nature. Stanislav Fort, Aisle’s founder and chief scientist, concluded that AI cybersecurity capability forms a “jagged” frontier—advances do not scale smoothly with model size or price but appear in uneven spikes across different architectures. Consequently, the true defensive advantage lies less in the model itself and more in the broader system surrounding its deployment.

Project Glasswing Consortium
To offset potential misuse, Anthropic restricted broad release of the Mythos preview and instead shared it with a consortium of more than 40 technology and critical‑infrastructure companies, dubbed Project Glasswing. Participants include Amazon, Apple, Microsoft, and Wall Street giant JPMorgan Chase. JPMorgan’s Chief Information Security Officer, Pat Opet, described the initiative as a “unique, early stage opportunity to evaluate next‑generation AI tools for defensive cybersecurity across critical infrastructure both on our own terms and alongside respected technology leaders.” The controlled distribution intends to give defenders a head‑start to patch insecure legacy code before the findings become publicly known.

Defensive Advantage and Early Access
Jake Scheetz, a technical architect at cybersecurity firm NetSPI, emphasized that “over 99% of Mythos’s findings are still unpatched by design,” allowing early‑access partners supporting critical software to identify and remediate issues before disclosure runs its course. He characterized this as a “rare example of a capability reaching defenders meaningfully ahead of attackers,” warning that squandering the advantage through panic or indifference would be a missed opportunity. By enabling defenders to act on vulnerabilities prior to widespread exploitation, Project Glasswing seeks to shift the temporal balance in favor of security teams.

Adapting Bank Risk and Control Frameworks
The Financial Services Information Sharing and Analysis Center (FS‑ISAC) issued step‑by‑step guidance to help financial firms understand and mitigate the risks of implementing generative AI. FS‑ISAC notes that while GenAI can enhance operations, customer service, and even cybersecurity posture, it also heightens security risks when deployed without proper safeguards. Recommendations include augmenting the cybersecurity workforce with AI, increasing efficiency, and rigorously training employees to recognize and counteract model errors, hallucinations, and fabricated outputs that could mislead decision‑making.

Human‑in‑the‑Loop Validation
To mitigate the danger of blind acceptance of AI outputs, experts advocate a “human‑in‑the‑loop” approach, treating AI‑generated insights as recommendations rather than autonomous actions. The Cybersecurity and Infrastructure Security Agency (CISA) warns that models can “fabricate a plausible, but false, response or data,” potentially leading operators astray. By embedding human oversight—such as validation scripts, peer review, or escalation protocols—banks can reduce the likelihood that erroneous AI conclusions precipitate costly mistakes or security gaps.

Supply Chain and Third‑Party Risks
The proliferation of AI tools amplifies supply‑chain vulnerabilities because these systems depend on vast data sets often sourced from third‑party vendors. Guidance from the New York State Department of Financial Services cautions that a breach of any outside supplier could expose a bank’s nonpublic data and serve as a gateway for broader network attacks. Consequently, institutions must extend their risk assessments to cover AI‑related vendor relationships, scrutinizing data handling practices, access controls, and incident‑response capabilities of all partners involved in the AI lifecycle.

Federal Guidance and NIST AI Profile
Federal agencies encourage banks to embed AI system assessments into their existing risk‑evaluation, mitigation, and monitoring processes. A concrete pathway is to adopt the National Institute of Standards and Technology’s (NIST) new Cyber AI Profile, which offers guidelines for strategically adopting AI while addressing and prioritizing cybersecurity risks. By integrating AI considerations into established control sets—such as identity management, encryption, and continuous monitoring—financial institutions can safeguard their networks against evolving threats without overhauling their entire risk framework.

Conclusion and Strategic Recommendations
The advent of Anthropic’s Claude Mythos Preview underscores a paradigm shift: cyber threats can now emerge and be exploited at unprecedented speed. While the model’s capabilities have been met with both alarm and skepticism, the consensus among regulators and security experts is clear—financial institutions must act decisively. This entails joining defensive consortia like Project Glasswing, updating data‑governance policies, investing in resilient infrastructure, implementing human‑in‑the‑loop validation, scrutinizing third‑party AI supply chains, and aligning AI adoption with frameworks such as NIST’s Cyber AI Profile. By proactively embedding these measures into their risk managementDNA, banks can turn a potential accelerator of cyber risk into a strategic advantage, securing their systems against the next wave of AI‑powered threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here