Why the dangers of Mythos AI may be a myth

22 Apr 2026 · 15 min · 8 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The episode debates whether Anthropic’s Mythos AI is truly a “red alert” danger or mostly hype. Mythos is an AI model that finds software vulnerabilities and shows how to break into systems, potentially compressing expert hacking work into minutes. Anthropic says releasing it publicly would be irresponsible; OpenAI’s Sam Altman calls the danger talk marketing. Technology correspondent Roland Manthorpe reports Mythos was shared with a small set of big firms (e.g., Microsoft, Google). The AI Security Institute says Mythos is better but not a huge leap; however, capability may be doubling every four months. Examples: Mythos reportedly found vulnerabilities in Firefox. NCSC head Richard Horne urges “10 times urgency” for patching—minutes, not months—especially for under-updated sectors like the NHS. Key claim: defense remains “cyber hygiene” (patching, 2FA), though attacks may scale faster.

Guests

Sam Coates (Sky News), Anne McElvoy (Politico), Roland Manthorpe (technology correspondent).

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

The Rise of Mythos AI

0:47 to 1:20

Discussion of a new AI model named Mythos and its implications.

“Hi everyone, Neil here with the news that Silicon Valley has a surprising new mantra when it comes to artificial intelligence.”

The Dangers of Mythos AI

1:20 to 2:06

Exploration of the potential risks associated with Mythos AI.

“What it's going to mean is where organisations are reliant on technology.”

Functionality and Concerns about Mythos

2:06 to 4:30

Detailed examination of how Mythos works and concerns about cybersecurity.

“Roland Manthorpe is our technology correspondent.”

Urgency in Cybersecurity Measures

4:30 to 6:46

Discussion on the need for urgent cybersecurity measures in light of Mythos.

“But what is underhyped is the trend and what it means.”

Potential Threats to Critical Sectors

6:46 to 8:10

Analysis of which sectors are most vulnerable to AI-driven attacks.

“that he's trying to get over to everyone.”

Defensive Strategies Against AI Attacks

8:10 to 10:15

Exploration of defense strategies against AI-enabled cyber threats.

“Yeah, I mean, that's totally a possibility.”

Future of AI in Cybersecurity

10:15 to 12:34

Discussion on the future implications of AI in cybersecurity.

“Or does it tip it in the balance of the hackers?”

Cyber UK Conference Insights

14:00 to 15:21

Learn about the prevailing attitudes towards cybersecurity at the Cyber UK conference.

“As mentioned, you're at the Cyber UK conference up in Glasgow.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:02Sky News. The full story first.

0:10It's a hacker's dream. The cyber security AI so powerful, its creators won't release it. And this is why.

0:24I'm Sam Coates from Sky News. And I'm Anne McElvoy from Politico. Downing Street drama, leadership battles and policy U-turns. We're on it before it breaks. We take you straight into the rooms where the real political conversations are happening. Smart Insight, clear analysis in your feeds by 7.45am. So you start your morning fully brief for the day ahead in British politics. Hit follow and listen to Politics at Sam & Anne's wherever you get your podcasts.

1:02Hi everyone, Neil here with the news that Silicon Valley has a surprising new mantra when it comes to artificial intelligence. Not sign up here, not try the demo, just a firm, slightly theatrical, no, you can't have this one, it's too dangerous. So I think we're at a significant moment in time. What it's going to mean is where organisations are reliant on technology. One of the biggest firms in the world, Anthropic, has built an AI model called Mythos. It finds holes in computer systems and then shows you exactly how to break in. Efficiently, repeatedly, and at a scale that makes a human hacker look like they're still trying to remember their password.

1:40Anthropic boss Dario Amadei says releasing it would be irresponsible, which I suppose is one way of putting it. Another, they've built something they're not entirely sure they can control. It seems almost inevitable that AI will increase the speed and the intensity and the frequency of attacks. And just to keep things nice and cynical, Sam Altman, boss of Rival OpenAI, says all this talk of danger sounds a lot like marketing. So what's actually going on?

2:10Roland Manthorpe is our technology correspondent. I spoke to him as he was attending the UK cybersecurity conference Cyber UK up the road in Glasgow. Roland, great to have you back on the podcast. Luke, Mythos. Just explain exactly what it is. Oh, well, Mythos is Anthropik's new AI model that they said was so powerful, so good at cybersecurity, they couldn't release it publicly. They thought it was too dangerous to release publicly. And so instead, they released it to a small select group of companies, you know, big tech firms, Microsoft, Google, and so on. And this announcement has just caused the most enormous stir.

2:46You know, on one hand, people are saying, oh, this is ridiculous. It's fear-based marketing. I think that's actually a quote from Sam Mortman at OpenAI, by the way. So, you know, serious people saying this. And on the other hand, people saying, right, this is red alert time. Oh, my goodness, this stuff is getting so powerful. It's terrifying. So it's definitely caused a real stir. What was this piece of software created to do in the first place? Oh, well, that's a really interesting question. It was just great to be good at AI, just all the usual things. And then just as a byproduct of being good, turned out to be amazing.

3:16at this specific aspect of cybersecurity, which is finding vulnerabilities, basically kind of holes in code that were already there. But normally, you would just need, you know, 10 million expert hours to find. And yeah, I mean, you know, that's what AI is brilliant at, kind of taking that human labor and compressing it into a really short time span. So when a company like Anthropic says, hold the bus a minute, guys, this might be a little bit too dangerous for mass use. I mean, I'm sorry, I always get chills up my spine whenever we speak, Roland, but on this particular one, the hairs on the back of my neck are standing up as well.

3:51Yeah, well, it's good to know I'm such a, you know, calm, reassuring presence for you. I know what you mean. And it's quite a tricky one, because we don't really know how, kind of what it's like, because we haven't got our hands on it. The assessment that I take most seriously is the one by the AI Security Institute, which is the British independent security institute which looks at AI models and they got advanced access to it. And they're absolutely world leading. And their assessment was, yes, it is much better, but it's not like it's this gigantic, huge leap and everything is different. So, you know, if you want my personal take on it, I would say that Mythos right now is perhaps slightly overhyped.

4:31But what is underhyped is the trend and what it means. Because, you know, when you look at these things on a chart, I mean, it's got that line. It's going up and up and up. And the AI Security Institute say that they reckon capability is doubling every four months, which is much faster than they expected. And I mean, this is not an exact science, but just think about it, right? Doubling every four months. That means by August, we'll have a model that's twice as powerful as Mythos. So that is, I think, the thing to be quite concerned about. What are the real-world applications of Mythos then? the ones that it was designed for, and the ones that Anthropic and the rest of the world are clearly now beginning to worry about.

5:07In terms of cybersecurity, yeah, it's this thing of finding vulnerabilities that has really got people worried. And it's able to find vulnerabilities in code that is quite essential to the whole internet, really. So it's found lots of vulnerabilities, for instance, in Firefox, Mozilla's Firefox. This is one of the supposed to be one of the kind of most secure piece of software we have. Millions of people have looked over this and it's finding all sorts of vulnerabilities that we didn't really know were there already. Now the important thing to say is that a vulnerability is not the same as an exploit.

5:40So a vulnerability is like an open door in code if you like. An exploit is the ability to walk through it and to do that you need to be able to chain together normally multiple vulnerabilities. So this doesn't mean like right game over everything's hacked but it does just suddenly mean that all these weaknesses are being surfaced in quite essential code. And that is really quite worrying. And it's for this reason that I was especially keen to come to this conference in Glasgow and speak to the head of the National Cyber Security Centre, because NCSC is the body that is meant to protect the UK against cyber attacks.

6:09So Roland, what is the official line when it comes to our kind of cyber defence? You saw him up close, you saw the whites of his eyes. How concerned is he right now? I'd say he is measured and not wanting to spook people. But he's trying to convey the urgency of the situation. He said to me, look, this is not a totally new thing. We know what to do. It's still about those basic cyber essentials of patching old code, but the urgency has gone up. He said companies need to deal with it with 10 times urgency. And that instead of having weeks or months to patch code, it's now minutes. And I think this is the message that he's trying to get over to everyone.

6:48Don't panic, but do take this extremely seriously. I think it's understandable for Richard Horne to adopt the position that he has on this particular topic, and he's certainly better brief than me. But when Anthropic are warning about the risks of one of their core products, look, we all have to sit up and pay attention. Let's be specific. What sectors should we be most concerned about that this particular piece of software could be pointed at by nefarious actors? Based on kind of my conversations with people in the sector, I would say it's exactly the sort of sectors that you would imagine, as in sectors that haven't really been keeping up on terms of their IT.

7:25It's not banks and so on, it's probably the NHS. That is really the area that you would imagine that their code isn't really up to scratch. We've seen within recent memory that a big cyber attack can end up taking down hospitals. This is really the kind of thing that might be quite likely. I mean, I suppose the big picture, it seems almost inevitable that AI will increase the speed and the intensity and the frequency of attacks. When I first heard of this, you know, and I don't want to be a doom monger here, but my mind went to, you know, the defence industrial complex. Is there a possibility that if this sort of software was given to hacking groups, was given to foreign nations, hostile foreign nations, that they could get inside our military and wreak havoc?

8:10Yeah, I mean, that's totally a possibility. But I suppose you've got to think that this technology is really good for defence as well as attack. In a way, the fundamentals haven't changed. We've always been in this cybersecurity race. Can we improve our defenses before our adversaries improve their attacks? Now we're just in a race to adopt AI. You know, in terms of your kind of more specific question, my concern would often be about things like procurement and those kind of issues and just, you know, sheer money. Do our defenders have the resources to actually get the very cutting edge stuff that they need?

8:44I mean, one thing is abundantly clear. If the Chinese don't have this now, they will do soon. I mean, everyone is kind of totally clear on that. There's no way that these capabilities can be hidden. They're going to get it sooner or later. Are we equipping in time to defend ourselves? What possible defence then can an institution, a government, a state have against a group in possession of Mythos right now? Well, according to NCSC, they say basically nothing's changed. The defence is still just kind of good cyber hygiene. You know, two-factor authentication, making sure you've got your on top of your passwords, all that sort of stuff.

9:19Because in a way, you know, you've got to remember is that Mythos is not some kind of magic tool. You know, you don't just press the button and then it hacks you. What it does is it finds existing vulnerabilities. If you're patching those vulnerabilities, well, then problem solved. There are lots of ways to defend against this. The worry, as I see it, is not that, oh, this stuff is so incredible. It's so good. It can't be defended against. It's just that as a country, we don't actually have a great record of just doing the basics. So you've seen with all these ransomware attacks over the last few years, they are exploiting usually very, very, very simple errors that could quite easily be fixed.

9:53But clearly, organisations aren't doing that. And I think that is the worry. And in a way, this is the challenge for someone like Richard Horne. How does he really get people to listen and really take this seriously without also panicking people? Does the creation of a tool like Mythos, does that tip the balance in favour of the internet defenders, the cyber security experts that are employed by firms to protect their IP, their money and so on and so forth? Or does it tip it in the balance of the hackers? It's a tricky one because remember, they've only released it to these select groups of organisations first.

10:25And yes, that includes the big cloud players who probably provide most of the security for most companies. But there's loads of people that are missing out. And one sort of unnoticed feature of this that people don't talk about is that these models are incredibly expensive to run. So Anthropic say that they found one critical vulnerability and that cost them$20 ,000. So it's not the case that now all defenders have access to this. They can just press go and it'll sort things out. It's slightly more complicated than that. But aren't we edging towards a point where these attacks are going to be taking place with such volume and at such speed that the only thing that will be able to respond to an AI hack is artificial intelligence itself.

11:06Yeah, I think that is inevitably the sort of direction that we're going to head in. The only ways to defend against AI attacks is with more AI. But, you know, look, I know I'm often not a reassuring presence on this podcast, but let me paint you kind of a more optimistic future of all this. Because you know I was saying that these vulnerabilities they're known about, well, often they're known about by criminal gangs who are exploiting them and not telling everyone. There's a whole market in these things. People are selling vulnerabilities online the whole time. It could well be that AI takes us to a better place because it exposes these things.

11:37We know about them and then we're able to fix them. And obviously, in that process, there would probably be some pretty painful readjustment. But we might actually end up somewhere where the vulnerabilities are known about. We have AI defences and actually overall our cybersecurity is better. OK, but Anthropic, whilst telling everyone that we need to be careful about their own model, There are reports out just today, in fact, that actually perhaps this mythos system has already made its way into the hands of unauthorized third parties. I mean, if we can't keep the genie inside the bottle, if you cannot keep this stuff secure, then nefarious actors will try and take advantage of it and in every possible way that they can imagine.

12:17I would say in cybersecurity circles, no one is that surprised that people's got unauthorized access to this. And everyone assumes that it will leak and that these capabilities will be out there. And they'll be in Chinese open source models that anyone can access before too long. It's almost an inevitability. But yeah, like I say, I mean, it is harder to execute with these things than you might think from just reading about them. It's a bit like, you know, your AI use in everyday life. It can do some magical things and it can really help you. But then also it can be like quite frustratingly stupid and it doesn't take the human out of the loop just yet.

12:51Roland, do you think that this might be one of those moments that we look back on as a turning point? anthropic issuing concerns about their own software, the scale and the scope of what it might be able to do at some point down the line, only now really becoming obvious. I mean, we have talked before about artificial intelligence, and we have both been moderate in our tone. But when we are talking about one of the biggest companies in the world, warning states, warning banks, I just feel like it might be more of a moment than we are able to realise just at this moment. Yeah, I completely agree.

13:22It's hard to really put the import of artificial intelligence into words. And I sort of struggle with this. But I think as a whole, it's going to be huge. But when it comes down to the cybersecurity thing, looking back over the history of technology, you always see this armature between attackers and defenders. And there are times when the attackers have a lead. But in general, we're also quite good at defending. We're not that bad at this. And so, yes, I think that AI will change all sorts of things. It will have a transformative effect on the world. But I'm also quite optimistic about our ability to handle this particular threat.

13:57It's going to be huge, but it's not the end of the world. As mentioned, you're at the Cyber UK conference up in Glasgow. I mean, what is the mood like amongst the people there? Is that the general mood amongst people there? A focus on the opportunity rather than necessarily the danger? A bit of both, I'd say. I mean, I'd say the dominant mood is something like, well, we did tell you. Or, well, you're really going to have to listen to us now. Because what they're saying is, look, we've been saying that you need to patch your systems and be careful about cybersecurity for decades. And honestly, people haven't really been listening.

14:31Well, you really need to listen now. You know, that's the message that they're trying to get over to their clients. And quite a lot does rest on people taking them seriously. Do you think we are yet? I mean, that's the question, isn't it? Honestly, I'm not totally sure that they are. And I did try and press Richard Horne on this and he didn't really want to go there. But I said to him, look, what you're saying is that the guidance is the same. We're just telling you that it's really important this time. But look, if you're just saying, just do the same things, how do people know to take it seriously?

15:02And I think this is my worry. I'm not really sure that the government and NCSC are managing to get it across to people how urgent this is. I suppose my My fear is that people won't change when they see the light. They'll change when they see the heat or they feel the heat and that there might need to be one or two major incidents before people really wake up to this. Roland, many thanks. Thanks very much for being with us. Now, does AI keep you up at night or do you welcome the arrival of our robot overlords? Do let me know the email address why at sky.uk. We're back again tomorrow.

15:45I'm Sam Coates from Sky News. And I'm Anne McElvoy from Politico. Downing Street drama, leadership battles and policy U-turns. We're on it before it breaks. We take you straight into the rooms where the real political conversations are happening. Smart Insight, clear analysis in your feeds by 7.45am. So you start your morning fully brief for the day ahead in British politics. Hit follow and listen to Politics at Sam & Anne's wherever you get your podcasts.

From the publisher

AI giant Anthropic has chosen not to release its latest model, Mythos Preview, to the public. The product was pulled after testing showed its unprecedented strengths in hacking.

Instead, Mythos has been made available to a small number of big tech companies including Amazon and Microsoft to help protect their software, rather than pick it apart.

So, has the day arrived which many have feared – where AI could change the world as we know it? Or are the scare stories around Mythos merely a myth?

Niall is joined by Rowland Manthorpe, technology correspondent at Sky News, to discuss the potential dangers as well as how safe the UK is from the threat of AI.

Have you got a question for Niall? Email the show – why@sky.uk

More from This Is Why

All 332 episodes
Why the dangers of Mythos AI may be a mythThis Is Why · 15 min
Listen in VO