An AI Model So Good at Hacking That Anthropic Won’t Release It to the Public
An AI Model So Good at Hacking That Anthropic Won’t Release It to the Public
On April 7, Anthropic announced a new AI model called Mythos. Two weeks later, the company’s CEO was sitting in the White House, talking to the chief of staff about what to do with it. That trajectory, from product launch to presidential meeting in under 14 days, tells you something about where AI capabilities have landed in 2026.
Anthropic describes Mythos as “strikingly capable.” That’s not typical marketing language from a company that built its brand on safety-first AI. The model can find and exploit software vulnerabilities faster than human cybersecurity experts. That claim made headlines, but the real story is messier than the headlines suggest.
What Mythos Actually Does
Mythos Preview, as the current version is called, goes beyond finding bugs. It strings together multiple vulnerabilities to create full exploits. Anthropic co-founder and policy chief Jack Clark described it at the Semafor World Economy conference: “We’re releasing it to a subset of some of the world’s most important companies and organizations so they can use this to find vulnerabilities.”
The company has restricted access to select customers. Not because of supply constraints or a staged rollout strategy. Because the model is genuinely dangerous in the wrong hands. The UK’s AI Security Institute evaluated Mythos and called it a “step up” over previous models, which were already improving fast. Their report noted that “Mythos Preview can exploit systems with weak security posture.” That’s a polite way of saying it can break into poorly defended networks.
Anthropic also launched something called Project Glasswing alongside the model. The initiative brings together Amazon, Apple, Google, Microsoft, and JPMorgan Chase to secure critical software against the exact kind of attacks Mythos could enable. When a company builds a tool and immediately assembles a defense coalition against it, that’s either responsible behavior or very sophisticated theater. Maybe both.
The White House Meeting
On Friday, April 17, Anthropic CEO Dario Amodei met with White House chief of staff Susie Wiles. The administration described the meeting as “productive and constructive.” Anthropic said the two sides discussed “cybersecurity, America’s lead in the AI race, and AI safety.”
The context makes this meeting more interesting than a standard tech executive visit. President Trump tried to ban all federal agencies from using Anthropic’s Claude chatbot in February, posting on social media that the administration “will not do business with them again!” Defense Secretary Pete Hegseth attempted to declare Anthropic a supply chain risk, a move with no precedent against a US technology company. Anthropic challenged both actions in federal court. Judge Rita Lin blocked enforcement of Trump’s directive in March.
The friction started because Anthropic wanted limits on how the Pentagon uses its technology. The company refused to allow deployment in fully autonomous weapons or domestic surveillance. Hegseth’s position was that Anthropic must permit any use the Defense Department considers lawful. When asked about the White House meeting on Friday, Trump said he had “no idea” it was happening.
So the same administration that tried to blacklist Anthropic is now meeting with its CEO to discuss collaboration on a model that could transform national security. Washington moves fast when the stakes get real.
Is the Threat Real?
David Sacks, the White House’s former AI and crypto czar, has been one of Anthropic’s loudest critics. He has publicly questioned whether the company exaggerates risks for strategic advantage. But on his “All-In” podcast, Sacks took a different tone about Mythos.
“Anytime Anthropic is scaring people, you have to ask, ‘Is this a tactic? Is this part of their Chicken Little routine? Or is it real?'” Sacks said. “With cyber, I actually would give them credit in this case and say this is more on the real side.”
His reasoning is straightforward. Coding models keep getting better at understanding software. Better understanding means better bug-finding. Better bug-finding means better exploit-creation. The capability follows logically from the technology’s trajectory.
The Stanford AI Index Report, published the same week, backs this up. Model performance on SWE-bench, a coding benchmark, jumped from 60% to near 100% in a single year. If coding ability is rising that fast, the offensive security applications are rising too. Mythos isn’t an anomaly. It’s a predictable outcome of current trends.
The China Clock
Clark made a point at the Semafor conference that deserves more attention than it received. “There will be other systems just like this in a few months from other companies,” he said, “and in a year to a year-and-a-half later, there will be open-weight models from China that have these capabilities.”
The math is blunt. Anthropic can restrict access to its model. US companies can build defenses. But the capability itself is not secret, and the underlying techniques are replicable. Once Chinese labs produce open-weight versions, anyone with a GPU cluster can download and deploy them. No permission required. The Stanford report showed the performance gap between US and Chinese models has collapsed to 2.7%. China filed 69.7% of all AI patents worldwide last year.
This is the real pressure behind the White House meeting. Not whether Anthropic and the Trump administration can patch up their relationship. Whether the US government can figure out how to use these models defensively before adversaries use them offensively. The timeline Clark described, a few months for competitors, roughly 18 months for open-source versions, gives policymakers very little room to maneuver.
What Happens Next
Anthropic is in talks with the European Union about Mythos and other unreleased models, according to European Commission spokesman Thomas Regnier. The EU AI Act entered full enforcement in January 2026, and Mythos sits squarely in the high-risk category that regulators care about most.
Back in Washington, the administration says any new technology used by the federal government will go through a technical evaluation period. How long that takes, and whether it moves faster than the open-source timeline Clark described, is an open question.
Forty-seven countries now have active AI legislation. Only 12 have enforcement mechanisms. The regulatory infrastructure is thin relative to the speed of deployment. Anthropic is trying to set its own rules by restricting access and building Project Glasswing. Whether self-regulation from a company the president tried to blacklist holds up as a long-term strategy is, to put it mildly, uncertain.
The Mythos situation is not really about one model from one company. It’s about what happens when AI capabilities cross a threshold where the defensive applications and the offensive applications are the same capability, just pointed in different directions. The companies building these models know it. The governments scrambling to respond know it. And the clock on open-weight alternatives is already running.
For tool-by-tool comparisons, see our AI coding listings and the comparisons section.