How dangerous is Anthropic’s Mythos AI? (Bruce Schneier)
Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to the general public. Instead, it would only be available to a select group of companies to scan and fix their own software.
The announcement requires context – but it contained an essential truth.
While Anthropic’s model is really good at finding software vulnerabilities, so are other models. The UK’s AI Security Institute found that OpenAI’s GPT-5.5, already generally available, is comparable in capability. The company Aisle reproduced Anthropic’s published results with smaller, cheaper models.
At the same time, Anthropic’s refusal to publicly release its new model makes a virtue out of necessity. Mythos is very expensive to run, and the company doesn’t appear to have the resources for a general release. What better way to juice the company’s valuation than to hint at capabilities but not prove them, and then have others parrot their claims?
Nonetheless, the truth is scary. Modern generative AI systems – not just Anthropic’s, but OpenAI’s and other, open-source models – are getting really good at finding and exploiting vulnerabilities in software. And that has important ramifications for cybersecurity: on both the offense and the defense.
Attackers will use these capabilities to find, and automatically hack, vulnerabilities in systems of all kinds. They will be able to break into critical systems around the world, sometimes to plant ransomware and make money, sometimes to steal data for espionage purposes, and sometimes to control systems in times of hostility. This will make the world a much more dangerous, and more volatile, place.
But at the same time, defenders will use these same capabilities to find, and then patch, many of those same systems. For example, Mozilla used Mythos to find 271 vulnerabilities in Firefox. Those vulnerabilities have been fixed, and will never again be available to attackers. In the future, AIs automatically finding and fixing vulnerabilities in all software will be a normal part of the development process, which will result in much more secure software.
Of course, it’s not that simple. We should expect a deluge of both attackers using newly found vulnerabilities to break into systems, and at the same time much more frequent software updates for every app and device we use. But lots of systems aren’t patchable, and many systems that are don’t get patched, meaning that many vulnerabilities will stick around. And it does seem that finding and exploiting is easier than finding and fixing. All of this points to a more dangerous short-term future. Organizations will need to adapt their security to this new reality.
But it’s the long term that we need to focus on. Mythos isn’t unique, but it’s more capable than many models that have come before. And it’s less capable than models that will come after. AIs are much better at writing software than they were just six months ago. There’s every reason to believe that they will continue to get better, which means that they will get better at writing more secure software. The endgame gives AI-enhanced defenders advantages over AI-enhanced attackers.
Even more interesting are the broader implications. The same searching, pattern-matching and reasoning capabilities that make these models so good at analyzing software almost certainly apply to similar systems. The tax code isn’t computer code, but it’s a series of algorithms with inputs and outputs. It has vulnerabilities; we call them tax loopholes. It has exploits; we call them tax avoidance strategies. And it has black hat hackers: attorneys and accountants.
Just as these models are finding hundreds of vulnerabilities in complex software systems, we should expect them to be equally effective at finding many new and undiscovered tax loopholes. I am confident that the major investment banks are working on this right now, in secret. They’ve fed AI the tax code of the US, or the UK, or maybe every industrialized country, and tasked the system with looking for money-saving strategies. How many tax loopholes will those AIs find? Ten? One hundred? One thousand? The Double Dutch Irish Sandwich is a tax loophole that involves multiple different tax jurisdictions. Can AIs find loopholes even more complex? We have no idea.
Sure, the AIs will come up with a bunch of tricks that won’t work, but that’s where those attorneys and accountants come in – to verify, and then justify, the loopholes. And then to market them to their wealthy clients.
As goes the tax code, so goes any other complex system of rules and strategies. These models could be tasked with finding loopholes in environmental rules, or food and safety rules – anywhere there are complex regulatory systems and powerful people who want to evade those rules.
The results will be much worse than insecure computers. Tax loopholes result in less revenue collected by governments, and regulatory loopholes allow the powerful to skirt the rules, both of which have all sorts of social ramifications. And while software vendors can patch their systems in days, it generally takes years for a country to amend its tax code. And that process is political, with lobbyists pressuring legislators not to patch. Just look at the carried interest loophole, a US tax dodge that has been exploited for decades. Various administrations have tried to close the vulnerability, but legislators just can’t seem to resist lobbyists long enough to patch it.
AI technologies are poised to remake much of society. Just as the industrial revolution gave humans the ability to consume calories outside of their bodies at scale, the AI revolution will give humans the ability to perform cognitive tasks outside of their bodies at scale. Our systems aren’t designed for that; they’re designed for more human paces of cognition. We’re seeing it right now in the deluge of software vulnerabilities that these models are finding and exploiting. And we will soon see it in a deluge of vulnerabilities in all sorts of other systems of rules. Adapting to this new reality will be hard, but we don’t have any choice.
- Bruce Schneier is a security technologist who teaches at the Harvard Kennedy School at Harvard University
See the original post here: https://www.theguardian.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai
Elon Musk’s only AI expert witness at the OpenAI trial fears an AGI arms race
... Today, they called the only expert witness to speak directly to AI technology: Stuart Russell, a University of California, Berkeley computer science professor who has studied AI for decades. His job was to offer background on AI and establish that this technology is dangerous enough to worry about. ...
Russell told jurors and Judge Yvonne Gonzalez Rogers that there were a variety of risks associated with the development of AI, ranging from cybersecurity threats to problems with misalignment and the winner-take-all nature of developing artificial general intelligence (AGI). Ultimately, he said that there was a tension between the pursuit of AGI and safety.
Russell’s larger concerns about the existential threats of unconstrained AI didn’t get aired in open court after objections from OpenAI’s attorneys led the judge to limit Russell’s testimony. ...
See the full story here: https://techcrunch.com/2026/05/04/elon-musks-only-expert-witness-at-the-openai-trial-fears-an-agi-arms-race/
Anthropic and Wall Street Giants Join Forces to Create New A.I. Firm
Anthropic is teaming up with several large investment firms to create a venture that will help companies integrate artificial intelligence tools into their systems, the latest example of the deepening ties between Wall Street and the A.I. industry.
The private equity firms Blackstone and Hellman & Friedman and the investment bank Goldman Sachs through its investment funds are among the financial backers in the new firm, which will work with companies to deploy Anthropic’s A.I. model Claude. ...
See the full story here: https://www.nytimes.com/2026/05/04/business/anthropic-blackstone-goldman-sachs-artificial-intelligence-firm.html
The Vanguard State: How Ukraine is Redefining the Character of War
...
Ukraine has not simply adopted robotic warfare - it has mastered its doctrine. We are now seeing credible reports of Ukrainian units using unmanned ground systems to probe, fix, and even clear Russian positions before a single soldier steps forward. These are not theoretical trials; these are frontline realities where machines absorb the first contact, drawing fire and shaping the battlefield to reduce the cost in Ukrainian lives. ...
At sea, the change is even more remarkable. Ukraine, a state that effectively lost much of its conventional naval capability early in the war, has managed to hold a far larger adversary at risk through a "denied space" strategy. ...
... the traditional "underdog" story is evolving. ...
Ukraine is no longer just catching up to modern standards - it is setting them. It has moved beyond the narrative of mere resilience and into one of asymmetric primacy. A state no longer needs air superiority in the traditional sense to contest the skies, nor a billion-dollar navy to win the sea. It needs networks, autonomy, and the willingness to deploy them at scale.
Ukraine is still fighting for its survival, but in doing so, it is teaching the rest of the world how the wars of the future will be fought.
See the full story here: https://www.realcleardefense.com/articles/2026/05/04/the_vanguard_state_how_ukraine_is_redefining_the_character_of_war_1180474.html
Perfectly Aligning AI’s Values With Humanity’s Is Impossible – Maybe the best we can do is make “neurodiverse” systems that challenge each other
...
IEEE Spectrum: You and your colleagues have now shown that misalignment of AI systems is inevitable, because any AI system complex enough to display general intelligence will produce unpredictable behavior. Your proof rests on two famous sets of premises—Gödel’s incompleteness theorems, which found that every mathematical system will have statements that can never be proven, and Turing’s undecidability result for the halting problem, which found that some problems are inherently unsolvable.
Zenil: The conventional wisdom assumes misalignment is a bug that can eventually be removed with the right optimization strategy. Our results show that the problem of alignment is not simply a lack of better data, more compute, or better engineering, but a limit built into both formal systems and universal computation. What I am arguing is that for sufficiently general AI systems, some degree of misalignment is structural, so the task shifts from elimination to management.
IEEE Spectrum: Can you describe your strategy of managed misalignment?
Zenil: Once perfect alignment looked unattainable in principle, the next move was obvious—stop trying to perfect one agent and start designing the ecology around it. This is what it would take to achieve any degree of controllability, and controllability has to come from outside, given the intrinsic impossibility of controlling from the inside. You see similar strategies in biology and medicine, where robust results often come from interacting systems rather than a single master controller.
The simplest way to put it is this: Do not trust one supposedly perfect AI to govern everything. Instead, build a structured ecosystem of different agents with different “values” that monitor, challenge, and constrain one another, much like courts, auditors, and competing institutions do in human society. None of them is perfect on its own, but their managed interaction can make the whole arrangement safer than any single dominant model.
The main thing not to misunderstand is that managed misalignment does not mean giving up on safety or letting AI behave however it likes. It means replacing the fantasy of absolute control with a more realistic form of distributed control. In that sense, it is not less serious about safety, but more serious about what safety actually requires.
IEEE Spectrum: How did you test your strategy?
...
Zenil: This work is not anti-AI. It is anti-naivety about control.
See the full story here: https://spectrum.ieee.org/amp/ai-alignment-2676752963
How A.I. Is Transforming China’s Entertainment Industry
...
Until recently, making a hit microdrama — the soapy, short-form, made-for-mobile shows that have become wildly popular in China — meant hiring actors, renting sets and spending weeks filming and editing.
Now, some Chinese companies are churning them out for $30 a minute, with no cameras, no crew and no human performers.
That’s thanks to artificial intelligence. ...
Most A.I.-generated microdramas, which under Chinese law are required to be labeled as such, attract little attention. But some clips have racked up hundreds of millions of views, in a country where people are generally more optimistic about A.I. than in the West. The Chinese market for A.I. microdramas is expected to be worth more than $3 billion this year, according to Chinese state media, out of a more than $14 billion market for microdramas in general.
But recently, the surge has also set off an outcry in China. Actors say their work opportunities have dried up. Celebrities and ordinary people alike have threatened legal action after discovering their likenesses in A.I.-generated microdramas. (ByteDance has since introduced restrictions on using real people’s faces in Seedance.) ...
Mr. Li said he did not oppose the use of A.I. in entertainment but thought the industry was applying it in the wrong way.
“They’re still just imitating humans or trying to make things more humanlike,” he said. “They should be trying to unleash more imagination, taking a more unconventional route.”
He continued: “After all, our fundamental value as humans is in our ability to imagine.” ...
Part of the reason he had turned to the shorter format — microdrama episodes are usually one or two minutes long — was for the quick returns. ...
He hopes to make projects that combine A.I. with live action. He is working on a project that he said is similar to “Stuart Little,” the film that featured an animated mouse alongside real actors.
“If we could feel the warmth of a real performance, and also see the power of A.I. technology, I think that would be great,” he said. ...
Some of Mr. Hou’s creative employees have backgrounds in filmmaking, but others are simply people “who are obsessed with A.I.,” he said. ...
“This work isn’t exactly traditional screenwriting. Part of it requires translating into a language that A.I. can understand,” he said. “People who don’t have a traditional directing or screenwriting background might actually be better at it.”
Producing a 100-minute animated series takes about one month and three employees. Realistic ones take around five people, because it is more labor-intensive to create images that are good enough. ...
And people would gradually find ways to adapt to the employment pains, too, he said. He himself had previously worked for big tech companies in Beijing before he was forced out by cutbacks and pivoted to A.I. filmmaking.
“The impact on employment — there definitely will be an impact,” Mr. Hou said. “But for individuals, what can you do? You can only embrace this new era and think about how to adapt.” ...
See the full story here: https://www.nytimes.com/2026/05/03/world/asia/china-microdrama-ai-backlash.html
Silicon Valley Is Bracing for a Permanent Underclass
...
“Whenever someone wrote a paper which talked about some negative aspect of A.I., he would say, ‘We’re not going to release something about a problem until we have a solution for it,’” said an employee who worked with Mr. Lehane, and who spoke on the condition of anonymity to discuss internal deliberations. Mr. Lehane characterized his approach differently: He wanted the economists on OpenAI’s global affairs team to “inform smart public-policy making,” not conduct “niche” academic research.
...
And what if we don’t act? What if we “let technology rip”? What if millions of people do lose their jobs to A.I., and nobody puts up the money or policy solutions to help them? In March, the Palantir chief executive, Alex Karp, spoke on a panel with the Teamsters president, Sean O’Brien. “The biggest challenge to A.I. in this country is political unrest,” Mr. Karp said. “If I were sitting here in private with my peers, I’d be telling them the country could blow up politically and none of us are going to make any money when the country blows up.”
See the full story here: https://www.nytimes.com/2026/04/30/opinion/ai-labor-work-force-silicon-valley.html
Canadian Feds reveal 6 pillars for long-touted, repeatedly delayed national AI strategy
...
The federal government said it will achieve those objectives through six pillars:
- Protecting Canadians and safeguarding our democracy.
- Empowering Canadians
- Powering AI adoption for shared prosperity.
- Building the Canadian sovereign AI foundation.
- Scaling Canadian champions.
- Building trusted partnerships and global alliances.
...
See the full story here: https://www.cbc.ca/news/politics/ai-strategy-pillars-evan-solomon-9.7180418
OpenAI Publishes 5 Principles For Its AGI Push
...
The Five Principles Announced This Week
The company says it will resist concentrated power and wants major AI decisions shaped through democratic processes, not only by AI labs, as part of its first principle of democratization. ...
The second principle, empowerment, gives users broad latitude. OpenAI says people should have meaningful control over how they use AI. Yet the same section ties that freedom to a duty to reduce catastrophic harm, local harm and social damage. ...
The third principle, universal prosperity, links AI access to massive infrastructure buildout and lower compute costs. ...
The fourth principle, resilience, moves the company closer to the language of national security. OpenAI points to biological risk, cybersecurity and critical infrastructure. It says no single lab can secure the future alone, and it wants to put in oversight to ensure that any society-wide harms can be detected early and mitigated easily. ...
The fifth principle, adaptability, is the most revealing. OpenAI says it will change course as it learns and that some periods may require placing resilience ahead of empowerment. This means that the closer AI gets to AGI capabilities, the more access may become conditional.
...
See the full story here: https://www.forbes.com/sites/ronschmelzer/2026/04/27/openai-publishes-five-principles-for-its-agi-push/
OpenAI just changed its principles. Here’s what’s changing
...
Both versions of the company’s principles say that OpenAI’s mission is to guarantee this technology “benefits all of humanity,” but the 2018 version explicitly mentions building it safely and beneficially.
“Our primary fiduciary duty is to humanity,” the document reads. “We anticipate needing to marshal substantial resources to fulfil our mission, but will always diligently act to minimise conflicts of interest among our employees and stakeholders that could compromise broad benefit.”
The 2026 version, however, said it needs to continue to build safe systems, but that society needs to contend with “each successive level of AI capability, understand it, integrate it, and figure out the best path forward together.” ...
The way forward, as CEO and cofounder Sam Altman sees it in 2026, is to democratise AI at all levels by giving everyone access to it and resisting the idea that the technology could “consolidate power in the hands of the few”. ... [philNote: "resistance is useless."]
AGI has a “ring of power” to it that “makes people do crazy things,” Altman wrote. To fight back, he said the only solution is to “orient towards sharing the technology with people broadly, and for no one to have the ring.” ...
See the full story here: https://ca.news.yahoo.com/openai-just-changed-principals-changing-112531234.html
Pages
- About Philip Lelyveld
- Mark and Addie Lelyveld Biographies
- Presentations and articles
- Trustworthy AI – A Market-Driven approach
- Tufts Alumni Bio