
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Anthropic's new AI model, Mythos, has identified thousands of software vulnerabilities, prompting major tech firms and financial authorities in the US and UK to restrict its release due to fears it could be exploited for cyberattacks. The AI's capabilities have sparked warnings about potential risks to critical infrastructure and financial systems.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly involves an AI system (Mythos) designed to find security vulnerabilities, which is a clear AI system use case. The AI's role is in the use phase, identifying bugs that could be exploited. While no direct harm has yet occurred from Mythos itself, the article warns of plausible future harms including advanced cyberattacks facilitated by AI, which could disrupt critical infrastructure or cause other harms. This fits the definition of an AI Hazard, as the AI system's use could plausibly lead to an AI Incident. The article does not describe any realized harm or incident caused by the AI system, so it is not an AI Incident. It is more than complementary information because it focuses on the credible risk and potential harms from the AI system's capabilities. Therefore, the correct classification is AI Hazard.[AI generated]