
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Anthropic's new AI model, Mythos, has demonstrated the ability to autonomously identify and exploit thousands of high-severity software vulnerabilities, surpassing most human experts. Fearing misuse and potential large-scale digital disruption, Anthropic has withheld public release, prompting urgent discussions with the U.S. government on AI safety and critical infrastructure risks.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Mythos) explicitly described as capable of identifying and exploiting software vulnerabilities, which is a direct AI system involvement. While no actual harm has been reported, the article emphasizes the credible risk that the AI could be used maliciously to cause cybersecurity incidents, including remote code execution and system breaches. This fits the definition of an AI Hazard, as the AI system's development and potential misuse could plausibly lead to significant harm (disruption of critical infrastructure, harm to property, or other significant harms). The article does not describe any realized harm yet, so it is not an AI Incident. It is more than complementary information because it focuses on the risk and capabilities of the AI system itself, not just responses or ecosystem context.[AI generated]