The cybersecurity-AI market is almost certainly bifurcating into two competing doctrines: Anthropic's controlled-proliferation model (restricted access to a more capable system — Mythos Preview, distributed through Project Glasswing) versus OpenAI's verified-democratization model (broader identity-verified access to a less capable specialist — GPT-5.4-Cyber via the TAC program).[A2] Neither addresses the core structural problem: models that find vulnerabilities at scale are advancing far faster than the industry can remediate what they find — over 99% of Mythos findings remain unpatched.[C3] Which doctrine prevails will likely be decided less by capability than by which governance framework survives the EU AI Act (obligations from 2 Aug 2026) and enterprise procurement.[B2] Confidence is high on the capability leap, moderate on the resolution path.
5 Key Judgments
Mythos Preview almost certainly represents the most capable AI system for autonomous vulnerability discovery and exploitation currently in existence, having demonstrated full zero-day chains across every major OS and browser tested.
The defensive value of Mythos is very likely constrained in the near term by the remediation bottleneck: over 99% of discovered vulnerabilities remain unpatched, and social-engineering vectors remain unaddressed by the model.
Mythos-class capabilities will likely proliferate to competing frontier models within 6–12 months, given that they emerged from general reasoning improvements rather than cyber-specific training.
The market is almost certainly bifurcating into Anthropic's controlled-proliferation doctrine and OpenAI's verified-democratization doctrine; the prevailing model will likely be determined by EU AI Act compliance and procurement, not raw capability.
GPT-5.4-Cyber is very likely less capable than Mythos at autonomous zero-day discovery, but introduces a differentiated capability in binary reverse engineering addressing a distinct defensive workflow.
4 Competing Hypotheses
click evidence to test diagnosticity| Evidence · click to toggle | S1Convergence (regulated middle) | S2Bifurcation hardens | S3External shock forces intervention | S4Status quo, no resolution |
|---|---|---|---|---|
| EU AI Act obligations begin 2 Aug 2026 | + | – | · | · |
| OpenAI opposes gated access publicly | – | −− | · | + |
| Consortium / member overlap (FAANG, MSFT) | + | – | · | · |
| 99%+ Mythos findings unpatched; find >> fix | · | · | −− | · |
| Independent threat-actor parallel dev likely | · | · | −− | – |
| Rapid government / banking engagement | + | – | + | – |
| Inconsistency score | 1 SURVIVES | 5 | 4 | 2 |
6 Entities of Interest
8 resolved · showing 6 · sorted by centralityOpenAI
Claude Mythos Preview
GPT-5.4-Cyber
Project Glasswing
EU AI Act
Capability Signals
find advances faster than fixRelationship Graph
⌘/Ctrl-scroll to zoom · drag to panChronology
indications & warning · hover a marker, click to jumpEvidence Register
8 sources · graded| Source | Details | Type | Admiralty | Date |
|---|---|---|---|---|
| UK AISI — Mythos evaluation↗ | 73% expert-level CTFs; 27 of 32 steps on network sim; scales with inference compute | Independent eval | A1 | Apr 2026 |
| Anthropic Red Team — exploit benchmark↗ | 181 working Firefox JS-engine exploits vs predecessor's 2 (~90×); control-flow hijacks | Primary · Lab | A1 | Apr 2026 |
| Anthropic Red Team — capability scope↗ | Zero-day chains across every major OS and browser; oldest a 27-year-old OpenBSD bug | Primary · Lab | A2 | Apr 2026 |
| Anthropic Red Team — emergence↗ | Capabilities emerged from general code/reasoning/autonomy gains, not cyber training | Primary · Lab | A2 | Apr 2026 |
| Fortune — remediation gap↗ | Over 99% of Mythos-discovered vulns unpatched; finding easier than fixing | Trade press | C3 | Apr 2026 |
| Help Net Security — GPT-5.4-Cyber↗ | Cyber-permissive variant; lowered refusal boundaries; binary reverse engineering | Trade press | B2 | Apr 2026 |
| Channels TV / Reuters — access philosophy↗ | OpenAI: centrally deciding who gets to defend themselves is neither practical nor appropriate | Wire | A2 | Apr 2026 |
| SFist / Reuters — government response↗ | Treasury and Fed convene banks; JPMorgan calls Glasswing an early-stage opportunity | Wire | B2 | Apr 2026 |