Rook Reports
Cyber

AI-Enabled Cyber Defense

Published 16 APR 2026Confidence ModerateTop Admiralty A1v1.0
AI-Enabled Cyber Defense — The Doctrinal Split · AICD-001-R01 · 2026-02 → 2026-04-16 · Mythos/Glasswing vs TAC · ACH + I&W
5
Key Judgments
thesis-level
8
Entities
resolved
12
Relationships
graph edges
12
Sources
graded
3
Scenarios
6–12mo horizon
A1
Top Admiralty
reliability / credibility
MOD
Confidence
resolution path
Bottom line up front

The cybersecurity-AI market is almost certainly bifurcating into two competing doctrines: Anthropic's controlled-proliferation model (restricted access to a more capable system — Mythos Preview, distributed through Project Glasswing) versus OpenAI's verified-democratization model (broader identity-verified access to a less capable specialist — GPT-5.4-Cyber via the TAC program).[A2] Neither addresses the core structural problem: models that find vulnerabilities at scale are advancing far faster than the industry can remediate what they find — over 99% of Mythos findings remain unpatched.[C3] Which doctrine prevails will likely be decided less by capability than by which governance framework survives the EU AI Act (obligations from 2 Aug 2026) and enterprise procurement.[B2] Confidence is high on the capability leap, moderate on the resolution path.

5 Key Judgments

KJ-01

Mythos Preview almost certainly represents the most capable AI system for autonomous vulnerability discovery and exploitation currently in existence, having demonstrated full zero-day chains across every major OS and browser tested.

Confidence: HighSources: A1 · A2, incl. independent eval
KJ-02

The defensive value of Mythos is very likely constrained in the near term by the remediation bottleneck: over 99% of discovered vulnerabilities remain unpatched, and social-engineering vectors remain unaddressed by the model.

Confidence: HighSources: C3, find >> fix
KJ-03

Mythos-class capabilities will likely proliferate to competing frontier models within 6–12 months, given that they emerged from general reasoning improvements rather than cyber-specific training.

Confidence: ModerateSources: A2, emergence mechanism
KJ-04

The market is almost certainly bifurcating into Anthropic's controlled-proliferation doctrine and OpenAI's verified-democratization doctrine; the prevailing model will likely be determined by EU AI Act compliance and procurement, not raw capability.

Confidence: ModerateSources: A1 · A2, comparative
KJ-05

GPT-5.4-Cyber is very likely less capable than Mythos at autonomous zero-day discovery, but introduces a differentiated capability in binary reverse engineering addressing a distinct defensive workflow.

Confidence: HighSources: B2 · C3, no AISI-equivalent eval

4 Competing Hypotheses

click evidence to test diagnosticity
Evidence · click to toggleS1Convergence (regulated middle)S2Bifurcation hardensS3External shock forces interventionS4Status quo, no resolution
EU AI Act obligations begin 2 Aug 2026+··
OpenAI opposes gated access publicly−−·+
Consortium / member overlap (FAANG, MSFT)+··
99%+ Mythos findings unpatched; find >> fix··−−·
Independent threat-actor parallel dev likely··−−
Rapid government / banking engagement++
Inconsistency score
1
SURVIVES
5
4
2
+ConsistentInconsistent−−Strongly inconsistent·Neutral
Result: S1 survives with the fewest inconsistencies (1). Toggle evidence to test how each item discriminates between hypotheses.

6 Entities of Interest

8 resolved · showing 6 · sorted by centrality
PRIMARYLAB

Anthropic

Controlled proliferation · Mythos Preview · organized Project Glasswing · $100M credits
4edges
4sources
1flags
LABCHALLENGER

OpenAI

Verified democratization · TAC program · GPT-5.4-Cyber · $10M cybersecurity grant
4edges
3sources
0flags
MODELCAPYBARA

Claude Mythos Preview

Autonomous zero-day discovery · 73% expert CTFs / 27 of 32 steps (UK AISI)
3edges
3sources
2flags
MODELBINARY RE

GPT-5.4-Cyber

Cyber-permissive variant · binary reverse engineering · broad verified access via TAC
3edges
2sources
0flags
CONSORTIUM~40 ORGS

Project Glasswing

FAANG · CrowdStrike · Palo Alto · JPMorgan · Linux Foundation · NVIDIA · ~11 core partners
3edges
2sources
1flags
POLICYEU

EU AI Act

Obligations from 2 Aug 2026 · high-risk classification pending · the governance test both doctrines must survive
3edges
1sources
1flags

Capability Signals

find advances faster than fix
Mythos vs predecessor — working exploits
2
Predecessor
181
Mythos
count · Firefox JS-engine exploits
Expert-level CTF performance
27%
GPT-5 (Aug)
73%
Mythos
percent · independent UK AISI evaluation
Remediation gap
99%+
Unpatched
<1%
Patched
percent · Mythos findings unpatched vs patched

Relationship Graph

⌘/Ctrl-scroll to zoom · drag to pan
AnthropicOpenAIMythos PreviewGPT-5.4-CyberGlasswingUK AISIUS GovernmentEU AI Act
Primary subjectOrganisationModel / infraState / policyPerson

Chronology

indications & warning · hover a marker, click to jump
Feb '26Feb '26Mar '26Mar '26Apr '26Apr '26ANTHROPIC2OPENAI3GOVERNMENT2EVAL1LATEST
16 Apr 2026
Bloomberg deep-dive on Mythos discovery; regulatory and banking response develops
GOVERNMENT / US / Bloomberg · graded B2
15 Apr 2026
Treasury Secretary and Fed Chair convene bank executives; administration briefed
GOVERNMENT / US / SFist / Reuters · graded B2
14 Apr 2026
UK AISI publishes independent Mythos evaluation: 73% expert CTFs; 27 of 32 on network sim
EVAL / UK / UK AISI · graded A1
14 Apr 2026
OpenAI expands TAC and launches GPT-5.4-Cyber — binary RE, broad verified access
OPENAI / US / OpenAI · graded A2
13 Apr 2026
Industry skepticism on the find-vs-fix remediation gap surfaces
ANTHROPIC / n/a / Fortune / InfoQ · graded C3
07 Apr 2026
Anthropic announces Mythos Preview and Project Glasswing (~11 core partners; $100M credits)
ANTHROPIC / US / Anthropic · graded A2
26 Mar 2026
Fortune leaks Mythos from an unsecured data cache, revealing the 'Capybara' tier
OPENAI / US / Fortune · graded B2
15 Feb 2026
OpenAI quietly launches TAC and a $10M cybersecurity grant on GPT-5.3-Codex
OPENAI / US / OpenAI · graded B2

Evidence Register

8 sources · graded
SourceDetailsTypeAdmiraltyDate
UK AISI — Mythos evaluation73% expert-level CTFs; 27 of 32 steps on network sim; scales with inference computeIndependent evalA1Apr 2026
Anthropic Red Team — exploit benchmark181 working Firefox JS-engine exploits vs predecessor's 2 (~90×); control-flow hijacksPrimary · LabA1Apr 2026
Anthropic Red Team — capability scopeZero-day chains across every major OS and browser; oldest a 27-year-old OpenBSD bugPrimary · LabA2Apr 2026
Anthropic Red Team — emergenceCapabilities emerged from general code/reasoning/autonomy gains, not cyber trainingPrimary · LabA2Apr 2026
Fortune — remediation gapOver 99% of Mythos-discovered vulns unpatched; finding easier than fixingTrade pressC3Apr 2026
Help Net Security — GPT-5.4-CyberCyber-permissive variant; lowered refusal boundaries; binary reverse engineeringTrade pressB2Apr 2026
Channels TV / Reuters — access philosophyOpenAI: centrally deciding who gets to defend themselves is neither practical nor appropriateWireA2Apr 2026
SFist / Reuters — government responseTreasury and Fed convene banks; JPMorgan calls Glasswing an early-stage opportunityWireB2Apr 2026
Graded on NATO Admiralty source qualification (STANAG 2511) · Berkeley-Protocol chain of custody · ICD 203 estimative language · Open-source assessment. Not investment or legal advice.