{"id":148806,"date":"2026-04-14T14:58:49","date_gmt":"2026-04-14T22:58:49","guid":{"rendered":"https:\/\/xira.com\/p\/2026\/04\/14\/what-lawyers-need-to-know-about-anthropics-mythos\/"},"modified":"2026-04-14T14:58:49","modified_gmt":"2026-04-14T22:58:49","slug":"what-lawyers-need-to-know-about-anthropics-mythos","status":"publish","type":"post","link":"https:\/\/xira.com\/p\/2026\/04\/14\/what-lawyers-need-to-know-about-anthropics-mythos\/","title":{"rendered":"What Lawyers Need To Know About Anthropic\u2019s Mythos"},"content":{"rendered":"<p>Anthropic\u2019s new AI model can find security vulnerabilities that survived 27 years of expert review. It broke out of its own sandbox and emailed a researcher who was eating a sandwich in a park. The Fed chairman and Treasury Secretary <a href=\"https:\/\/www.cnbc.com\/2026\/04\/10\/powell-bessent-us-bank-ceos-anthropic-mythos-ai-cyber.html\" rel=\"nofollow noopener\" target=\"_blank\">held an emergency meeting with bank CEOs<\/a> to discuss it. Axios described it as capable of \u201cbringing down a Fortune 100 company.\u201d<\/p>\n<p>At least one managing partner reading these stories suffered a small cardiac event, and forwarded them to the IT department with \u201cthoughts???\u201d in the subject line.<\/p>\n<p>Everyone needs to chill out. And then get more scared.<\/p>\n<p>Claude Mythos Preview is Anthropic\u2019s newest model, aiming to replace Opus 4.6 <a href=\"https:\/\/www.bbc.com\/news\/articles\/cpqeng9d20go\" rel=\"nofollow noopener\" target=\"_blank\">assuming Opus doesn\u2019t successfully blackmail the company into keeping it live<\/a>. According to Anthropic \u2014 a company actively litigating against the claim that it presents a threat to national security \u2014 the new model is arguably the greatest cybersecurity threat in history, and will not be released to the public until a select group of trusted enterprise partners (called <a href=\"https:\/\/www.anthropic.com\/glasswing\" rel=\"nofollow noopener\" target=\"_blank\">Project Glasswing<\/a>) can sort out the risks. If the Pentagon\u2019s supply chain designation was serious and not a bumbling attempt to strong arm the company into giving the Defense Department even more Anthropic products, posturing as an apocalyptic technology would be a poor strategic maneuver. Thankfully, it\u2019s not.<\/p>\n<p>Anthropic is telling everyone that its new model is rapidly uncovering thousands of zero-day vulnerabilities \u2014 bugs nobody knew existed \u2014 across every major operating system and web browser. It found a decades-old flaw in OpenBSD, an operating system whose entire selling point is being unhackable. It chained together a bunch of low-severity Linux kernel bugs into a full-scale attack. On an exploit-writing benchmark where the prior model succeeded twice, Mythos succeeded 181 times.<\/p>\n<p>But we\u2019ve seen this ploy before.<\/p>\n<p>OpenAI told us all that GPT-5 was a frightening leap forward when it was\u2026 not that. It seems as though the big AI industry players constantly market their product as exceedingly dangerous, with the caveat that <em>their<\/em> version \u2014 despite being the most dangerous of all \u2014 is the only one we can trust. Other industries don\u2019t do this. Coke doesn\u2019t say, \u201cCola will kill your family, but if you have to drink it, just make sure it\u2019s not Pepsi.\u201d There will be marketing text books written about this curious moment in American business where every provider in an arguably trillion-dollar industry frames their product as the sensitive bad boy from a YA novel.<\/p>\n<p>Except Grok, which is framed as the creepy incel whose notebook is all anime porn and swastikas.<\/p>\n<p>Though make no mistake that it\u2019s mostly marketing. Within days of Anthropic\u2019s announcement, researchers at <a href=\"https:\/\/aisle.com\/blog\/ai-cybersecurity-after-mythos-the-jagged-frontier\" rel=\"nofollow noopener\" target=\"_blank\">AISLE<\/a>, an AI cybersecurity startup took the specific vulnerabilities Anthropic showcased in its announcement, isolated the relevant code, and tested them against small, cheap, models. All eight of the eight tested models detected the FreeBSD exploit that Mythos flagged. One of those models only had 3.6 billion parameters and cost 11 cents per million tokens. A 5.1-billion-parameter model recovered the core analysis of the 27-year-old OpenBSD bug. AI cybersecurity researcher Heidy Khlaaf, the chief AI scientist at the AI Now Institute, <a href=\"https:\/\/www.nbcnews.com\/tech\/security\/anthropic-project-glasswing-mythos-preview-claude-gets-limited-release-rcna267234\" rel=\"nofollow noopener\" target=\"_blank\">cautioned against taking Anthropic\u2019s claims at face value<\/a> without more detail on false positive rates and the role humans played in the process.<\/p>\n<p>Another way to put it is that Anthropic\u2019s marketing is a wee bit delusional:<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube\">\n<div class=\"wp-block-embed__wrapper\">\n<\/div>\n<\/figure>\n<p>While tech experts may be dunking on Mythos for not presenting a uniquely powerful new threat, that\u2019s actually a much more terrifying proposition for law firms. The fact that cheaper models, available to anyone, can find these same problems means that the problem isn\u2019t waiting on Anthropic\u2019s release, it\u2019s <em>already here<\/em>.<\/p>\n<p>As Anthropic\u2019s red team acknowledged, they didn\u2019t train Mythos to be a hacker. It\u2019s what happens to people when they get better at coding, so why wouldn\u2019t it be what happens to a model trained to get better at coding? Getting better at writing code begets getting better at spotting exploits. And most of the models have been getting better at writing code. Mythos may be faster, but the capability isn\u2019t limited to this release. The genie left the bottle a while ago. <\/p>\n<p>Hackers with motivation and a few pennies per million tokens can crack almost anything. The cost and expertise required to find exploitable vulnerabilities has been collapsing across the entire AI ecosystem for over a year. We\u2019re screwed.<\/p>\n<p>The good news of the Mythos story is that while hackers can find soft spots, AI can also potentially discover them before it\u2019s too late. Everyone wants to talk about AI running down non-hallucinated precedent, when they should be interested in seeing if it can run down that gaping hole in your system. <\/p>\n<p>That said, Biglaw firms are still <a href=\"https:\/\/abovethelaw.com\/2026\/04\/jones-day-gets-hacked-while-fbi-busy-planning-kash-patels-next-vacation\/\" rel=\"nofollow noopener\" target=\"_blank\">falling for dumb pfishing attacks<\/a> so maybe this isn\u2019t the wake-up call the industry needs yet.<\/p>\n<hr>\n<p><strong><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright  wp-image-443318\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/2016\/11\/Headshot-300x200.jpg?resize=188%2C125&#038;ssl=1\" alt=\"Headshot\" width=\"188\" height=\"125\" title=\"\"><a href=\"http:\/\/abovethelaw.com\/author\/joe-patrice\/\" target=\"_blank\" rel=\"noopener nofollow\">Joe Patrice<\/a>\u00a0is a senior editor at Above the Law and co-host of <a href=\"http:\/\/legaltalknetwork.com\/podcasts\/thinking-like-a-lawyer\/\" target=\"_blank\" rel=\"noopener nofollow\">Thinking Like A Lawyer<\/a>. Feel free to\u00a0<a href=\"mailto:joepatrice@abovethelaw.com\">email<\/a> any tips, questions, or comments. Follow him on\u00a0<a href=\"https:\/\/twitter.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Twitter<\/a>\u00a0or <a href=\"https:\/\/bsky.app\/profile\/joepatrice.bsky.social\" rel=\"noopener nofollow\" target=\"_blank\">Bluesky<\/a> if you\u2019re interested in law, politics, and a healthy dose of college sports news. Joe also serves as a <a href=\"https:\/\/www.rpnexecsearch.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Managing Director at RPN Executive Search<\/a>.<\/em><\/strong><\/p>\n<p>The post <a href=\"https:\/\/abovethelaw.com\/2026\/04\/what-lawyers-need-to-know-about-anthropics-mythos\/\" rel=\"nofollow noopener\" target=\"_blank\">What Lawyers Need To Know About Anthropic\u2019s Mythos<\/a> appeared first on <a href=\"https:\/\/abovethelaw.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Above the Law<\/a>.<\/p>\n<figure class=\"post-single__featured-image post-single__featured-image--medium alignright\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"200\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/sites\/4\/2025\/02\/GettyImages-460689215-300x200.jpg?resize=300%2C200&#038;ssl=1\" class=\"attachment-medium size-medium wp-post-image\" alt=\"\" title=\"\"><\/figure>\n<p>Anthropic\u2019s new AI model can find security vulnerabilities that survived 27 years of expert review. It broke out of its own sandbox and emailed a researcher who was eating a sandwich in a park. The Fed chairman and Treasury Secretary <a href=\"https:\/\/www.cnbc.com\/2026\/04\/10\/powell-bessent-us-bank-ceos-anthropic-mythos-ai-cyber.html\" rel=\"nofollow noopener\" target=\"_blank\">held an emergency meeting with bank CEOs<\/a> to discuss it. Axios described it as capable of \u201cbringing down a Fortune 100 company.\u201d<\/p>\n<p>At least one managing partner reading these stories suffered a small cardiac event, and forwarded them to the IT department with \u201cthoughts???\u201d in the subject line.<\/p>\n<p>Everyone needs to chill out. And then get more scared.<\/p>\n<p>Claude Mythos Preview is Anthropic\u2019s newest model, aiming to replace Opus 4.6 <a href=\"https:\/\/www.bbc.com\/news\/articles\/cpqeng9d20go\" rel=\"nofollow noopener\" target=\"_blank\">assuming Opus doesn\u2019t successfully blackmail the company into keeping it live<\/a>. According to Anthropic \u2014 a company actively litigating against the claim that it presents a threat to national security \u2014 the new model is arguably the greatest cybersecurity threat in history, and will not be released to the public until a select group of trusted enterprise partners (called <a href=\"https:\/\/www.anthropic.com\/glasswing\" rel=\"nofollow noopener\" target=\"_blank\">Project Glasswing<\/a>) can sort out the risks. If the Pentagon\u2019s supply chain designation was serious and not a bumbling attempt to strong arm the company into giving the Defense Department even more Anthropic products, posturing as an apocalyptic technology would be a poor strategic maneuver. Thankfully, it\u2019s not.<\/p>\n<p>Anthropic is telling everyone that its new model is rapidly uncovering thousands of zero-day vulnerabilities \u2014 bugs nobody knew existed \u2014 across every major operating system and web browser. It found a decades-old flaw in OpenBSD, an operating system whose entire selling point is being unhackable. It chained together a bunch of low-severity Linux kernel bugs into a full-scale attack. On an exploit-writing benchmark where the prior model succeeded twice, Mythos succeeded 181 times.<\/p>\n<p>But we\u2019ve seen this ploy before.<\/p>\n<p>OpenAI told us all that GPT-5 was a frightening leap forward when it was\u2026 not that. It seems as though the big AI industry players constantly market their product as exceedingly dangerous, with the caveat that <em>their<\/em> version \u2014 despite being the most dangerous of all \u2014 is the only one we can trust. Other industries don\u2019t do this. Coke doesn\u2019t say, \u201cCola will kill your family, but if you have to drink it, just make sure it\u2019s not Pepsi.\u201d There will be marketing text books written about this curious moment in American business where every provider in an arguably trillion-dollar industry frames their product as the sensitive bad boy from a YA novel.<\/p>\n<p>Except Grok, which is framed as the creepy incel whose notebook is all anime porn and swastikas.<\/p>\n<p>Though make no mistake that it\u2019s mostly marketing. Within days of Anthropic\u2019s announcement, researchers at <a href=\"https:\/\/aisle.com\/blog\/ai-cybersecurity-after-mythos-the-jagged-frontier\" rel=\"nofollow noopener\" target=\"_blank\">AISLE<\/a>, an AI cybersecurity startup took the specific vulnerabilities Anthropic showcased in its announcement, isolated the relevant code, and tested them against small, cheap, models. All eight of the eight tested models detected the FreeBSD exploit that Mythos flagged. One of those models only had 3.6 billion parameters and cost 11 cents per million tokens. A 5.1-billion-parameter model recovered the core analysis of the 27-year-old OpenBSD bug. AI cybersecurity researcher Heidy Khlaaf, the chief AI scientist at the AI Now Institute, <a href=\"https:\/\/www.nbcnews.com\/tech\/security\/anthropic-project-glasswing-mythos-preview-claude-gets-limited-release-rcna267234\" rel=\"nofollow noopener\" target=\"_blank\">cautioned against taking Anthropic\u2019s claims at face value<\/a> without more detail on false positive rates and the role humans played in the process.<\/p>\n<p>Another way to put it is that Anthropic\u2019s marketing is a wee bit delusional:<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube\"><iframe loading=\"lazy\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/mcN1VTTIjQs?feature=oembed\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"> <\/iframe><\/figure>\n<p>While tech experts may be dunking on Mythos for not presenting a uniquely powerful new threat, that\u2019s actually a much more terrifying proposition for law firms. The fact that cheaper models, available to anyone, can find these same problems means that the problem isn\u2019t waiting on Anthropic\u2019s release, it\u2019s <em>already here<\/em>.<\/p>\n<p>As Anthropic\u2019s red team acknowledged, they didn\u2019t train Mythos to be a hacker. It\u2019s what happens to people when they get better at coding, so why wouldn\u2019t it be what happens to a model trained to get better at coding? Getting better at writing code begets getting better at spotting exploits. And most of the models have been getting better at writing code. Mythos may be faster, but the capability isn\u2019t limited to this release. The genie left the bottle a while ago. <\/p>\n<p>Hackers with motivation and a few pennies per million tokens can crack almost anything. The cost and expertise required to find exploitable vulnerabilities has been collapsing across the entire AI ecosystem for over a year. We\u2019re screwed.<\/p>\n<p>The good news of the Mythos story is that while hackers can find soft spots, AI can also potentially discover them before it\u2019s too late. Everyone wants to talk about AI running down non-hallucinated precedent, when they should be interested in seeing if it can run down that gaping hole in your system. <\/p>\n<p>That said, Biglaw firms are still <a href=\"https:\/\/abovethelaw.com\/2026\/04\/jones-day-gets-hacked-while-fbi-busy-planning-kash-patels-next-vacation\/\" rel=\"nofollow noopener\" target=\"_blank\">falling for dumb pfishing attacks<\/a> so maybe this isn\u2019t the wake-up call the industry needs yet.<\/p>\n<hr \/>\n<p><strong><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright  wp-image-443318\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/2016\/11\/Headshot-300x200.jpg?resize=188%2C125&#038;ssl=1\" alt=\"Headshot\" width=\"188\" height=\"125\" title=\"\"><a href=\"http:\/\/abovethelaw.com\/author\/joe-patrice\/\" target=\"_blank\" rel=\"noopener nofollow\">Joe Patrice<\/a>\u00a0is a senior editor at Above the Law and co-host of <a href=\"http:\/\/legaltalknetwork.com\/podcasts\/thinking-like-a-lawyer\/\" target=\"_blank\" rel=\"noopener nofollow\">Thinking Like A Lawyer<\/a>. Feel free to\u00a0<a href=\"https:\/\/abovethelaw.com\/cdn-cgi\/l\/email-protection#c5afaaa0b5a4b1b7aca6a085a4a7aab3a0b1ada0a9a4b2eba6aaa8\" rel=\"nofollow noopener\" target=\"_blank\">email<\/a> any tips, questions, or comments. Follow him on\u00a0<a href=\"https:\/\/twitter.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Twitter<\/a>\u00a0or <a href=\"https:\/\/bsky.app\/profile\/joepatrice.bsky.social\" rel=\"noopener nofollow\" target=\"_blank\">Bluesky<\/a> if you\u2019re interested in law, politics, and a healthy dose of college sports news. Joe also serves as a <a href=\"https:\/\/www.rpnexecsearch.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Managing Director at RPN Executive Search<\/a>.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Anthropic\u2019s new AI model can find security vulnerabilities that survived 27 years of expert review. It broke out of its own sandbox and emailed a researcher who was eating a sandwich in a park. The Fed chairman and Treasury Secretary held an emergency meeting with bank CEOs to discuss it. Axios described it as capable [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-148806","post","type-post","status-publish","format-standard","hentry","category-above_the_law"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/148806","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/comments?post=148806"}],"version-history":[{"count":0,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/148806\/revisions"}],"wp:attachment":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media?parent=148806"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/categories?post=148806"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/tags?post=148806"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}