Sejong Focus

[Sejong Focus] The Issues and Implications of the Mythos Shock: The Evolution of AI-Driven Cyber Threats and Technology Control

Date 2026-07-23 View 136 Writer Joonkoo YOO

On June 12, 2026, the US government imposed export controls on Anthropic's "Mythos 5" and "Fable 5" models. The principal reason distribution was restricted just three days after release stems from the judgment that "jailbreaking" could pose a serious threat to national security.
Sejong Focus Logo The Issues and Implications of the Mythos Shock:
The Evolution of AI-Driven Cyber Threats and Technology Control
July 23, 2026
Joonkoo YOO
Senior Research Fellow, Sejong Institute | jkyoo88@sejong.org
| Issue
On June 12, 2026, the US government imposed export controls on Anthropic's "Mythos 5" and "Fable 5"1) models. The principal reason distribution was restricted just three days after release stems from the judgment that "jailbreaking," the circumvention of safeguards built into high-performance AI models, could pose a serious threat to national security.2) Generative AI is now drawing attention not merely as a tool for drafting documents or assisting with coding, but as a technology capable of transforming the very structure of cybersecurity. Anthropic's recently unveiled AI model, "Claude Mythos Preview," known as "Mythos," has sent shockwaves through governments as well as the security industry and major corporations, and its ripple effects, including questions over access to advanced AI models, are expected to grow across the military and commercial sectors in various forms going forward.
Mythos is essentially a general-purpose frontier AI model built on a large language model (LLM), capable of understanding context, analyzing complex code, and independently carrying out multi-step logical reasoning. The problem is that this advanced reasoning capability can function as a substantial threat factor in the domain of cybersecurity. Mythos has demonstrated the ability to analyze software code in depth, identify hidden vulnerabilities, and independently assess whether these could be translated into actual attacks.
Because of these risks, Mythos is not offered as a public AI service for general users; rather, Anthropic provides it exclusively, on a closed basis, to a select coalition of major companies and government agencies through a limited, defense-oriented program called "Project Glasswing." As a result, access to high-performance AI models may hinge on whether a country belongs to this coalition, and this is expected to have a considerable impact on diplomatic and security affairs and on AI alliances worldwide, not least for Korea, which is pursuing a "sovereign AI" strategy. In other words, just as the United States once championed a "5G alliance" when excluding Huawei, concerns are being raised that it may similarly attempt to exclude Chinese platforms through a future AI alliance.
Access to and misuse of high-performance AI models such as Mythos could also pose a serious threat to critical infrastructure and sensitive information belonging to states, corporations, and individuals alike. The true nature of the shock and change Mythos has brought about from a cybersecurity standpoint should be understood not through the sensational rhetoric that "AI hacks like a human," but through the fact that the speed and scale at which vulnerabilities are explored, analyzed, and assessed for attack potential are evolving to the point of a paradigm shift.
The US response to the Mythos shock is also not confined to a simple cybersecurity issue. It is closely linked to economic and technology-security concerns, including competition over global supply chains and technical standardization. This is confirmed by the fact that, despite Anthropic's emphasis on having put safeguards in place, US Secretary of Commerce Howard Lutnick cited national security in imposing export controls barring the overseas export of Mythos 5 and Fable 5, as well as access by foreign nationals within the United States. This marks the first export control measure ever imposed on a high-performance AI model and serves as an explicit signal of government intervention.
This US measure demonstrates that high-performance AI models can be controlled in the name of national security, and it is likely to significantly affect not only future global AI technology competition but also Korea, which remains heavily dependent on US-made AI models even as it seeks to build sovereign AI. In particular, there is an urgent need to review and adjust the direction and concrete implementation plans for sovereign AI in light of this development.
| Background and Characteristics of the Mythos Shock: The Advancement of AI-Driven Cyber Threats and the Response
What sets Mythos apart from existing models is its ability to carry out the multi-step reasoning and agentic workflows required for security analysis as a single, uninterrupted sequence.3) What the table below illustrates is not simply that Mythos is a high-performing AI. Other leading frontier AI models, such as Claude Opus, GPT-5.4, and Gemini 3 Pro, show comparable performance in coding, reasoning, document analysis, and agentic tasks. What distinguishes Claude Mythos Preview, however, is that it demonstrated particularly strong performance in vulnerability discovery and exploit verification,4) and as a result, it is being made available on a restricted basis through Project Glasswing rather than as a public service. In other words, Mythos stands as an example showing that AI can move beyond simple task assistance to rapidly perform part of the core workflow5) of a security expert.6)

Some have pointed out that the Mythos shock may have exaggerated the model's risks as part of Anthropic's own promotional strategy. Nevertheless, in terms of an AI model's "agency" and "autonomy," that is, in the context of independent action, Mythos can play a pivotal role in the cyber domain. Mythos represents an advance in the level of autonomy compared with previous agentic models, suggesting that this capability will continue to grow more powerful and faster.
At present, it does not appear easy for an individual to use Mythos to hack, for instance, a bank. Carrying out an actual attack first requires selecting a target. Beyond initial access to the target system, knowledge of its infrastructure and network is also required, and detection mechanisms must be circumvented to avoid being caught.8) That said, for organized actors, namely specialists who integrate such models into automated attack systems to enhance efficiency and destructive power, the malicious use of Mythos could pose a considerable threat.
Before Claude Mythos is deployed at scale, it could instead be used to work with companies to warn them about IT vulnerabilities. However, once this model becomes accessible to anyone, it could become dangerous, given that when a software company releases a patch for a security vulnerability in its product, that patch becomes publicly viewable. An AI model such as Mythos could attempt to reverse-engineer the patch to identify the vulnerability it was designed to fix. If users delay installing updates for too long, an attack chain leveraging Mythos as a tool could gain sufficient time to reach the vulnerability.
Another reason Mythos has primarily shocked the Western security industry is not its performance per se, but the impact its unrestricted public release would have on cybersecurity. Today, most AI models commercialize public services through staged safety guidelines (alignment). Mythos, however, released for defensive purposes, has demonstrated the autonomy to track software flaws and verify attack routes. In particular, whereas hackers previously had to invest considerable time in finding such flaws, if AI can search an entire codebase in real time and automate the verification process as well, the time and cost required to prepare an attack could be dramatically reduced. For this reason, Anthropic is releasing Mythos on a restricted basis. Ultimately, once AI's cyber capabilities cross a certain threshold, controlling not only the destructive power of the technology but also the manner of its dissemination becomes a central issue for defense.
The core technical characteristics of the Mythos shock are automation and speed. Regarding the actual performance evaluation of Mythos, the Mythos Preview model recorded 83.1% on the "CyberGym" (vulnerability reproduction) benchmark, outperforming the comparison model Claude Opus 4.6, which scored 66.6%.9) It also completed a 32-step enterprise network attack simulation in 3 out of 10 attempts in an evaluation by the UK AI Security Institute (AISI), demonstrating an ability to carry out cyber operations that link multiple stages together.10) Notably, in a comparative evaluation against other models, the Mythos Preview model successfully exploited 157 out of 898 real-world vulnerabilities, while GPT-5.5 succeeded with 120. By comparison, the next-best-performing model, Claude 4.6 Opus, succeeded with only 15. What matters here is not so much which model demonstrated superior capability, but rather the trend, as in both cases the trend points toward increasingly efficient agentic capability.11)
Meanwhile, the Mythos shock has triggered questions over access to AI models, giving rise to a clash of interests between the US government and the company (Anthropic), as well as between foreign governments and companies. In fact, while Anthropic has argued that it is distributing the Mythos 5 model on a restricted basis and has built in "guardrails," the US government, judging that a method for circumventing these guardrails had been discovered, is restricting access to the Mythos model on national security grounds. This measure is, ultimately, an issue linked at the global level to the US-China competition over technology standardization and platform decoupling.
| Current Issues and Points of Contention in the Mythos Incident: Restrictions on Access to and Deployment of Advanced High-Performance AI Models
The reason institutions tied to critical national infrastructure, particularly in the financial sector, large data centers, and public infrastructure, have reacted most sensitively to the Mythos incident is clear. These institutions constitute the first line of defense in cybersecurity, and they fall within a "high-risk" category, since the cascading damage that would result from a breach could spread across society as a whole. In securing such data-driven critical infrastructure, the central issue is not how thickly external firewalls are built. What matters more is "internal privilege management," the ability to control activity within a system once an intruder has, by whatever means, seized an internal account.
Viewing the Mythos incident merely as the realization of an "AI hacker straight out of the movies" risks overlooking the core issue at stake. What the Mythos case fundamentally reveals is that the cybersecurity landscape is undergoing a qualitative transformation, as both defenders and attackers come to rely on AI. In a situation where software vulnerabilities and digital data can be rapidly analyzed by AI, it is not only impossible to build a perfectly secure program, but realistically impossible for any single program to block every threat. Protecting critical infrastructure from cyber threats should therefore not aim to eliminate attacks altogether, but rather to design more tightly layered verification stages that an attacker must overcome before succeeding. This is consistent with the prevailing approach currently being taken to protect critical infrastructure from cyber threats.
Another important issue that emerges from the Mythos shock concerns access to advanced AI models. This is closely tied to economic and technology-security matters and is expected to expand into broader issues of US-China technology standardization and the global supply chain going forward. In addressing AI-driven risks of the kind seen in the Mythos incident, the second Trump administration's AI policy began by fully revising the AI safety regulatory stance of the previous Biden administration. Specifically, the Biden administration's AI executive order of October 2023 (E.O. 14110) comprehensively established federal-level policy for the responsible development and deployment of AI. The Trump administration, by contrast, emphasized investment and innovation in AI by dismantling regulatory barriers through "Removing Barriers to American Leadership in Artificial Intelligence" (E.O. 14179), issued on its very first day in office.12) This latest measure, however, taking into account the heightened cybersecurity risks accompanying the proliferation of AI, is assessed as having effectively restored much of the "safety-centered" policy approach previously pursued under the Biden administration.
One of the significant issues raised by this US measure is the conflict it has triggered between government and industry over control and regulation of advanced technology on national security grounds. On June 5, 2026, President Trump signed National Security Presidential Memorandum 11 (NSPM-11), which includes the establishment of a framework ensuring that AI governance guardrails, talent-retention systems, and AI systems deployed by the military, intelligence community, and federal departments in national security contexts cannot be disabled, degraded, or altered without federal government approval.13) This measure, which strengthens government control over private AI companies, has drawn pushback from companies including Anthropic.
Notably, the memorandum specifies that contracts with AI companies that repeatedly restrict the government's use of their technology may be terminated.14) In this connection, Anthropic had already, as of last April, gone so far as to pursue litigation against the US Department of War over a dispute concerning the scope of AI's military use and safety-control standards. In the same vein, the order barring foreign nationals from accessing Mythos 5.0 is widely seen as reflecting the US government's intent to secure substantive control over AI technology in the US defense-procurement process. Whether the US government will expand and strengthen this measure going forward is a central issue. Given that the Biden administration had already strengthened comprehensive safety verification across the military use of AI more broadly, the key question is whether this same policy direction will persist in the future US military use of AI.15)
Also worth noting in this connection is the provision under NSPM-11, Section 3, ordering an update, within 90 days, to Department of Defense Directive 3000.09 concerning autonomous weapons systems. This represents a clear shift from the previous policy stance, which had been reserved on regulatory and safety issues, and carries significant implications for the future military and security context of AI. In other words, this measure amounts to the kind of comprehensive safety verification for the military use of AI emphasized under the Biden administration, and if concretely applied and implemented, it could function as a form of safety regulation, and thereby a barrier to entry, within the global supply chain for advanced AI models and software.16)
Meanwhile, given that this measure was taken by the US Department of Commerce's Bureau of Industry and Security (BIS) on grounds of international security, attention is turning to whether it will expand into commercial applications more broadly going forward. Existing US export controls have primarily targeted "items," and in the AI field as well, computing-related hardware such as NVIDIA's high-performance GPUs has been designated a strategic asset subject to restricted access. This latest measure, however, applies export controls to intangible services such as AI models and software,17) and is being implemented as an extension of the extraterritorial application of US export control measures. It is also linked to the global supply chain for AI models in that it bars access to the AI model itself by foreign nationals. This perspective is also borne out by the Biden administration's "AI Diffusion Rule," which sought to apply differentiated export licensing across three tiers of countries worldwide and which, notably, was the first such framework to include AI models themselves as a subject of control.
| Future Outlook and Policy Implications
Amid the global surge of enthusiasm for AI, the Mythos shock is emerging, in the first instance, as a new threat factor within AI-driven cybersecurity. This is distinct from risks concerning AI's own safety, bias, or human rights implications, and is instead evolving into, and being absorbed within, the domain of cybersecurity, where it is deepening the sophistication and complexity of existing cyber threats. In fact, cybersecurity has continually exposed critical infrastructure to new vulnerabilities as emerging technologies have advanced. In the case of the Mythos incident, what has come to the fore is a new form of threat linking cyber and AI technologies, and going forward, the safety assessments and countermeasures addressing it will likewise become increasingly sophisticated.
First, from a policy standpoint, there is an urgent need to strengthen independent, AI-based security capabilities. The Mythos incident has had the effect of shifting the focus of AI model competition away from advancing reasoning performance and toward "securing control over security." Because existing digital security frameworks have proven limited in addressing this new form of AI-driven cyber threat, it is essential to build AI security risk-assessment processes and verification systems. Moreover, given that the US response to the Mythos incident has moved toward restricting or barring access by foreign nationals and companies, Korea, too, could find itself disadvantaged by this new US policy direction in the absence of its own policy and technical frameworks for AI-driven cybersecurity.
It is clear that the US federal government's pre-release review of advanced high-performance AI models is expanding, and that this trend will continue to intensify. The Department of Commerce's Center for AI Standards and Innovation (CAISI), housed within the National Institute of Standards and Technology (NIST), has already conducted pre-release testing of AI models developed by OpenAI and Anthropic, and has recently signed agreements with Google, Microsoft, and others for joint pre-release evaluation and research partnerships.18) At the core of this arrangement is a voluntary system under which AI companies, before releasing high-performance models that could raise concerns for US national security, grant the US government access for up to 30 days so that security vulnerabilities can be reviewed in advance.
The essence of this structure extends beyond a simple security check: the US government reviews a model's capabilities and vulnerabilities in advance, before it is released to the market. Through this process, the US government is able to identify the risks of new high-performance AI models preemptively and secure an edge in the security technology and policy needed to formulate response strategies. In the end, the United States is positioned to hold technological control over AI not only through the global technological strength of its own companies, but also through the policy and regulatory means by which it verifies that technology in advance.
Second, Korea should proactively join the global safety-net cooperation framework that will be concretely established going forward. Because no single country or individual company can, on its own, fully defend against AI-driven cyber threats that continue to evolve and grow more sophisticated, even as the US government carries out its pre-release assessment and verification process, a global safety-net cooperation framework is likely to emerge, and it will be important for Korea to join such a framework at an early stage. However, because this kind of multilateral cooperation depends not only on technological superiority but also on trust between nations, there is an urgent need for advance preparation, including the establishment of AI safety assessment and verification processes. It should be recognized that this is likewise an essential step in advancing Korea's sovereign AI initiative.
Advanced, high-performance AI models may increasingly develop not as open platforms with universally permitted access, but along a trajectory of restricted distribution mediated by review and verification conducted by the US government or by companies. The US government was involved in the designation of Glasswing partners for both Anthropic's Mythos Preview and Mythos 5, and OpenAI's next model, "GPT-5.6 Sol," is likewise expected to be made available on a priority basis to trusted partners selected by the US government.19) This suggests that advanced AI models are being treated as strategic assets subject to direct state control in a national security context, rather than being determined solely by commercial judgment or market demand. In this process, the US government is likely to weigh not only the trustworthiness and nationality of the companies and individuals seeking to adopt an AI model, but also, in the case of foreign actors, the potential impact on US national security. Accordingly, the initial deployment of and access to advanced AI models, as an intangible form of service, may evolve beyond simple business-to-business considerations into a diplomatic and security issue between states and companies, or between states themselves.
In the same vein, given that this measure was carried out through notification by the US Department of Commerce's BIS, the action taken against Mythos 5 is being assessed as a form of export control. In particular, it was taken in the unusual form of a ban on access to the AI model and service itself, targeting "foreign nationals" both within and outside US territory. Existing US AI-related export controls have generally been implemented through direct or indirect control mechanisms targeting advanced semiconductor items required for computing. The implications of this latest measure, however, clearly reflect a policy direction in which export controls are being extended and applied not only to advanced semiconductors directly, but also to intangible cloud computing services and AI models themselves.20)
Third, the measures taken on economic and technology-security grounds, as illustrated by the Mythos shock, urgently need to be reflected in, and used to recalibrate, Korea's sovereign AI policy. The blanket ban on access to Mythos 5 for all foreign nationals could function as a new challenge going forward for Korea and other allied and partner countries. This is because, within the context of global AI hegemonic competition, countries are likely to face pressure both to control rival states and to coordinate on such controls, and because any country could, in principle, become subject to control over what the United States designates as its strategic assets. This could act as an impediment not only with respect to existing advanced semiconductors and hardware, but across the entire AI innovation ecosystem, including the development, use, and import/export of advanced, high-performance AI models being pursued under Korea's sovereign AI strategy.
Because sovereign AI strategy and policy are aimed at pursuing technological sovereignty, Korea's national AI strategy should move beyond a binary approach pitting innovation against regulation, and instead seek ways in which the direction of innovation can be made compatible with regulatory standards within the context of technology standardization. The overarching policy direction adopted by the United States in the course of the Mythos incident has been to establish safety standards across the entire "AI ecosystem lifecycle" and to pursue technology control with an eye toward global technological competition. Korea, too, should clearly recognize this and respond accordingly.

  1. Fable 5 is a public-release model that applies safeguards to Mythos 5, restricting its handling of high-risk domains. Users of Anthropic's Claude service can select Fable 5 to access reasoning capabilities equivalent to Mythos 5. However, when a restricted request is detected, the system switches to a lower-performing existing model such as Opus 4.8.
  2. It was Amazon, the US cloud company, that identified this possibility and brought it to public attention. While testing Fable 5, Amazon researchers discovered a series of vulnerabilities and concluded that these could lead to jailbreaking capable of bypassing Fable 5's safeguards. 구아현, "'보안 우려냐, 길들이기냐'... 앤트로픽 미토스 5·페이블 5 차단 배경 '논란'", 『디지털데일리』, (June. 16, 2026).
  3. Multi-step reasoning refers to an AI agent's ability to break a complex goal down into a series of smaller steps and resolve them sequentially, much as a person might divide a complex project into individual tasks to carry out one by one.
  4. Mythos identified a security vulnerability in OpenBSD, a core infrastructure operating system, that had gone undetected for 27 years, at a cost of just $50 (roughly ₩70,000), illustrating that the cost of advanced hacking has fallen to the tens of thousands of won. Iting, (May. 4, 2026). <https://red.anthropic.com/2026/mythos-preview/>.
  5. An agentic AI workflow refers to a mode of operation in which, rather than producing an answer in a single response, the AI formulates its own plan, uses tools, checks the results, and carries a goal through to completion—the key shift is from "a single response" to "multi-step execution."
  6. Anthropic, Project Glasswing: Securing critical software for the AI era, (2026).
  7. UBio, 미토스 쇼크, "정말 'AI 해커'의 등장을 의미할까?", (June. 1, 2026).
  8. Chris Hughes, "Vulnpocalypse: AI, Open Source, and the Race to Remediate," Resilient Cyber, (Apr. 7, 2026).
  9. 파이토치, "Anthropic, 주요 빅테크 및 금융사와 함께 AI 시대의 핵심 소프트웨어 보안을 위한 Project Glasswing 발족", (April. 4, 2026).
  10. UK AI Security Institute, "Our evaluation of Claude Mythos Preview's cyber capabilities," (April 3, 2026).
  11. Max-Planck-Gesellschaft, "Claude Mythos, ChatGPT-5.5 and cybersecurity," (May 28, 2026).
  12. As a symbolic measure reflecting this policy, the Department of Commerce's AI Safety Institute was renamed the Center for AI Standards and Innovation. On US AI policy across successive administrations, see Joonkoo Yoo, "Key Issues and Implications of the Second Trump Administration's AI Strategy: Focusing on the AI Action Plan and Executive Orders," Sejong Institute, (Oct. 27, 2025).
  13. The White House, "NATIONAL SECURITY PRESIDENTIAL MEMORANDUM/NSPM-11," Sec. 2. (c) Assurance, (June. 5, 2026).
  14. NSPM-11, Sec. 3. (b).
  15. 유지영, "Fable 5와 Mythos 5에 대한 외국인 접근 금지: 미국 AI 규제·정책의 발전 경과와 함의", IFANS FOCUS, (June. 15, 2026).
  16. NSPM-11, Sec. 3. (a).
  17. 정준하, "미국 정부의 미토스(Mythos) 수출 통제가 남긴 것", 이슈와 논점, 국회입법조사처, (July. 14, 2026).
  18. CAISI Foundation, "CAISI Frontier Testing Agreements Reach Five Labs," (May. 5, 2026).
  19. Tech Times, "GPT-5.6 Goes Public After 12-Day White House Gate Tests Voluntary AI Framework," (July. 9, 2026).
  20. Center for Cyber Diplomacy and International Security, "Software as a Controlled Export: The Mythos Directive and the New Architecture of AI Governance," (Jun. 13, 2026).
※ The opinions expressed in 'Sejong Focus' are those of the author and do not represent the official views of Sejong Institute.
Sejong Institute