AI DOERS
Book a Call
← All insightsAI Excellence

Why Anthropic Refuses to Release Claude Mythos

Anthropic built Claude Mythos, a frontier model that finds software vulnerabilities better than almost any human, and chose not to release it. Instead it shares gated access through Project Glasswing so companies can patch flaws before equally powerful models reach the wrong hands.

Why Anthropic Refuses to Release Claude Mythos
Illustration: AI DOERS Studio

Anthropic built something and decided not to let anyone have it. That is the sentence the AI industry spent most of this week processing. I am Madhuranjan Kumar, and the story matters more than most announcements of this type, because the specifics are verifiable and the mechanism producing the capability will not stay rare.

Anthropic found a 27-year-old bug in OpenBSD, and that is not the alarming part

The model is called Claude Mythos, and what it actually did in testing is where the story becomes real rather than just dramatic. Mythos identified a vulnerability in OpenBSD, an operating system famous in security circles for being one of the most rigorously audited codebases in existence, that had been sitting there undetected for 27 years. It found a 16-year-old flaw in FFmpeg, this breakdown processing library buried inside countless consumer applications and streaming services. It chained together multiple Linux kernel bugs to take full root control of a machine, working with almost no human guidance.

The benchmark numbers are equally significant. On the cybersecurity vulnerability reproduction test, Mythos hit 83.1 percent accuracy against 66.6 percent for Claude Opus 4.6. On SWE-bench Pro, the leading software engineering evaluation, it scored nearly 24 points higher than its predecessor. On SWE-bench Verified it jumped from 80 to 94. Those are step changes, not minor version improvements.

These are not aspirational claims about potential capabilities. They are specific findings about specific real systems that exist and have been checked by independent researchers. A 27-year-old OpenBSD bug is either documented or it is not. The specificity is the credibility.

How it works (short)

The safety-first framing deserves both skepticism and respect

There is a pattern worth naming alongside the genuine concern. When OpenAI held back GPT-2 in 2019, citing danger, the model eventually proved manageable and was released without incident. The too-dangerous-to-release narrative also helps a lab raise capital, attract talent, and build pent-up interest before an eventual release. Both things can be true simultaneously: the specific capabilities Mythos demonstrated are real and documented, and the announcement also serves Anthropic's commercial interests in specific ways.

The skepticism does not cancel the concern. It calibrates it. The right response is not dismissal and not panic. It is recognizing that a real technical development happened, that the framing around it involves commercial dynamics as well as genuine safety reasoning, and that the practical implications for businesses run independently of whether Mythos ever ships to the public.

Project Glasswing is the part worth examining most carefully. Rather than a general release, Anthropic gave gated access to a selected group of companies with one explicit instruction: use this to find and patch flaws in your own software before any wider release. They also published an unusually detailed system card for something they chose not to ship. That combination suggests the lab believes the defensive use case is real and valuable even if the general release risk is too high. That is a more nuanced position than the headline suggests.

Vulnerability reproduction score (typical)

Cybersecurity capability is an emergent side effect of coding performance

The most significant technical fact in the Mythos story is the one Anthropic stated plainly and that most coverage buried: they did not train Mythos for cybersecurity. They trained it to be good at code, and the ability to find and chain vulnerabilities emerged as a consequence of that general coding competence.

That mechanism is what makes this story directly relevant to every business that has never thought about zero-days. The competitive race to build better coding models is running simultaneously at every major lab. Better coding comprehension means better ability to read any code, identify patterns, and find gaps. The model that tomorrow writes your team's internal tools more competently is the same kind of model that, at higher capability levels, finds flaws in those tools more reliably.

The open-weight model development the same week reinforces this. GLM 5.1, released under an open license and freely downloadable, scored higher than the prior Claude and GPT on software engineering benchmarks. A model at that capability level is available to anyone with appropriate hardware, not only to well-funded organizations. The tools capable of auditing code are becoming more accessible at roughly the same pace that frontier models are becoming more capable. The defensive window for unreviewed software is narrowing from both directions.

Meta's Muse Spark announcement from its Super Intelligence Labs, which moved from near-last to fourth on the Artificial Analysis capability index, is further context for the same trend. Multiple organizations are simultaneously advancing coding capability, and the side effect of that advance is better vulnerability-finding, regardless of whether that was anyone's intention.

The competitive landscape shifted in one week, and local businesses are not insulated

Anthropic's decision to cut third-party tool access to Claude subscriptions, cutting off tools like OpenClaw that burned through tokens on the Max plan, landed in the same week as the Mythos announcement. That decision frustrated builders who had structured workflows around those integrations. It also reveals something about where the economics of AI access are heading: labs will increasingly optimize their subscription tiers for their own platform rather than for third-party usage patterns. Businesses that built automations on top of AI subscriptions through third-party tools are getting a preview of a less permissive environment.

The Seedance 2.0 rollout in the US, filling the gap left by Sora's reduced availability, points at the same dynamic in a different domain. This breakdown generation market reorganized itself to serve demand that was going unmet. When one tool or platform becomes unavailable or expensive, the market reshuffles quickly and businesses that had built workflows around a single vendor face disruption. Diversification across tools matters more in a market moving this fast.

The week's through-line, across the Mythos story, the GLM 5.1 release, the Muse Spark launch, and the access policy change, is that the capability race is diffusing capability broadly while simultaneously concentrating access control at the platform level. The tools that find vulnerabilities are getting more capable and more accessible. The tools that individual businesses depend on for day-to-day operations are subject to unilateral policy changes from the labs that provide them.

The concrete move for a business sitting on customer data

The lesson from Mythos is not about accessing the model. It is about what the model's existence reveals: the class of tool capable of finding decades-old flaws in hardened software is arriving in consumer-accessible forms, and ordinary business software is less hardened than OpenBSD. The 27-year-old OpenBSD bug survived because the tools examining it were not capable enough to find it. Your business software has similar long-standing gaps that simply have not been examined at that capability level yet.

The practical steps are the same whether your business is a medical practice, an accounting firm, an agency, or a local service company. First, list every piece of software that touches customer data, including old internal tools that nobody maintains. Second, use a capable AI coding model, freely available at subscription costs most businesses already pay, to review your software for known vulnerability patterns and outdated dependencies. Third, patch in order of which findings could reach your most sensitive data, not in order of what is easiest to fix.

For a business that uses Google Ads and paid social campaigns and collects leads into a CRM, the software stack is typically the landing page, the form handler, the CRM integration, and whatever internal dashboards the team uses. Each of those is a surface that an automated scanner will probe. A quarterly review that identifies and closes the most obvious entry points in each of those surfaces is low-cost relative to what a data incident costs to resolve.

The Glasswing companies received something specific and rare: early access to a capability that will eventually be more widely available. The instruction they got is not scarce. Anyone can follow it: find your own flaws before someone else does, while the tools for doing so are still primarily in defensive hands. That window exists right now. It will not stay open indefinitely as the market for general-purpose coding models continues to develop.

Do it with an expert
You can build this yourself, or have it set up right the first time.

That is exactly what we do at AI DOERS. Book a private 30-minute call with Madhuranjan Kumar and we will map the fastest path to it for your specific business.

Book your call →
Madhuranjan Kumar

Madhuranjan Kumar

Founder, AI DOERS · Performance Marketing

Madhuranjan Kumar brings 20 years of performance-marketing experience and has managed over $200 million in Facebook ad spend for brands across the United States and beyond. His expertise spans the full modern marketing stack: Meta, Google Ads, TikTok, email automation, CRM, and the websites that hold it together. At AI DOERS he turns that track record into lead-generation systems for businesses across every industry.

← Back to all insights
Why Anthropic Refuses to Release Claude Mythos | AI Doers