Why the White House Treated a Claude Model Like Controlled Infrastructure
Because the model, Claude Mythos, can complete a multi-step cyber attack end-to-end and find decades-old vulnerabilities for under two dollars, the government blocked Anthropic from widening access, citing national security and compute priority, and started governing frontier AI like weapons-grade infrastructure rather than ordinary software.

A frontier AI model solved a challenge in ten minutes and twenty two seconds that would take a human expert around twelve hours, and it cost one dollar and seventy three cents to do it. That single figure is why the White House blocked Anthropic from widening access to its Claude Mythos model, and it is why frontier AI is starting to be governed like controlled national infrastructure rather than software you sign up for. I, Madhuranjan Kumar, think the news itself matters less than what it tells a normal business to do, so instead of arguing policy I am going to walk one law firm through its response, chapter by chapter, because a firm is exactly the kind of target this capability reshapes.
Chapter one: what actually happened, and why it is a turning point
The facts first. Anthropic wanted to grow its Claude Mythos preview from around fifty organizations to one hundred twenty, adding seventy more, and according to reporting from the Wall Street Journal, the government stepped in and said no. Two reasons were given. The first was national security, because a model this good at finding software vulnerabilities could cause serious harm if it spread too widely. The second was compute, because the government worried that serving seventy new organizations might degrade its own priority access, a claim Anthropic disputes.
The reason a law firm should read past the headline is the precedent. When a government treats access to a model like access to weapons-grade infrastructure, it is confirming that the underlying capability is real and consequential. This was not marketing. It was a regulator deciding that cheap, automated vulnerability-finding is dangerous enough to ration. For a firm sitting on client records, sealed settlements, financials, and privileged communications, that confirmation is the starting gun.

Chapter two: understanding the capability the firm is up against
Before hardening anything, the firm had to understand what it was defending against, and the benchmarks are sobering. A UK government security institute runs a simulated corporate network attack that is thirty-two steps long, the kind of end-to-end intrusion a skilled human would need roughly twenty hours to complete. Claude Mythos finished it end to end in about three out of ten attempts. Then a competing model, GPT 5.5, became the second system to finish the same simulation, succeeding in about two out of ten tries, which proved the result was not a one-off fluke tied to a single lab.
The cost is the part that changes the threat model. GPT 5.5 solved a reverse-engineering challenge in ten minutes and twenty-two seconds for about one dollar and seventy-three cents of API usage, work that might take a human expert around twelve hours. And Claude Mythos surfaced a twenty-seven-year-old vulnerability in OpenBSD that had long been considered secure. The right mental model, which the firm adopted, is that these systems do not invent new vulnerabilities. They expose ones that already existed, the way a microscope reveals bacteria that were always on your skin. The danger was already sitting in the firm's systems. The tool just makes it cheap to find.

Chapter three: accepting that the capability will not stay rare
The firm's instinct was to hope that restrictions would keep this out of attackers' hands. That hope does not survive contact with the policy reality. With no law on the books, the government is effectively deciding which labs may release, which one analyst describes as a de facto licensing regime, like building a dam against a tsunami. The warning attached to that description is blunt: the capability will diffuse within roughly six to eighteen months, whether from Western labs or open-source Chinese ones, so technical safeguards on your own systems will matter far more than access bans upstream.
There is a democratization point the firm's partners initially missed. Skilled engineers tend to judge these tools by their own ability and shrug, because the tools add little a top engineer could not already do. But top engineers are a tiny fraction of the population. For the other ninety-nine percent who could not find or exploit a bug at all before, an AI that can is the difference between zero and possible. It works like the printing press removing the need to be one of the few who could read. That is the source of both the opportunity and the risk, and it means the pool of people who can attack the firm is about to expand dramatically.
Chapter four: the hardening plan, with numbers
Once the firm accepted that cheap vulnerability-finding is coming for everyone within about a year, the work became concrete and unglamorous. The plan followed four moves, and I will attach an illustrative measure to show the direction of travel: the count of known, unpatched vulnerabilities sitting in the firm's systems over twelve weeks.
First, inventory where sensitive data lives, because you cannot protect what you have not mapped. Second, patch aggressively and on a fixed schedule rather than only when something breaks, since the same models that help attackers also help defenders surface and fix flaws faster. Third, limit how far any one login reaches, so a single compromised account cannot touch everything, and encrypt the sensitive archives. Fourth, run modern scanning to surface the old vulnerabilities these models are good at finding, then re-run those scans as the capability spreads.
Illustratively, the firm started with around eighteen known unpatched vulnerabilities scattered across its systems. After four weeks of scheduled patching and tightened access, that dropped to about seven. By week twelve, with scanning running on a cadence and the worst exposures encrypted and segmented, it sat near two. Those numbers are illustrative, not a promise, and it is worth remembering that the alarming benchmark success rates came from controlled evaluations with no active defenses, so they are not a forecast for a hardened network. But the direction is exactly the point: a firm that treats this as real and moves early shrinks its exposure fast, while a firm that waits for regulation to protect it does not.
Chapter five: where this connects to the rest of the business
Security is not a walled-off IT project, and the firm's response touched the parts of the business that face clients. The same discipline that maps where sensitive data lives also cleans up the CRM and website stack, because intake forms and client portals are exactly the surfaces attackers probe first, and a tidy, access-controlled stack is both safer and easier to run. The firm's trust story, that it takes client confidentiality seriously enough to harden proactively, became a genuine differentiator worth saying out loud in its SEO and organic search content and in the messaging behind its Facebook and Instagram ad campaigns, because in legal services, demonstrated diligence is a selling point, not just an overhead.
Chapter six: sitting with the dual-use reality
The hardest part for the firm's partners to accept was that there is no clean version of this capability. Labs describe their approved customers as defenders who patch bugs faster, and that is true. But the exact same capability that lets a defender find and fix a flaw faster lets an attacker find and exploit it faster. It is dual-use by nature, and no amount of careful customer selection changes the underlying tool. That is precisely why the firm stopped waiting for upstream gatekeeping to protect it and focused on its own systems, because the thing being rationed will not stay rationed.
This is also why the microscope analogy did so much work internally. The models are not manufacturing new dangers out of thin air. They are revealing flaws that already sat in the firm's software, sometimes for decades, the way that twenty-seven-year-old OpenBSD vulnerability sat quietly in code long assumed to be secure. Once the partners internalized that the bugs already existed and the only thing changing was how cheaply they could be found, the argument for aggressive, scheduled patching became impossible to wave away. You are not defending against a hypothetical future weapon. You are closing doors that have been unlocked the whole time.
Chapter seven: what the firm chose not to do
Just as instructive is what the firm refused to do, because the wrong responses were tempting. It did not try to ban AI internally, which would have been both unenforceable and beside the point, since the risk lives in unpatched systems, not in staff using assistants. It did not wait for a formal law, because the policy landscape is explicitly unsettled, a de facto licensing regime with no written rules, and betting the firm's confidentiality on regulation arriving in time would have been reckless. And it did not treat the eye-catching benchmark numbers as a literal forecast, because those evaluations ran on undefended systems with no active protections in place, so a hardened network behaves very differently.
Instead the firm did the unglamorous, controllable things: mapped its data, patched on a schedule, segmented access so one compromised login could not reach everything, encrypted the sensitive archives, and ran modern scanning on a cadence to surface old flaws before someone else did. None of it was exotic. All of it was within a normal firm's reach, which is exactly the point. The businesses that come through the next couple of years intact will not be the ones with the most exotic defenses. They will be the ones that did the ordinary hardening early, while the bugs were still cheap to find and patch and before the capability finished diffusing to everyone who might want to use it against them.
Chapter six: the honest takeaway for any business
The law firm was a vehicle, but the lesson is general. Every business that stores sensitive data should assume the capability is universal and close, then act before it diffuses. Inventory your data, patch on a real schedule, limit how far any one account reaches, and use the same tools defensively to find the old bugs before someone else does. None of this requires you to be a security researcher. It requires you to treat the risk as real and move while the bugs are still cheap to find and patch, which is the one window where being early actually pays.
The window where being early actually pays
The reason to move now rather than later comes down to a narrow window that is already closing. Right now the capability to find and exploit old vulnerabilities cheaply is concentrated in a handful of models and organizations, which is exactly why the government is rationing access. But the clear warning from analysts is that this capability will diffuse within roughly six to eighteen months, whether from Western labs or open-source Chinese ones, and once open weights are downloaded by enough people, no policy can pull them back. That means the pool of people who can probe your systems is about to widen dramatically, and it will not narrow again.
A business that hardens during this window buys itself a real head start, because the old flaws these models are so good at surfacing get closed before the capability is everywhere. A business that waits until the capability is universal is patching under fire, with far more people able to find the same doors. The math strongly favors moving while the tools are still scarce on the attacker's side and already available on the defender's side, which is roughly the situation today. Inventory your data, patch on a schedule, segment your access, and run the scans now, so that when cheap vulnerability-finding becomes ordinary, your systems are already the hard target rather than the easy one. Being early is not caution here. It is the single highest-leverage security decision available, and its value decays every month you delay.
You can absolutely take these first steps yourself, and hardening your systems today is the right free starting point. If you would rather have someone map where you are exposed, set up the patching and scanning routine, and build a practical plan for a world where this capability reaches everyone, that is exactly the kind of work I do for clients, and you can bring me in to handle it.
That is exactly what we do at AI DOERS. Book a private 30-minute call with Madhuranjan Kumar and we will map the fastest path to it for your specific business.
Book your call →
