When China Gets Its Own Mythos
MICHAEL SULMEYER is Professor of the Practice at Georgetown University and previously served as the U.S. Assistant Secretary of Defense for Cyber Policy.
In April, Anthropic disclosed that its newest frontier AI model, Claude Mythos, could find and exploit security vulnerabilities in software better than “all but the most skilled humans.” By way of example, the company noted that the model had uncovered a flaw that had gone undetected for 27 years in a secure operating system used to run firewalls that guard sensitive networks. The revelation jolted the cybersecurity and national security communities. Despite some allegations that Anthropic’s warnings about Mythos simply constituted marketing, leading commercial software companies given early access to the model have corroborated Anthropic’s claim. Work that long belonged to a small class of elite specialists can now be done by AI, faster and at a greater scale than human teams or earlier automated tools can match.
As firms use Mythos to hunt and fix flaws in their products, a more urgent question looms: how to defend the United States and its allies from AI-powered cyberwarfare. The United States may only have nine to 12 months to protect its critical infrastructure from AI-powered attacks. Currently, two American companies, Anthropic (for which I consult) and OpenAI, have publicly demonstrated AI models advanced enough to detect flaws in software far beyond the human capacity to find, and they are restricting the use of these models to defensive cybersecurity work.
But the United States’ adversaries, and the criminals in their orbit, will soon wield the same offensive tools. China, in particular, is already racing to build and acquire these AI capabilities and may be closer to developing its own Mythos than many U.S. policymakers hope. Advanced AI will sharpen an instrument that Beijing already prizes: the credible threat to deter a fight over Taiwan before it begins by disrupting the island’s critical infrastructure and that of any nation that seeks to defend it.
Previously, successfully attacking the computer systems that run critical infrastructure—actually managing to physically shut down an energy plant, water purification plant, or pipeline—demanded specialists fluent in each kind of system’s obscure protocols. Attacks like these were rare because they were time- and resource-intensive. Mythos has already demonstrated that it can find and exploit flaws with minimal human direction, and such a model could generate many such damaging compromises automatically.
That would allow for a kind of cyberattack different from any prior one in both scale and kind. The risk is not a single massive strike on a piece of key infrastructure, a cyber–Pearl Harbor, but a world in which China and others can cheaply and quickly gain footholds across far more of the systems that run daily life—water, power, transit—and hold them at risk to deter, extort, or simply wait.
The United States has a window to bolster its critical infrastructure’s defenses, but that window is short, and those defenses are weak to begin with. In a campaign called Volt Typhoon, Chinese state-linked hackers already demonstrated how deeply they can burrow into U.S. critical infrastructure, including organizations in the water, power, and transportation sectors. Now is the time to put policy options on the table that were previously considered out of bounds: taking dramatic steps to preempt would-be attacks, making once-in-a-generation investments in cyberdefense, and helping U.S. AI labs protect themselves against the most advanced threats.
Throughout much of the Internet era, finding novel software vulnerabilities required expensive, highly skilled specialists. The scarcity of these specialists constrained the top end of the contest between cyber defenders and attackers. But the arrival of AI models such as Mythos and GPT-5.5-Cyber is removing that constraint. Until the unveiling of these new models, it had been hard to turn access to infrastructure’s IT networks into reliable control over the physical equipment that opens a valve, trips a breaker, or alters a chemical dose. In 2017, for instance, hackers that the U.S. Department of Justice linked to a Russian military research institute penetrated a Saudi petrochemical plant and attempted to disable its safety instrumented systems, the last line of automated defense that keeps industrial equipment from exploding or releasing toxic gas. But even after the attackers gained such deep access, their code failed to account for the exact behavior of the plant’s specific safety controllers and inadvertently tripped the equipment into a protective shutdown, exposing the operation before it could cause physical harm.
That final step has historically remained dependent on a small number of specialists who understand the proprietary control systems of a particular vendor’s equipment. The scarcity of people with enough of the right experience has kept catastrophe rare. But a high-powered AI model that can read obscure industrial firmware and develop the exact compromise that would take a specialist months threatens to turn the hardest part of designing an infrastructure attack into a routine task. A coordinated disruption across hundreds of water systems, substations, and pipelines at once has now become a more plausible risk. The most advanced AI models could soon make widespread physical compromise something a single adversary can execute, or even credibly threaten without firing a shot.
Understanding the danger, Anthropic has not released Mythos openly, instead putting it into the hands of defenders first by restricting access to a coalition of technology, finance, and open-source organizations, an effort it calls Project Glasswing. This was a notable decision: a company chose to withhold its most powerful product from broad release because the product could be turned, with little modification, into a weapon. (Eventually, Anthropic offered Fable—a product using the same underlying model but with enhanced safety guardrails—to the public.)
Within weeks of Anthropic launching Project Glasswing, OpenAI made GPT-5.5-Cyber available to vetted security teams through a program it called Trusted Access for Cyber. The early results were stunning. Microsoft, using an internal scanning system built using multiple models, disclosed sixteen previously undetected flaws in the Windows networking stack. And the cybersecurity firm Palo Alto Networks, testing the new models against its own products, reported finding far more vulnerabilities in a single scan than it typically discloses in a month.
At the moment, the most capable cybervulnerability discovery tools belong to defenders. This is the best news in cybersecurity in decades. And despite some very capable new releases, it does not seem that Chinese labs yet possess a Mythos-level AI model.
But U.S. policymakers may not know when China achieves that capability. Private companies ultimately must publicize their models to make developing them worthwhile; even Anthropic announced Mythos’s existence while restricting its use. Governments, however, will be cautious about if, when, and how they advertise their possession of systems built to serve as national security assets.
Recent developments suggest that China is getting close to acquiring its own Mythos-class AI model. In mid-June, about a day after the U.S. government temporarily banned foreign access to Anthropic’s newly released Mythos and Fable models, the Chinese company Zhipu AI released a model called GLM-5.2. The firm claims GLM-5.2 can compete with Anthropic’s second-best model, Opus, on certain benchmarks. Unlike Mythos or OpenAI’s most capable models, GLM-5.2 is an “open-weight” model that users can download and deploy without seeking permissions from the company that made it or relying on infrastructure that the U.S. government can control. Any safeguards can be easily removed. Essentially, almost anyone can access it and use it for almost any purpose for a fraction of the cost of advanced American AI models.
China’s rapid progress in developing such models is a function of tools available to the regime. The first is illicit or adversarial distillation. Chinese competitors use the outputs of leading American models to train cheaper imitations. In a February memo to Congress, OpenAI reported that it had observed accounts tied to DeepSeek employees circumventing its access controls to harvest model outputs for distillation. That same month, Anthropic disclosed a comparable campaign. Adversarial distillation is just another chapter in a two-decade campaign that China has run to steal American IP, including the theft of American Superconductor’s wind turbine technology and the suspicious resemblance between China’s J-31 fighter jet and the U.S. F-35.
As AI models advance, they become powerful tools for building even more capable AI. It should not come as a surprise that U.S. AI companies are using their own models to build the next generation of models, but it is easy to miss the fact that America's chief competitors are also using top U.S. models to engineer the next version of their own models, as well.
China is not only building domestic alternatives to U.S. AI models. Chinese actors are making efforts to gain illicit access to the most powerful export-controlled AI semiconductor chips. Over the past year, the U.S. Department of Justice has prosecuted multiple large chip-smuggling networks. Smuggling alone cannot deliver the compute needed to train advanced models. But just as China is building its own models, it is building its own chips.
Finally, whenever China acquires new, high-end AI capabilities, they become available to the state in short order. Domestic Chinese AI labs operate under a regulatory framework oriented toward state access. The country’s National Intelligence Law requires Chinese companies to cooperate with state intelligence collection, and the Cyberspace Administration gives the government visibility into model behavior and outputs. As soon as a Chinese lab develops Mythos-class offensive cyber-capability, it is highly likely that the People’s Liberation Army and China’s intelligence apparatus will have early access to it.
The decisions by American companies to limit access to models that could orchestrate unprecedented attacks on physical infrastructure have bought critical time. But each month that an adversary can siphon abilities from U.S. models and gain access to more advanced chips is a month subtracted from the defenders’ head start.
Critical infrastructure increasingly sits at the nexus between cyberspace and the physical world. If something goes wrong in these systems, the impact is not that people’s passwords get stolen and they need credit monitoring. It is the potential loss of power to a city, the contamination of a water supply, or the seizing-up of a regional transit network. This risk is not hypothetical. In December 2015, Russian hackers who had breached Ukrainian utilities with malware called BlackEnergy cut power to over 200,000 customers for several hours.
The United States’ critical infrastructure targets are structurally weak and unprepared for such an attack. They are owned and operated by thousands of small and medium-sized municipal districts and utility companies, most of which lack the budget, staff, or leverage to demand secure products from their vendors. They carry decades of technical debt, often running operational technology that was not even designed to be connected to the Internet and cannot be easily patched or replaced. Securing this firmware is far more complicated than updating an iPhone; it requires revalidation for safety that entails testing and local installations that take the facility offline. That means that even if a vulnerability is identified and a safe fix is engineered, it can take years to validate, schedule, and deploy it in equi
Hacker News
news.ycombinator.com