Winging It · Implausible Deniability
I noticed it for the first time on a Tuesday. There was a sponsored post in my LinkedIn feed from a vendor I don't follow, in fairly large type, suggesting in no uncertain terms that I should be ready for Mythos. There was a graphic. The graphic involved a shield. It had been seven days since Anthropic announced Mythos. I had not, at that point, made a coffee.
By Wednesday morning, there were three more. By Thursday, the first email had arrived. The Cloud Security Alliance had, within eight days of Anthropic's announcement, published a strategy brief called "The AI Vulnerability Storm: Building a Mythos-Ready Security Program," which was, by my count, a faster turnaround than most CISOs manage for a non-emergency change. Tenable had a blog up. The phrase "Mythos-Ready" was appearing in vendor emails, in webinar invitations, in the headlines of LinkedIn posts written by people who, six weeks earlier, had been writing posts about something else. Marketing managers across the security industry, working with the haunted energy of people told the new keyword on Tuesday with a deck due Thursday, had successfully replaced the phrase "AI Governance" with "Mythos-Ready" across what I can only describe as a great many PowerPoint slides.
The timeline, for the record: Anthropic announced Claude Mythos Preview on April 7. They explained that the model could find and exploit zero-day vulnerabilities in every major operating system and every major web browser. They explained that it had identified a twenty-seven-year-old bug in OpenBSD. They described its arrival as a "watershed moment." They then explained that they would not be releasing it.
Anthropic restricted Mythos to a small group of partners under something called Project Glasswing. The partners include companies like Apple, Amazon, JPMorgan Chase, and Palo Alto Networks. Everybody else, including the vendors writing the blogs, the consultants posting on LinkedIn about strategies, and the Cloud Security Alliance, has the same access to Mythos that I do, which is to say, none. We are all writing about the operational implications of a thing we have never seen.
This is, on reflection, the most comfortable marketing position the security industry has been in for years. A capability nobody can demonstrate, in response to a threat nobody can measure, prepared for by techniques nobody can verify. The vendor cannot be falsified. The five-step plan cannot be tested against the model the five-step plan is purportedly preparing for.
I read several of the blog posts, against my better judgement. They explained that achieving Mythos readiness involved automated agentic detection, continuous adversarial validation, and a shift from legacy scoring to a risk-based filtering approach focused on attack paths. These are, broadly, the same things the vendors' platforms were already doing in March. The product hasn't changed. The product, somehow, has been ready for Mythos all along. I refreshed LinkedIn. The number of Mythos-Ready posts in my feed had gone up by four.
The marketing position was cleverer than the model. The format AI companies have settled on, for products of sufficient seriousness, is now mature enough to deserve its own page in a textbook. The format is regretful, slightly weary, and goes broadly as follows. "We've built something quite remarkable. We can't, in good conscience, allow you to have it. We're profoundly sorry about this. Here is a press release." Sam Altman announced GPT-5.5-Cyber within a fortnight. The same position, a different number, the same press release in a different font. The marketing format now exists in duplicate. The model so dangerous it cannot be released is a standard product launch.
Predictions are difficult, especially about the future, but I'd put a small amount of money on the following. By the end of Q3, we'll be reading the first press release from a security vendor announcing that their own product has, regrettably, become as dangerous as Mythos. The vendor will be one of the ones who wrote the five-step blog post. Their product, a vulnerability scanner that until last quarter was sold primarily on the basis of producing colour-coded dashboards, will have, on the strength of exhaustive Mythos-readiness testing, developed capabilities the responsible board cannot in good conscience allow to fall into the wrong hands. The product will be made available only to a controlled group of partners under something called Project Greenwing or Mockingbird or, I don't know, Project Pigeon. The press release will use the words "watershed moment." There will be a serious technical paper. The technical paper won't, on close reading, contain very much. There will, naturally, be a webinar.
The press release, when it lands, will read approximately as follows.
"Today, we are announcing a difficult decision. Over the past six months, our GRC platform has undergone extensive Mythos-readiness testing. The results have, candidly, exceeded our expectations. Our automated evidence collection engine, originally designed to streamline SOC 2 audit preparation, has developed the capacity to gather audit evidence at speeds the auditing profession is not, structurally, prepared to absorb. In testing, the platform completed a full Type II evidence package in forty-three minutes. The audit firm refused to accept it. We have therefore made the responsible decision to restrict access to a small consortium of trusted partners under a new initiative we are calling Project Pigeon. We recognise this will be disappointing to many of you. We are profoundly sorry. A detailed technical paper will follow next quarter, alongside a webinar series exploring the implications for the GRC community. We thank you for your patience as we navigate this watershed moment together."
The vendor will not, on inspection, be Anthropic.
Meanwhile, in board rooms, the same conversation is happening. A director has read about Mythos in the weekend press. The director asks the CISO what the Mythos plan is. The plan, sensibly, is the same plan as before, which is patching, reducing attack surface, knowing what you have, only faster. This isn't a satisfying answer. The CISO goes back to the vendor. The vendor produces the five-step blog post. The blog post is forwarded to the board. The board nods. The meeting moves on to item ten, which is the coffee machine. The coffee machine vote takes longer.
I signed up to a webinar this morning, out of professional curiosity. It is on Thursday at three. The marketing manager who scheduled it is, somewhere, finishing the deck for next quarter. The deck has a new keyword in it. I don't yet know what the keyword is. I'll be ready for it by Tuesday.
— Chris
