A few weeks ago, Anthropic did something almost no frontier lab has done in the middle of a competitive race: it held a model back. Claude Mythos – its most powerful system to date – was given to a small coalition of companies, banks and regulators rather than released. The reason was cybersecurity. The implication is much bigger than that.
Watch our full briefing on Mythos and what it signals →
The cybersecurity story is real. The UK’s AI Security Institute tested Mythos and found it was the first model to complete a 32-step simulated cyber attack – a step-change in autonomous capability that no other public model has come close to. Canada’s finance minister, François-Philippe Champagne, compared it to the Strait of Hormuz: a chokepoint on the global financial system. Central banks are meeting about it. The FCA has had access. The Bank of England has commented.
That’s the bit governments are panicking about, and it’s the bit the news cycle has run with.
It’s also the bit that’s least useful for the rest of us.
The more important point, for any organisation outside critical national infrastructure, is this: the same complexity that lets a model chain together 32 steps to break a security system is what lets it run a 32-step business process end to end. Mythos is not primarily a cyber story. It’s an agent capability story.
Strip out the security panic and what you’re left with is a measurable trend. Research from METR shows the complexity of tasks frontier models can complete autonomously has been doubling every seven months since 2022. That’s the AI equivalent of Moore’s Law, and Mythos sits exactly where the curve says it should – just earlier than most boards have prepared for.
The people who have actually tested Mythos estimate a six- to eighteen-month window before competitors and open-source equivalents catch up. Meta has one in development. Several Chinese labs are close. Once those land, the capability is out – not contained to fifty vetted partners, but available to download and run on private infrastructure.
That’s the real countdown. It isn’t about Mythos. It’s about what every serious lab will be shipping by this time next year.
The other signal worth reading is how the institutions that spent the last two years dismissing AI safety concerns are now positioning themselves. Casey Newton, writing in Platformer this week, captured the shift cleanly:
“The models are getting more capable – and more dangerous. What [had been] dismissed as the doomer industrial complex now includes a growing number of federal agencies.”
Google, Microsoft and xAI have all now agreed to submit frontier models to the US Commerce Department for review before release. The UK’s AISI is testing models in advance. The EU AI Act lands in August. Whatever regulator covers your sector is having the same internal meeting this month, and they will be looking for evidence that organisations are taking AI literacy and governance seriously – not just buying licences.
The compliance burden is no longer a future risk. It’s a present one.
In conversations with leadership teams over the last two months, we keep seeing the same three patterns:
Terrified at the top – buying Copilot licences as a security blanket and hoping that counts as a strategy.
Confused in the middle – waiting for permission, waiting for a policy, waiting for someone else to go first.
Tinkering at the edges – a few enthusiasts doing interesting things, no system to share what they learn.
All three patterns share a quieter problem. They produce activity – licences bought, pilots run, enthusiasts encouraged – without building the capability an organisation actually needs. The gap between activity and capability is the one that widens over the next eighteen months, as agent systems get more capable and the organisations that did the harder work pull ahead. The job now is to build AI capability as a system, not a side project: clear governance, shared learning, board-level commitment, real change to how work gets done. The case for boards has three parts – market correction risk, competitive threat, and the compliance burden coming down the track.
Three things:
Watch the briefing. The full thirty-minute reality check – diagnosis, evidence, the timeline of how we got here – is on the event page. Share it with whoever in your organisation you think needs to see it.
Take the board pack. We’ve put the slides, the data and the timeline into a Creative Commons board briefing pack. Find it here. Remix it for your own organisation – no attribution required.
Run an AI show and tell. The single highest value thing any team can do this week is to take 5 minutes each to show anything they have done with AI that week. It’s the cheapest culture intervention available and it works.
The most important thing to understand about AI right now isn’t the size of any single model. It’s the recursion. The systems are getting faster at getting faster at getting faster. Mythos is a data point on that curve, not the end of one.
The regulators and finance ministries now reading the curve are arriving at the same place we are. The question for the rest of us is whether we read it in time to do something useful with the eighteen months we’ve got.
→ Watch the AI Reality Check briefing
Share with a friend.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.