
In the new world, the state of alert is the new normal

“There are only two types of companies: those that have been hacked and those that will be.” This remark, made in 2012 by then FBI Director Robert Mueller , became a mantra that for more than a decade summed up an uncomfortable truth: in our digital world, for any company in any country, a cybersecurity breach is not a question of if, but of when.
For a long time, cybersecurity was perceived as a trivial, technical problem, confined to IT departments (and, whatever people may say, in some contexts this perception still persists today). But the reality is that this is no longer the case. Whether one wants to accept it or not, at the governance level cybersecurity is a Board issue, because it touches operational continuity, corporate reputation and, in many sectors, regulatory compliance as well.
And although the topic has become increasingly mainstream, it has never been more so than when the Mythos case erupted.
What Mythos Is (and why it is frightening)
Mythos is the most capable Artificial Intelligence model ever developed (so far) by Anthropic, the company behind the family of language models (LLMs, Large Language Models) known as Claude. First announced in April 2026, Mythos can understand and modify complex software. As a result, it is also a model capable of identifying weaknesses in that code.
The launch of Mythos did not follow the usual script. Initially, Anthropic decided not to release the model because, already in preview, it had shown that it could find thousands of high-criticality vulnerabilities in a very short time, including some present in all major operating systems and browsers: flaws embedded in the software on which the entire global economy rests.
Instead, the company launched Project Glasswing, a coalition that gave access to Mythos to around fifty organizations — mostly large U.S. technology companies and cybersecurity firms — with one main objective: to use Mythos before attackers did, in order to find and fix flaws in their own digital infrastructure. The idea was to provide a temporary asymmetric advantage, for once in favor of defenders. The result was striking: within a few weeks, partners had identified — according to data released by Anthropic — more than ten thousand high- or critical-severity vulnerabilities.
In the meantime, a debate opened up. A company that builds its most powerful model and decides not to sell it, in a sector where being first is everything, inevitably raises suspicions.
Given AI's ability to affect corporate security and privacy in profound ways, since the explosion of the Generative AI trend many corporate cybersecurity leaders (Chief Information Security Officers or CISOs) have found themselves deeply involved in the governance of this technology. And quite a few of them interpreted the move as a clever positioning exercise (especially ahead of Anthropic's future IPO): the model attracts enormous attention precisely because you cannot have it. The doubt remained, however: were Mythos's capabilities real, or were they marketing narrative?
The release, the block, and what it revealed
In June 2026, Anthropic released a twin model of Mythos: Fable 5. The two share the same “engine”, but with a crucial difference in safeguards. Fable is designed for general use and incorporates specific guardrails (safety mechanisms embedded in the model): when it receives potentially high-risk cyber requests, it routes them to a less capable model, a mechanism that has so far been triggered in fewer than 5% of sessions.
Yet Fable's release lasted only a very short time. On June 12, three days after launch, the U.S. Department of Commerce imposed “export” controls on Anthropic that required it to exclude from access any non-U.S. citizen, including the company's own foreign employees. The order took effect immediately and, unable to verify users' nationality in real time, Anthropic suspended access for everyone, withdrawing the model from every platform. The trigger was a report by Amazon researchers who had found a way to bypass Fable's guardrails, pushing it to identify vulnerabilities and, in one case, to produce code demonstrating their potential exploitation.
A few days later, the block was lifted, and with it came a detail that partly changed the narrative. Tests conducted by Anthropic showed that many less powerful models — including earlier versions of Claude, OpenAI's GPT-5.5 and Chinese open-source models such as Alibaba's Qwen (which is suspected of having been trained in part on Fable itself) — were able to identify the same vulnerabilities highlighted in the Amazon report. In other words, the ability to identify flaws of this kind is not exclusive to Mythos/Fable — at most, they find them more quickly.
On June 30 the controls were removed and, from July 1, Fable 5 became available again globally, with updated guardrails. Mythos remains reserved for qualified partners; Project Glasswing was recently joined by the first European entity, the European Union Agency for Cybersecurity (ENISA).
Beyond Mythos: the storm on the horizon
It is at this point that the main lesson of the Mythos/Fable case emerges, almost counterintuitively. The danger cannot be managed by restricting access to a single model, because equivalent capabilities already exist — or will exist within a few months (or even weeks) — in dozens of other models, some open source and available to anyone at extremely low cost. Defense cannot be based on the hope that adversaries do not have the tools; we must assume the opposite.
The implications are concrete. An AI-based tool such as Mythos can detect thousands of vulnerabilities in a matter of weeks. Vulnerability discovery accelerates because the incentive for attackers is clear; remediation lags because, here, the incentives are inverted: applying a patch means blocking corporate productivity, to a greater or lesser extent. To deal with this continuous state of alert, organizations will need to equip themselves on two fronts.
The first: having the right tools to defend themselves — a far from trivial issue in a world where a state can block or limit the release of a particularly cutting-edge model, with the risk of creating a “poverty line” (a line of digital poverty) separating companies capable of responding to threats from those inexorably left behind for lack of adequate tools. Fable's block opened several questions that goes beyond technology: who controls these models, who can access them and under what conditions. This is no longer just a commercial issue, but a contest of power between states. It is a topic that deserves a discussion of its own, and it will be the heart of the second article of this Trending Topic .
The second: knowing how to respond in time, which means that the cyber risk governance we are used to must change. Containing risk may require accepting that it is the criticality level of a vulnerability, not the business calendar, that determines when a patch is applied. A reversal of priorities that until now would have been unthinkable. How the corporate security model changes in practice when AI and automation become structural components of both attack and defense — affecting which processes and which roles — will be the subject of the third part of this Trending Topic.
The opinions and reflections presented in these articles draw on a series of discussions held over recent months within the Corporate Information Security Roundtable , an initiative involving European and American Chief Information Security Officers, as well as on the research activities of DEVO Lab , SDA Bocconi’s laboratory dedicated to studying innovation and the adoption of new technologies in companies.



