
Mythos and Fable show how frontier AI can become a dual‑use weapon: a powerful defender of critical infrastructure and, in the wrong hands, a scalable cyber‑attack engine.
Threats to infrastructure
Anthropic’s Mythos‑class models have demonstrated the ability to rapidly discover and exploit severe software vulnerabilities across major operating systems and browsers, including flaws missed for decades. This translates into accelerated risks for energy grids, financial systems, telecom networks and other critical infrastructure, because even non‑expert actors can be guided to identify and weaponize weaknesses in complex codebases.
Proactive defenses
Organizations should treat frontier AI as both an asset and a risk, integrating it into secure code review, red‑teaming, patch management and threat hunting while enforcing strict access controls and usage policies. Governments and operators must collaborate on model evaluation, scenario testing and AI‑specific incident response playbooks, especially for sectors designated as critical infrastructure.
US sanctions and controls
In June 2026, the US government issued an export‑control directive forcing Anthropic to suspend access to Fable 5 and Mythos 5 for all foreign nationals, citing national security concerns over possible jailbreaks and misuse. These controls were later lifted after Anthropic agreed to proactively detect and address security risks, work closely with US authorities on release protocols and report malicious activity linked to its models.
Chinese competition
Chinese cybersecurity firm 360 has publicly claimed to be developing tools that match Anthropic’s Mythos‑class AI capabilities, underscoring an emerging strategic race in offensive and defensive cyber‑AI between the US and China. For global critical infrastructure operators, this competition means they must assume that highly capable vulnerability‑hunting AI systems will be available to both defenders and adversaries, and plan accordingly.
Indian government safeguards for business
The Indian government is building a secure and resilient cyberspace through its National Cyber Security Policy, which focuses on protecting information infrastructure for citizens, businesses and the state. It has established institutions such as the National Cyber Security Coordinator and sectoral Computer Emergency Response Teams to coordinate incident response and issue advisories that help local enterprises strengthen controls before attacks occur.
For businesses, India’s measures include mandatory reporting of certain cyber incidents to CERT‑In, guidelines for protecting critical and sensitive information infrastructure, and promotion of best‑practice frameworks and capacity‑building programmes targeted at MSMEs. These steps encourage proactive risk assessment, secure configurations, continuous monitoring and staff awareness, helping Indian organizations stay ahead of emerging AI‑driven threats like Mythos and Fable‑enabled attacks.
cyberwar ed team




