What the Government's Restriction of Mythos AI Signals
The U.S. government temporarily applied export controls to Mythos 5 and the safeguarded Fable 5, leading Anthropic to suspend access because it could not reliably verify users’ nationality. The controls were lifted after Anthropic strengthened its safeguards and government researchers evaluated them.
“Government restrictions reflect concern that advanced cyber-focused AI could accelerate vulnerability discovery and exploitation faster than organizations can respond,” says Rafe Pilling, director of threat research at Sophos.
The restrictions acknowledge that these capabilities have potential national security implications if misused, Pilling adds.
DIVE DEEPER: Find out how to quantify cyber risk for your organization.
How Mythos-Level AI Outpaces Traditional Security Programs
Traditional vulnerability management assumes discovery, validation, prioritization and patching unfold on human timelines. Mythos-level systems can automate discovery and iterate on attack paths continuously, while defenders still need to test patches and protect operational continuity.
“Patch cycles measured in weeks were designed for a threat that also moved in weeks,” Dickson says. “Defenders are still running on a human clock while the discovery side of the fight has switched to a machine clock, and clocks running at different speeds is exactly how you lose a race you didn't know you were in.”
He says security leaders need continuous asset discovery, attack-path analysis and risk-based remediation. Runtime monitoring must identify novel behavior rather than depend solely on known signatures.
Why Legacy Systems and OT Environments Are Especially Exposed
Legacy systems and operational technology environments often combine unsupported software, limited visibility and systems that cannot be patched without affecting production. AI does not create that technical debt, but it reduces the expertise and time required to find exploitable weaknesses.
“Legacy systems carry years of technical debt,” says Mike Arrowsmith, chief trust officer at NinjaOne. “While Mythos doesn’t create these vulnerabilities, it does expose them.”
The consequences extend beyond data loss: An OT intrusion can interrupt production, damage equipment or create physical danger.
Arrowsmith says enterprises should map IT-to-OT connections, eliminate unnecessary access and apply compensating controls where immediate modernization is impossible.
