Something happened in April 2026 that every board member, CEO, and senior leader needs to know about.

Anthropic — one of the world’s leading AI companies — released a model called Claude Mythos Preview. They did not make it publicly available. Instead, they handed access to a small group of trusted technology partners under a programme called Project Glasswing.

Why such caution? Because this model is unlike anything that has come before it.

Within weeks of testing, Claude Mythos had independently found thousands of previously unknown security vulnerabilities across every major operating system and web browser on the planet. No human needed to guide it. It worked autonomously, like a highly skilled hacker who never sleeps.

This is the AI cybersecurity wake-up call that business leaders can no longer ignore.


What Is Claude Mythos?

Claude Mythos is Anthropic’s most powerful AI model to date. It sits above the Claude Opus tier and was built specifically for complex, long-running tasks — including autonomous coding, deep reasoning, and security research.

Anthropic describes it as:

“a new class of intelligence built for ambitious projects.”

It is not a chatbot. It is not a productivity tool. It is an agent — meaning it can plan, reason, and act across multiple steps without human input.

That distinction matters enormously for what it can do to your organisation.


The Threat Is Real and It Is Here Now

Here is what Claude Mythos Preview demonstrated in controlled testing:

  • It found and exploited a 17-year-old vulnerability in widely used server software — fully autonomously
  • It completed expert-level cybersecurity attack simulations with a 73% success rate
  • It chained multiple small weaknesses together to create a single devastating attack path
  • Once inside a simulated network, it could map systems, move laterally, and extract data within hours

Two years ago, the best AI models could barely handle beginner-level security tasks. Today, a model exists that can do what would take a team of expert human hackers days — and it can do it in hours, repeatedly, at scale.

Think about what that means for your organisation.

A cybercriminal does not need to be a technical genius anymore. They just need access to a powerful AI model. And models with similar capabilities to Mythos will not stay locked up forever.

As Anthropic themselves put it:

“Everyone needs to prepare for AI-assisted attackers. There will be more attacks, faster attacks, and more sophisticated attacks.”

This is not a technology problem sitting in your IT department. It is a business risk at the highest order — and it belongs in the boardroom.


Why Most Organisations Are Not Ready

Bain & Company’s 2025 Cybersecurity Survey found that most companies plan to increase cybersecurity spending by only around 10% annually.

That figure is dangerously low for the AI era we have entered.

Most organisations have spent years underfunding cybersecurity and treating it as a technical back-office function. That worked when attackers were limited by human capacity. It does not work when attackers can deploy AI agents that operate around the clock, learn from every attempt, and probe thousands of vulnerabilities simultaneously.

The gap between how protected most businesses think they are and how exposed they actually are has never been wider.

Here is the uncomfortable truth:

If your board is not talking about AI-enabled cyber threats right now, your board is behind.


The Two Sides of This Moment

This is where the story shifts — and why there is also reason for optimism.

The same capabilities that make Claude Mythos dangerous in the wrong hands make it extraordinarily powerful in the right ones.

Anthropic’s Project Glasswing is the proof. Rather than releasing this model into the open, they built a programme with trusted partners — including Microsoft — to use Mythos to find and fix vulnerabilities before attackers can exploit them.

Microsoft’s own security teams are already using AI in their operations, analysing over 400 trillion network flows every day.

This is the dual nature of the moment we are in:

  • AI is the most powerful attack tool ever built
  • AI is also the most powerful defence tool ever built

The organisations that understand this — and act on it — will be the ones that survive and thrive in the AI era. The organisations that ignore it will be exposed.


What Business Leaders Need to Do Right Now

You do not need to become a cybersecurity expert. But you do need to lead.

Here is what to do:

1. Put cyber on the board agenda — permanently

This is not an IT update. It is a strategic risk conversation.

2. Conduct an honest assessment of your exposure

Understand where your biggest gaps are in the context of AI threats.

3. Invest in fundamentals

Strong basics (access control, patching, identity management) still matter — massively.

4. Explore AI-powered defence

Use AI to monitor, detect, and respond faster than attackers.

5. Build AI literacy at leadership level

AI understanding is now a fiduciary responsibility.


The Bigger Picture: AI and Cyber Are Now the Same Conversation

For years, AI and cybersecurity were separate topics.

Not anymore.

Claude Mythos has collapsed that distinction.

AI is now the engine of both attack and defence. That means:

👉 AI strategy and cybersecurity must be discussed together
👉 At the same table
👉 With urgency

The most important business conversation of 2026 is not productivity.

It is this:

Are you protected from AI — and are you using AI to protect yourself?


What Project Glasswing Tells Us About the Future

Anthropic’s approach signals something critical.

They gave access to defenders first — to fix vulnerabilities before attackers gain similar tools.

That advantage is real.

But it is temporary.

AI capabilities will spread.

And when they do, the organisations that are unprepared will be exposed first.


A Final Word for Board Members and CEOs

Claude Mythos is a signal.

AI has crossed a threshold.

The era of AI-enabled cyber threats is not coming.

It is already here.

But so is the era of AI-powered defence.

The leaders who understand both sides — and act — will protect their organisations, customers, and people.

That is the leadership challenge of 2026.

If this is on your board agenda — it should be — then it’s time to move from awareness to action.

Mark Kelly works with boards and leadership teams to turn AI risk and opportunity into clear strategy, practical roadmaps, and measurable outcomes.

👉 Book Mark Kelly as your AI keynote speaker for your next event
👉 Engage for executive strategy sessions on AI, cybersecurity, and business transformation

Get clarity. Build capability. Lead with confidence in the AI era.

Share This Story, Choose Your Platform!

Planning an event or leadership offsite?

Mark Kelly delivers evidence-based AI keynotes and hands-on AI leadership workshops for boards, executive teams and conferences across Ireland and Europe.

Check Mark’s availability