In April, Anthropic disclosed that its newest frontier AI model, Claude Mythos, could find and exploit security vulnerabilities in software better than “all but the most skilled humans.” By way of example, the company noted that the model had uncovered a flaw that had gone undetected for 27 years in a secure operating system used to run firewalls that guard sensitive networks. The revelation jolted the cybersecurity and national security communities. Despite some allegations that Anthropic’s warnings about Mythos simply constituted marketing, leading commercial software companies given early access to the model have corroborated Anthropic’s claim. Work that long belonged to a small class of elite specialists can now be done by AI, faster and at a greater scale than human teams or earlier automated tools can match.
As firms use Mythos to hunt and fix flaws in their products, a more urgent question looms: how to defend the United States and its allies from AI-powered cyberwarfare. The United States may only have nine to 12 months to protect its critical infrastructure from AI-powered attacks. Currently, two American companies, Anthropic (for which I consult) and OpenAI, have publicly demonstrated AI models advanced enough to detect flaws in software far beyond the human capacity to find, and they are restricting the use of these models to defensive cybersecurity work.
But the United States’ adversaries, and the criminals in their orbit, will soon wield the same offensive tools. China, in particular, is already racing to build and acquire these AI capabilities and may be closer to developing its own Mythos than many U.S. policymakers hope. Advanced AI will sharpen an instrument that Beijing already prizes: the credible threat to deter a fight over Taiwan before it begins by disrupting the island’s critical infrastructure and that of any nation that seeks to defend it.
Previously, successfully attacking the computer systems that run critical infrastructure—actually managing to physically shut down an energy plant, water purification plant, or pipeline—demanded specialists fluent in each kind of system’s obscure protocols. Attacks like these were rare because they were time- and resource-intensive. Mythos has already demonstrated that it can find and exploit flaws with minimal human direction, and such a model could generate many such damaging compromises automatically.
That would allow for a kind of cyberattack different from any prior one in both scale and kind. The risk is not a single massive strike on a piece of key infrastructure, a cyber–Pearl Harbor, but a world in which China and others can cheaply and quickly gain footholds across far more of the systems that run daily life—water, power, transit—and hold them at risk to deter, extort, or simply wait.
The United States has a window to bolster its critical infrastructure’s defenses, but that window is short, and those defenses are weak to begin with. In a campaign called Volt Typhoon, Chinese state-linked hackers already demonstrated how deeply they can burrow into U.S. critical infrastructure, including organizations in the water, power, and transportation sectors. Now is the time to put policy options on the table that were previously considered out of bounds: taking dramatic steps to preempt would-be attacks, making once-in-a-generation investments in cyberdefense, and helping U.S. AI labs protect themselves against the most advanced threats.
FIRST-MOVER ADVANTAGE
Throughout much of the Internet era, finding novel software vulnerabilities required expensive, highly skilled specialists. The scarcity of these specialists constrained the top end of the contest between cyber defenders and attackers. But the arrival of AI models such as Mythos and GPT-5.5-Cyber is removing that constraint. Until the unveiling of these new models, it had been hard to turn access to infrastructure’s IT networks into reliable control over the physical equipment that opens a valve, trips a breaker, or alters a chemical dose. In 2017, for instance, hackers that the U.S. Department of Justice linked to a Russian military research institute penetrated a Saudi petrochemical plant and attempted to disable its safety instrumented systems, the last line of automated defense that keeps industrial equipment from exploding or releasing toxic gas. But even after the attackers gained such deep access, their code failed to account for the exact behavior of the plant’s specific safety controllers and inadvertently tripped the equipment into a protective shutdown, exposing the operation before it could cause physical harm.
That final step has historically remained dependent on a small number of specialists who understand the proprietary control systems of a particular vendor’s equipment. The scarcity of people with enough of the right experience has kept catastrophe rare. But a high-powered AI model that can read obscure industrial firmware and develop the exact compromise that would take a specialist months threatens to turn the hardest part of designing an infrastructure attack into a routine task. A coordinated disruption across hundreds of water systems, substations, and pipelines at once has now become a more plausible risk. The most advanced AI models could soon make widespread physical compromise something a single adversary can execute, or even credibly threaten without firing a shot.
Understanding the danger, Anthropic has not released Mythos openly, instead putting it into the hands of defenders first by restricting access to a coalition of technology, finance, and open-source organizations, an effort it calls Project Glasswing. This was a notable decision: a company chose to withhold its most powerful product from broad release because the product could be turned, with little modification, into a weapon. (Eventually, Anthropic offered Fable—a product using the same underlying model but with enhanced safety guardrails—to the public.)
Within weeks of Anthropic launching Project Glasswing, OpenAI made GPT-5.5-Cyber available to vetted security teams through a program it called Trusted Access for Cyber. The early results were stunning. Microsoft, using an internal scanning system built using multiple models, disclosed sixteen previously undetected flaws in the Windows networking stack. And the cybersecurity firm Palo Alto Networks, testing the new models against its own products, reported finding far more vulnerabilities in a single scan than it typically discloses in a month.
WITHIN STRIKING DISTANCE
At the moment, the most capable cybervulnerability discovery tools belong to defenders. This is the best news in cybersecurity in decades. And despite some very capable new releases, it does not seem that Chinese labs yet possess a Mythos-level AI model.
But U.S. policymakers may not know when China achieves that capability. Private companies ultimately must publicize their models to make developing them worthwhile; even Anthropic announced Mythos’s existence while restricting its use. Governments, however, will be cautious about if, when, and how they advertise their possession of systems built to serve as national security assets.
Recent developments suggest that China is getting close to acquiring its own Mythos-class AI model. In mid-June, about a day after the U.S. government temporarily banned foreign access to Anthropic’s newly released Mythos and Fable models, the Chinese company Zhipu AI released a model called GLM-5.2. The firm claims GLM-5.2 can compete with Anthropic’s second-best model, Opus, on certain benchmarks. Unlike Mythos or OpenAI’s most capable models, GLM-5.2 is an “open-weight” model that users can download and deploy without seeking permissions from the company that made it or relying on infrastructure that the U.S. government can control. Any safeguards can be easily removed. Essentially, almost anyone can access it and use it for almost any purpose for a fraction of the cost of advanced American AI models.
U.S. policymakers may not know when China gets a Mythos-class model.
China’s rapid progress in developing such models is a function of tools available to the regime. The first is illicit or adversarial distillation. Chinese competitors use the outputs of leading American models to train cheaper imitations. In a February memo to Congress, OpenAI reported that it had observed accounts tied to DeepSeek employees circumventing its access controls to harvest model outputs for distillation. That same month, Anthropic disclosed a comparable campaign. Adversarial distillation is just another chapter in a two-decade campaign that China has run to steal American IP, including the theft of American Superconductor’s wind turbine technology and the suspicious resemblance between China’s J-31 fighter jet and the U.S. F-35.
As AI models advance, they become powerful tools for building even more capable AI. It should not come as a surprise that U.S. AI companies are using their own models to build the next generation of models, but it is easy to miss the fact that America’s chief competitors are also using top U.S. models to engineer the next version of their own models, as well.
China is not only building domestic alternatives to U.S. AI models. Chinese actors are making efforts to gain illicit access to the most powerful export-controlled AI semiconductor chips. Over the past year, the U.S. Department of Justice has prosecuted multiple large chip-smuggling networks. Smuggling alone cannot deliver the compute needed to train advanced models. But just as China is building its own models, it is building its own chips.
Finally, whenever China acquires new, high-end AI capabilities, they become available to the state in short order. Domestic Chinese AI labs operate under a regulatory framework oriented toward state access. The country’s National Intelligence Law requires Chinese companies to cooperate with state intelligence collection, and the Cyberspace Administration gives the government visibility into model behavior and outputs. As soon as a Chinese lab develops Mythos-class offensive cyber-capability, it is highly likely that the People’s Liberation Army and China’s intelligence apparatus will have early access to it.
exposed on all flanks
The decisions by American companies to limit access to models that could orchestrate unprecedented attacks on physical infrastructure have bought critical time. But each month that an adversary can siphon abilities from U.S. models and gain access to more advanced chips is a month subtracted from the defenders’ head start.
Critical infrastructure increasingly sits at the nexus between cyberspace and the physical world. If something goes wrong in these systems, the impact is not that people’s passwords get stolen and they need credit monitoring. It is the potential loss of power to a city, the contamination of a water supply, or the seizing-up of a regional transit network. This risk is not hypothetical. In December 2015, Russian hackers who had breached Ukrainian utilities with malware called BlackEnergy cut power to over 200,000 customers for several hours.
The United States’ critical infrastructure targets are structurally weak and unprepared for such an attack. They are owned and operated by thousands of small and medium-sized municipal districts and utility companies, most of which lack the budget, staff, or leverage to demand secure products from their vendors. They carry decades of technical debt, often running operational technology that was not even designed to be connected to the Internet and cannot be easily patched or replaced. Securing this firmware is far more complicated than updating an iPhone; it requires revalidation for safety that entails testing and local installations that take the facility offline. That means that even if a vulnerability is identified and a safe fix is engineered, it can take years to validate, schedule, and deploy it in equipment with a 15-to-25-year lifecycle, and many operators, facing the prospect of downtime they cannot afford, have little choice but to defer updates.
It is therefore possible that a fix designed today and extensively tested for safety wouldn’t be installed until 2030. This is an eternity in an age of AI-driven cyberattacks. The operators most exposed to the coming wave are precisely those least equipped to defend themselves, and no amount of voluntary information-sharing will close that gap.
BATTEN THE HATCHES
On June 2, U.S. President Donald Trump signed an executive order creating a voluntary framework giving the government up to 30 days of early access to new frontier models before their broader release and directing federal IT networks to make some security enhancements. This is a useful first step, but Washington must mount a much fuller offense. The measures that follow aim to preempt attacks and prevent harm. But some intrusions will get through, so the United States must also build the resilience to absorb, contain, and recover from the compromises it cannot stop.
The United States and its closest international partners should use the capabilities they hold to disrupt the infrastructure that adversaries are using to distill and steal American models and gain illicit access to advanced AI semiconductors. Washington should impose real costs on the actors running those campaigns and degrade hostile prepositioning in U.S. networks before it can be activated. The U.S. government has the ideal partnership between the National Security Agency and U.S. Cyber Command, led by one dual-hatted leader, to focus the nation’s intelligence, security, and cyber combat power to disrupt these threats.
The United States also needs a dedicated institution to coordinate cyberdefense with deep expertise in the physical consequences of cyberattacks. The best candidate is the Idaho National Laboratory, the federal lab that, in 2007, famously (and chillingly) demonstrated that a cyberattack could physically destroy a diesel generator, not only steal data or disrupt communications. This lab could oversee the provisioning of concrete defensive capabilities to small and medium-sized operators in the water, electricity, and transportation sectors.
Simply scanning for vulnerabilities will not be enough. While patching is necessary, it is insufficient: defenders must do more than patch more, better, and faster. The coming flood of AI-discovered flaws will overwhelm any patching regime, and for many aging systems, no patch will ever come. The United States needs to emphasize redesigning defenses so that even a successful intrusion cannot produce a catastrophic physical result. This kind of resilience means ensuring that operators can keep critical services running in a degraded, manual mode until systems are restored.
The United States needs a dedicated institution to coordinate cyberdefense.
The U.S. government, as well as infrastructure owners and operators, will have to motivate vendors to cooperate. The programs through which the AI labs share their most cyber-capable models with select defenders should prioritize admitting these vendors. Complicating things is the fact that many of the major companies that make the control systems that run U.S. water and energy plants, factories, pipelines, and other infrastructure are headquartered outside the United States. Getting these international companies to improve or patch their products’ cybersecurity will require coordinating with foreign capitals, making U.S. critical infrastructure defense a matter of alliance coordination as much as a domestic policy project.
The United States must also urgently learn the lessons of the long-running Chinese campaign to steal American intellectual property. It took too long to stand up protections such as the Defense Department’s threat-sharing with cleared contractors. A 2014 federal indictment accused Chinese military officers of hacking American firms, including the nuclear-reactor manufacturer Westinghouse, as early as 2006, but that protective program was not formalized until 2012. Today, companies throughout the AI stack are high-value foreign intelligence targets. The United States should not repeat that delay and, instead, swiftly strengthen counterintelligence support and other efforts to check the Chinese playbook.
Projects to disrupt distillation and illegal access to the most advanced chips, coordinate fixes to American infrastructure operators’ cybersecurity through a single government lab, and protect leading AI companies from espionage can all accelerate immediately if U.S. leaders demand it. The president can order many of these actions directly and can work with Congress to fast-track a meaningful appropriation for a once-in-a-generation effort to improve the security and resilience of critical infrastructure. Washington must move at speed. If the United States fails to act before its chief competitors acquire these AI models, the homeland may confront a wave of AI-powered cyberattacks unlike any it has ever faced.
Loading…

