menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

When China Gets Its Own Mythos

1 0
yesterday

In April, Anthropic disclosed that its newest frontier AI model, Claude Mythos, could find and exploit security vulnerabilities in software better than “all but the most skilled humans.” By way of example, the company noted that the model had uncovered a flaw that had gone undetected for 27 years in a secure operating system used to run firewalls that guard sensitive networks. The revelation jolted the cybersecurity and national security communities. Despite some allegations that Anthropic’s warnings about Mythos simply constituted marketing, leading commercial software companies given early access to the model have corroborated Anthropic’s claim. Work that long belonged to a small class of elite specialists can now be done by AI, faster and at a greater scale than human teams or earlier automated tools can match.

As firms use Mythos to hunt and fix flaws in their products, a more urgent question looms: how to defend the United States and its allies from AI-powered cyberwarfare. The United States may only have nine to 12 months to protect its critical infrastructure from AI-powered attacks. Currently, two American companies, Anthropic (for which I consult) and OpenAI, have publicly demonstrated AI models advanced enough to detect flaws in software far beyond the human capacity to find, and they are restricting the use of these models to defensive cybersecurity work.

But the United States’ adversaries, and the criminals in their orbit, will soon wield the same offensive tools. China, in particular, is already racing to build and acquire these AI capabilities and may be closer to developing its own Mythos than many U.S. policymakers hope. Advanced AI will sharpen an instrument that Beijing already prizes: the credible threat to deter a fight over Taiwan before it begins by disrupting the island’s critical infrastructure and that of any nation that seeks to defend it.

Previously, successfully attacking the computer systems that run critical infrastructure—actually managing to physically shut down an energy plant, water purification plant, or pipeline—demanded specialists fluent in each kind of system’s obscure protocols. Attacks like these were rare because they were time- and resource-intensive. Mythos has already demonstrated that it can find and exploit flaws with minimal human direction, and such a model could generate many such damaging compromises automatically.

That would allow for a kind of cyberattack different from any prior one in both scale and kind. The risk is not a single massive strike on a piece of key infrastructure, a cyber–Pearl Harbor, but a world in which China and others can cheaply and quickly gain footholds across far more of the systems that run daily life—water, power, transit—and hold them at risk to deter, extort, or simply wait.

The United States has a window to bolster its critical infrastructure’s defenses, but that window is short, and those defenses are weak to begin with. In a campaign called Volt Typhoon, Chinese state-linked hackers already demonstrated how deeply they can burrow into U.S. critical infrastructure, including organizations in the water, power, and transportation sectors. Now is the time to put policy options on the table that were previously considered out of bounds: taking dramatic steps to preempt would-be attacks, making once-in-a-generation investments in cyberdefense, and helping U.S. AI labs protect themselves against the most advanced threats.

FIRST-MOVER ADVANTAGE

Throughout much of the Internet era, finding novel software vulnerabilities required expensive, highly skilled specialists. The scarcity of these specialists constrained the top end of the contest between cyber defenders and attackers. But the arrival of AI models such as Mythos and GPT-5.5-Cyber is removing that constraint. Until the unveiling of these new models, it had been hard to turn access to infrastructure’s IT networks into reliable control over the physical equipment that opens a valve, trips a breaker, or alters a chemical dose. In 2017, for instance, hackers that the U.S. Department of Justice linked to a Russian military research institute penetrated a Saudi petrochemical plant and attempted to disable its safety instrumented systems, the last line of automated defense that keeps industrial equipment from exploding or releasing........

© Foreign Affairs