What to know about the AI models that are jolting Washington - POLITICO
Skip to Main Content
What to know about the AI models that are jolting Washington<br>Researchers who have tested Anthropic’s Mythos and OpenAI’s GPT-5.5 say their hacking capabilities are a “game-changer.”
Those who have experimented with Mythos and GPT-5.5 in a controlled setting say the tools are advancing much faster than anticipated — and will change the digital security landscape forever. | Sebastien Bozon/AFP via Getty Images
By Maggie Miller and Aaron Mak05/24/2026 07:00 AM EDT
Anthropic and OpenAI have spent the last month touting the hacking capabilities of their new artificial intelligence models.<br>Researchers with access to these tools say they’re not exaggerating — and warn that the fallout could be even larger than imagined, as tools such as Anthropic’s Claude Mythos and OpenAI’s GPT-5.5 continue to develop.
“It was very clear to me that this was going to be a game-changer,” Lee Klarich, chief product and technology officer at cybersecurity company Palo Alto Networks, said of testing Mythos when it was first unveiled. “I would actually say if you asked me today, it’s more [powerful] than I thought it was going to be then.”
Both AI companies have kept testing of their frontier AI models limited to small groups of trusted organizations because of the technologies’ advanced cyber capabilities, which have so far outpaced other publicly available digital tools — and even the most skilled human minds.<br>At the time of its announcement last month, Anthropic said Mythos had “already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser,” and warned that the consequences of setting this technology loose could be “severe” for global economies, public safety and national security.<br>This has led to government agencies, congressional committees, banks and regulators clamoring for access in recent weeks, so that they can secure critical networks before adversaries get their hands on the technology to launch devastating cyberattacks.<br>POLITICO spoke to nine of the nation’s top cyber researchers and tech leaders who have experimented with Mythos and GPT-5.5 in a controlled setting, and all of them came to the same startling conclusion: These tools are advancing much faster than anticipated — and will change the digital security landscape forever.<br>Isaac Evans, CEO of cybersecurity company Semgrep, said that when trialing Mythos, it “exceeded our expectations.”<br>“The model’s not superhuman across all dimensions, but at least in some narrow cases, it’s really demonstrating an uncanny ability around exploit generation,” Evans said.<br>He added that some described Mythos as capable of generating “a SolarWinds every quarter,” referring to the Russian government’s breach of U.S. federal agencies in 2020. The incident is widely regarded as one of the worst hacks in history and affected more than 18,000 organizations worldwide through compromised software.<br>Jonathan Trull, chief information security officer of IT security company Qualys, which is testing GPT-5.5, said the model “can basically do what your most advanced app security engineer can do.”<br>This early feedback from those who have experimented with these models makes clear that the mystique around emerging AI technology is not just marketing. Rather, it reflects how the race to create the most sophisticated AI tools that can outsmart human intelligence has begun — and no one person, industry or government has yet figured out how to prevent them from being used to create widespread destruction.<br>Many of the specific vulnerabilities that models such as Mythos and GPT-5.5 have been able to sniff out are not yet public — though details are starting to leak.<br>Mythos was able to bypass Apple security for its MacOS system in just days, The Wall Street Journal reported last week, a famously tough program to crack. Rep. Lou Correa (D-Calif.), a member of the House Homeland Security Committee, told POLITICO after emerging from a closed-door briefing from Anthropic on Mythos earlier this month that the AI tool was able to break into his bank account with ease.<br>And Cloudflare Chief Security Officer Grant Bourzikas stated in a blog post published this week that Mythos can both identify vulnerabilities and write code to exploit them, marking a “real step forward” for this type of advanced AI technology.<br>Cybersecurity firm Broadcom, which has been testing Mythos against its own software code, described its findings as “jolting” in a report published last month.<br>“We are learning things that appear unlikely to ever have been uncovered by human researchers alone,” the report reads.<br>Advanced AI tools could potentially be a game-changer for cyber officials who secure critical networks across critical sectors, including water facilities, hospitals and telecommunication networks. This is because AI models will allow coders to check for bugs in new software...