The Mythos Effect: How Frontier AI Is Reshaping Risk, Security and Governance
By Daniel Popovski, Senior Policy and Advocacy Advisor, Governance Institute of Australia

The suspension of the new AI tool, Mythos, over US government security concerns shows how quickly frontier AI is reshaping the cybersecurity environment.
Governance frameworks are struggling to keep pace as the technology rapidly advances and boards need to treat AI as a strategic risk rather than a purely operational one.
The key issue is not simply a more capable AI model, but the emergence of AI systems that can autonomously discover and potentially exploit software vulnerabilities at a scale and speed beyond human capabilities.
This has triggered concerns about critical infrastructure security, frontier model governance, board and executive capability, and the widening gap between vulnerability discovery and remediation.
AI has shifted the cybersecurity paradigm
Mythos represents a fundamental change in cyber risk. AI may radically reduce the cost and expertise required to discover cyber vulnerabilities, shifting the balance of power between attackers and defenders. As highly capable AI becomes more widely available, malicious actors will deliver cyber threats at greater scale and speed.1 The Australian Cyber Security Centre warns that organisations that don’t improve their defences will be vulnerable to these AI-enabled cyber threats. This cannot be left to cyber defenders alone… and it will require a rethink of process and require organisational change in some areas.2 The Center for Humane Technology describes this as a potential “skeleton key” for the digital world, raising questions about how society should govern technology that can systematically uncover weaknesses in critical systems.3
The real risk: discovery, response and remediation gap
Organisations that previously used Mythos to identify operational and cybersecurity vulnerabilities across complex environments now have clearer visibility of previously unknown weaknesses, security gaps and architectural risks, strengthening their understanding of required cyber responses. However, since Anthropic has withdrawn Mythos models globally, it raises an immediate governance and risk management challenge.
Adopting a defensible approach to tech governance
The existence of a known vulnerability is often more significant than the mechanism by which it was discovered, particularly where it applies to Australia’s most critical infrastructure assets regulated by the SOCI Act. For organisations, the key question is not whether immediate remediation was feasible, but whether appropriate controls could be implemented to reduce risk to an acceptable level, particularly whether the organisation can demonstrate that it understood the risk, assessed it appropriately and implemented reasonable measures to manage it. Critically, organisations must be able to demonstrate that appropriate processes, governance and decision-making amount to a defensible approach as much as technical outcomes. In the Governance Institute’s latest white paper, Governing in the age of agentic AI, the evolution of governance in relation to frontier AI agents necessitates directors demonstrating why a decision was taken, how it was executed and whether it can withstand challenge after the fact.
Regulators put organisations on notice
ASIC, APRA and the Australian Signals Directorate have warned that as AI becomes more autonomous, risk is moving faster and is less predictable, requiring stronger oversight and more robust cyber and resilience controls. The recently published Five Eyes cyber security agencies statement has summarised practical actions that can be taken now to address the emerging frontier AI model governance challenges, including:
- Reducing the organisation’s attack surface
- Accelerating patching processes
- Addressing legacy systems
- Reviewing and strengthening identity and access controls
- Preparing for incidents before they happen
For Australian entities operating critical infrastructure, particularly financial services and other highly connected sectors with shared third-party software technologies, asking the question whether governance frameworks can oversee agentic or highly autonomous AI systems has become a necessity.
3 https://centerforhumanetechnology.substack.com/p/anthropics-mythos-has-changed-cybersecurity