Summary
- AI-driven vulnerability discovery and attack automation are compressing the time between software flaws being identified and potentially exploited.
- Organisations need to combine AI-assisted defence with stronger software protection, identity controls, governance, and human oversight.
- Machine-speed cyber operations are changing the economics of attack and defence, making trusted, rapid decision-making increasingly important.
Contributed article
Todd Moore
Vice President of Encryption Products, Thales
The arrival of powerful security LLMs such as Anthropic’s Claude Mythos has intensified discussion about the future of cybersecurity as a function. Anthropic reports that its model can identify and exploit vulnerabilities, reverse-engineer closed-source software, and combine weaknesses into complex attack paths. It is already helping surface previously undiscovered vulnerabilities and causing software vendors to reassess their approach to patching.
Regardless of the individual tools that emerge – whether Mythos or otherwise – what was once a possibility is now a reality, raising questions as to what cybersecurity looks like, and how organisations should respond as more advanced capabilities inevitably develop.
AI is compressing cyber timelines
AI is not reinventing cybersecurity; it’s accelerating it. Vulnerabilities, reverse engineering and automated scanning have existed for decades. Attackers are moving from human speed to machine speed, while most defenders still operate on human timelines. Software flaws that might have been hidden for months or years may now be discovered in minutes, with AI capable of chaining vulnerabilities together and automating attack paths.
Organisations must assume their software will be continuously analysed, deconstructed and stress-tested by adversarial AI. Although this isn’t a reason to panic, it does require a fundamental rethink of software protection.
As the window between discovery and exploitation shrinks, developers need to make applications more resilient by protecting sensitive code and data, securing keys and secrets, and embedding runtime defences that detect tampering or debugging attempts. It’s all about reducing the visibility attackers rely on, alongside increasing the effort required to analyse and compromise applications, thus regaining defender time.
The economics of cybersecurity are changing
While it lowers the barrier to entry for attackers, running advanced AI models still requires significant compute power, infrastructure and investment, creating new operational and economic trade-offs as organisations balance AI models with human expertise.
It has meant that time has become extraordinarily valuable as a resource. The longer defenders can delay, disrupt or complicate attacks, the more expensive they become from both a compute and operational perspective, making organisations less attractive targets.
This demands a more industrialised approach to cybersecurity, combining AI-augmented security operations, AI-driven DevSecOps, advanced testing and automated response within a trusted framework.
As AI-powered reconnaissance, automated vulnerability discovery and sophisticated phishing continue to grow, organisations must combine AI-driven defence with human judgement to prioritise risk, make informed decisions and maintain operational stability. The objective is faster, more resilient security while maintaining human oversight and accountability.
Trust, governance, and identity must keep pace
One of the consequences of improving both defence capabilities and the speed of response, often using AI to do so, is that organisations in turn must consider the governance and identity implications of introducing these non-human actors into their environments.
Just as human users are accompanied with their own protection and monitoring, AI agents accessing applications, data and workflows also need to be treated as identities themselves. Their permissions must be tightly controlled, credentials protected, actions logged and authority continuously reviewed. As complexity increases, it emphasises the need for identity to no longer be a one-time authentication event, but an ongoing process of verifying access, intent, and behaviour.
This is fundamentally a governance and digital trust challenge. Organisations must review the systems they have in place for Identity and Access Management to ensure they’re up to the task of monitoring not just what systems are being accessed, but what permissions are being granted, the scope of activity, and the controls and auditing accompanying it.
A new operational reality
Mythos may ultimately be remembered less as a single technology and more as a sign that cybersecurity has entered a new era defined by automation, machine-speed operations and compressed timelines.
The organisations that succeed will be those that adapt strategically: making their software harder to analyse, strengthening governance around identity and trust, and evolving security and patching operations to match the speed of the threat landscape. Just as importantly, organisations will need to prioritise where they invest their security efforts, spending their security tokens wisely to maximise the level of defence and resilience they can achieve.
In a world where both attackers and defenders operate at machine speed, the ability to make trusted decisions quickly may become one of the most important security capabilities of all.




