Anthropic announced Claude Mythos in April 2026 and withheld it from public release, citing global cybersecurity implications. In controlled deployment it flagged 23,019 potential vulnerabilities across 1,000 open-source projects, of which external security firms confirmed 1,587 of the 1,900 reviewed. The actuarial question is not whether AI changes the cyber threat landscape. It is whether cyber can remain a line of independent losses or has to be priced as an accumulation peril.

Key Takeaways

  • 73% success on expert-level capture-the-flag challenges made Mythos Preview the first model to clear that tier, in the UK AI Safety Institute's evaluation. No model could complete expert CTF tasks before April 2025.
  • 1,094 of 1,587 confirmed findings (62.4%) were validated high or critical severity, and Anthropic projects the full corpus yields nearly 3,900 high-or-critical vulnerabilities, potentially 6,200 as scanning continues.
  • Under $20,000 bought a thousand-run OpenBSD campaign, and complex Linux exploit development finished in under a day for less than $2,000.
  • 25% probability of a 10-point loss ratio increase across the U.S. cyber market in CyberCube's modelling, with 10% at 20 points and low single digits at 30.

What the Model Actually Did

Benchmark Mythos Preview Claude Opus 4.6 Significance
Expert CTF success rate 73% N/A (could not complete) First model to succeed at expert tier
“The Last Ones” (32 steps) 22 avg, 3/10 full completions 16 avg, 0 completions First model to complete full simulation
Firefox vulnerabilities found 271 <25 10x improvement over prior generation
CyberGym benchmark 83.1% 66.6% 16.5-point gap
Firefox JS exploits constructed 181 working 2 working 90x exploit development rate
OSS-Fuzz crashes (tier 1-2) 595 ~250-275 2x+ fuzzing effectiveness

The multi-step results matter more than the benchmark scores. On "The Last Ones," a 32-step corporate network attack simulation estimated at roughly 20 hours of human professional effort, Mythos completed all 32 steps in 3 of 10 attempts and averaged 22 steps. Claude Opus 4.6 averaged 16 and completed none. XBOW, the external red-team evaluator, judged it a significant step up over all existing models regardless of provider.

The archaeology is the other signal. Mythos found 271 vulnerabilities in Firefox alone, more than ten times what the prior generation identified in the same codebase, plus a 27-year-old OpenBSD bug, a 16-year-old FFmpeg vulnerability and a 17-year-old FreeBSD remote code execution flaw. These were not new defects. They were old defects nobody had the labour to find.

Which is why the cost line is the capability. Vulnerability research has been rationed by the scarcity and expense of skilled researchers, and a thousand-run OpenBSD campaign for under $20,000 removes that constraint. Anthropic's response, Project Glasswing, gave controlled access to 12 launch partners including AWS, Apple, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, NVIDIA and Palo Alto Networks, backed by $100 million of model credits. Within a month those partners identified over 10,000 high-or-critical-severity vulnerabilities, and Palo Alto Networks reported the equivalent of a year of pentesting in under three weeks.

Independence Was Load-Bearing and It Is Gone

Cyber rate filings assume losses across a portfolio are reasonably independent. A ransomware attack on a healthcare provider does not raise the probability of one on a manufacturer, and that assumption is what makes a compound frequency-severity model appropriate.

Two things break it here. The same vulnerability sits in thousands of organisations at once because they share open-source dependencies, cloud infrastructure and software supply chains, so a critical flaw in a library used by 10,000 companies opens one correlated exposure window that stays open until each of them patches. And the discovery cost fell far enough that a single actor can find and weaponise at that scale.

Geographic diversification has no analogue. A Florida hurricane book hedges a California earthquake book; nothing hedges a shared software dependency. CyberCube describes concentration as structurally embedded at multiple layers of the stack, from lithography and chip fabrication through GPU compute, foundation models and hyperscale cloud.

Scenario Loss Ratio Impact Probability (CyberCube) Historical Precedent
Moderate AI-accelerated campaign +10 points 25% Comparable to elevated ransomware years
Major coordinated exploitation +20 points 10% Between BlueKeep and NotPetya impact
Systemic AI-driven event +30 points Low single-digit BlueKeep 2019 (30-point rise observed)

The BlueKeep precedent is what makes the right column something other than speculation. That wormable Windows vulnerability drove a 30-point average loss ratio rise across U.S. cyber insurance in 2019, and it required human discovery and manual exploitation.

The pricing consequence follows from the first row rather than the last. A 25% probability of a 10-point loss ratio increase is a frequency-weighted expected impact of 2.5 points, and that belongs in the rate indication as a catastrophe load rather than sitting in the tail commentary. Events of this shape are not tail-of-tail; at those probabilities they sit inside the body of the loss distribution, which is also where the reserving problem lives, because IBNR built on independence understates a correlated event by construction.

Chubb's Evan Greenberg named the segment carrying it on the Q1 call: middle-market companies, "the biggest meatball," with more money, weaker perimeters and less focus on hygiene. That is also the segment that buys the most cyber coverage. Chubb itself ran an 84.0% P&C combined ratio in the quarter against 95.7% a year earlier, which is the balance sheet from which pricing uncertainty is comfortable to discuss.

The Policy Form Does Not Mention Any of This

Most cyber wordings do not expressly reference AI, so losses arising from AI-discovered vulnerabilities are non-affirmatively covered. That is silent cyber again, one layer up, and Lloyd's spent three years forcing syndicates to clarify the first version through market bulletins.

The unresolved questions are specific. If an attacker uses a model to find a zero-day in widely used open-source software and exploits it across hundreds of insureds at once, does each policy respond independently or do aggregation clauses engage? Does failing to patch a vulnerability that was discoverable by AI but not publicly disclosed breach a reasonable security measures condition? Nothing in the current forms answers either.

Glasswing sharpens the second question rather than settling it. Access has expanded to roughly 150 organisations from an initial cohort of around 50, and partners work to a 90-day reporting timeline, so disclosure follows a structured delay. Over 99% of vulnerabilities Mythos discovered remained unpatched as of May 2026. During that window the organisations inside the perimeter can find and fix their own exposure, and everyone else carries risk they cannot see, in the same libraries, at the same time.

Beazley's Alessandro Lezzi offers the counterweight on timing, noting these models still require significant computational power and are expensive to operate, which limits threat actors' ability to deploy them at scale. That is true and it is a statement about cost, not about capability, and cost is the variable in this story that has been falling.

The market is already pricing the aggregation rather than the wording. Beazley holds over $1 billion of protection against systemic cyber aggregation including $670 million of cyber catastrophe bonds, and Lloyd's requires portfolio-level sub-limits, tighter event definitions and informal caps on exposure concentration by sector and platform. Reinsurance is repricing a correlated peril while the primary contract underneath it still describes an independent one.

Further Reading on actuary.info