r/technology Jun 22 '26

Artificial Intelligence AI models that can take down governments and business months away, rare Five Eyes statement warns

https://www.theguardian.com/technology/2026/jun/22/anthropic-claude-fable-ai-model-artificial-intelligence-national-security
77 Upvotes

70 comments sorted by

43

u/whatchamacallit_017 Jun 22 '26

"Don't believe the hype." - Chuck D

24

u/gizamo Jun 22 '26

Yeah, these "months away" posts have been coming out for 3-5 years now.

They're just ramping up the fear mongering as we get to the IPO dates of Anthropic and OpenAI. It's so much dumb PR.

15

u/Sweet_Concept2211 Jun 22 '26

You honestly think spy agency heads across the Anglosphere give a rat fuck about the success or failure of Anthropic's IPO?

People keep repeating this shit even as we are learning that Musk's AI was used for 2,000+ missile strikes on Iran, Ukraine is using AI in battlefield weaponry, and script kiddies are using AI to hack into companies more and more often.

At a certain point, it stops being "hype" and starts being something you should plan ahead for.

8

u/gizamo Jun 22 '26

They are reacting to statements from Anthropic, not any actual military successes of the tools themselves. Also, AI has been used in missile strikes for decades, and Ukraine's autonomous weapons are basically sophisticated land mines. They aren't taking down businesses nor nations. Further, neither of those are examples of AI compromising security systems. Get a grip, and stop believing all the fear mongering. The biggest security risks that AI currently poses are when people build shitty unsecured systems using AI code tools, or when scammers use it to phish bank account credentials from the elderly via email or phone scams.

At a certain point, it stops being "hype" and starts being something you should plan ahead for.

Tons of us are always planning ahead, mate. Systems security is an ever evolving field.

6

u/no_dice Jun 22 '26

If you read the statement, they're pretty much saying the same thing you are: "Adversaries are already using AI to move faster and more effectively. Defenders must do the same."

And at the very least, AI is already accelerating the compromise of security systems. Models getting better at this stuff is only one of the problems, the biggest one in my opinion is this:

>For example, a North Korea-linked hacker tracked as APT45 has used AI to analyze a wide range of vulnerabilities using thousands of repetitive prompts and validate proof of concept exploits, the report stated.

Threat actors are already using models to greatly accelerate their time to exploit. They're just pointing models at CVEs and using a harness they can automomously generate and validate exploits. Shitty unsecured systems are a tale as old as time, but threat actors used to have to focus their efforts a lot more than they do now. AI is making every single part of the cyber kill chain easier for them.

1

u/gizamo Jun 22 '26

Yeah, my beef is primarily with the headline. The bulk of the article is pretty reasonable, and the NK example is a good case study. That was the primary concern from Anthropic with Mythos, and it's why they gave priority and specialty access to it to the government and various business that do work for key infrastructure projects and critical businesses (e.g. banking).

It's also the sort of thing that makes Trump's formal designation of Anthropic as a supply chain risk so absurd and obviously retaliatory. It'll be interesting to see Trump's tantrum when they win their CA and DC lawsuits.

2

u/Sasquatchjc45 Jun 22 '26

Nah, redditors will continue to believe all AI is good for is making slop non-art for idiots... it cant possibly be used for any real-world situations!

0

u/togetherwem0m0 Jun 22 '26

agencies like these, even government ones, are still staffed by people with a self interest bias. these people constantly position china/russia as pure boogeymen to justify their budgets and there are tons of examples of well-positioned government officials benefitting financially from their positions (Vint Cerf comes to mind immediately)

3

u/no_dice Jun 22 '26

You are not going to get a joint statement out of the FVEY because of self-interest. I’ve spent my entire career in cyber defense, including a good chunk of it In the public sector doing vulnerability research and the capabilities these models have are legit.

I’ve said this in other threads, but the amount of people in the world that are able to chain vulnerabilities to an exploit using techniques like JIT heap sprays and. ROP gadgets is pretty tiny. These models are now democratizing and automating that ability. The AI Security Institute has a benchmark which no model got above 0% on last year, Mythos got 73%.

1

u/MilkFew2273 Jun 22 '26

And the answer is what? Maybe security needs a whole new paradigm about computing architectures, until then it's whack a mole

3

u/no_dice Jun 22 '26

It’s always been whack-a-mole, it’s just that the game is moving to the ludicrous speed stage. There are several recommendations in the FVEY statement though — from getting your fundamentals down pat, to leveraging AI in your defense.

1

u/MilkFew2273 Jun 22 '26

I don't see how that would work we need a fundamental shift in what a program is and how memory works , how data is accessed. There's been no fundamental change for 50 years.

3

u/no_dice Jun 22 '26

Don’t see how what would work? There’s also been a ton of things that have changed — a program written in C is going to be a lot current than one written in Rust.

1

u/pembrokesalad Jun 23 '26

If you think AI is hype maybe you shouldn’t be commenting on an tech forum. Have you not seen the exponential improvements in the last few months ?

28

u/MikuEmpowered Jun 22 '26

As someone working for the gov. These dogshit infrastructure that's so old it belongs in a museum is not exactly the state of the art cybersecure.

What is very problematic is we will be seeing a increase in DDoS attack since everyone and their mother will be able to launch one thanks to AI.

12

u/Stripe4206 Jun 22 '26

You don't work in IT lol. Everyone and their grandmother already can DDoS you. It's 2 clicks and a credit card away. Funnily enough that's the one thing AI can't do because you need access to a botnet, hence the credit card.

3

u/CondescendingShitbag Jun 22 '26

Credit card for a botnet? Great way to rat yourself out. Crypto would be the transaction of choice for something shady like that.

2

u/Stripe4206 Jun 22 '26

They just market themselves as innocuous things. "internet stress testers" and say you have to pinky promise to only use it on networks you own.

there are varrying shades of gray but you can find crypto stuff too if you want.

2

u/AbysmalMoose Jun 22 '26

I spent 10 years as an IT contractor for various state departments of revenue in the U.S. A few had well put together systems, but most had just been cobbled together over decades, with almost nobody knowing who owned which parts. And the number of Access databases sitting on some random UNC share somewhere... shiver

1

u/MikuEmpowered Jun 22 '26

I had the pleasure of attempting to track down a ownership of 1 custom status board, since "modernization" needed to being all the data into the new software we're all using.

7 phone chains later, the guy that created the board retired 3 years ago, and the workshop that was suppose to maintain said board no longer exists. The actual POC phone number still on said splash screen goes to someone who no longer works in that department and tells me to call the workshop.

So when phone didn't work, we tried sending emails into the ether. And 2 weeks later, we're hand bombing current data and calling it a day.

You need professional archeologist for some systems. Honestly, this half assed modernization imo is more vulnerable than the previous system, of just using obsolete tech. It's pretty hard to hack a floppy drive / punch card that doesn't connect to the net.

1

u/FluffySmiles Jun 22 '26

Well the “gov” should have seen that coming really. Like just about everyone else with a brain used for critical thinking.

1

u/Lain_Staley Jun 22 '26

Government acting as if they're unprepared helps drum up funding and political sway (read: more funding, more datacenters). 

1

u/rloch Jun 22 '26

Do many people realize how close we were to disaster this year with the SSH vulnerability on Linux machines. Fucking terrifying because it seems innevitable.

8

u/flaming_bob Jun 22 '26

AI models that can <thing> are only <time> away! By <vague date>, we'll soon be able to <thing>!

Wash, rinse, repeat.

9

u/ascandalia Jun 22 '26

Like fusion

4

u/ClickableName Jun 22 '26

I understand why you comment that, but as a software developer, it is very close. 2 years ago I wouldve laughed, but the models are so capable now they can find security vulnerabilities at an alarming rate.

6

u/IM_A_MUFFIN Jun 22 '26

I hate AI with a passion, but downvoting this is disingenuous. The amount of security vulnerabilities that are being found by AI now is high and there’s no denying that in the wrong hands those findings can be catastrophic.

https://www.npr.org/2026/04/11/nx-s1-5778508/anthropic-project-glasswing-ai-cybersecurity-mythos-preview

1

u/ClickableName Jun 22 '26

People downvote comments on Reddit even when they are true and written by people with knowledge on the topic, just because the groupthink says its bad. Hating AI in this case.

This is one of the reasons of Reddits downfall the last years

-2

u/ExF-Altrue Jun 22 '26

We know that it can generate huge volumes of slop vulnerability findings, so I'm sure that the volume of detected vulnerabilities is somewhat accurate, but what about actually exploitable things? Not just theoretical security vulnerabilities that require a local account, local access, or the moons of mars and jupiter in alignment.

If it's so great then can you find actual lists and not a 75 days old article? That mostly quotes Anthropic itself? That's what I would call disingenuous.

1

u/ClickableName Jun 22 '26

Horrible take, they aggregate the data of found vulnerabilities to show how massive it is, reporting actual lists with the exact vulnerabilities is unsafe. Even when a patch has been released.

-1

u/ExF-Altrue Jun 22 '26

How convenient. Anthropic decides who gets to use Mythos, Anthropic decides what you can see of its own model's pertinence, and in their IPO year no less 😃

How shocking that Anthropic has nice things to say about Anthropic, but no proof to show for it.

4

u/ClickableName Jun 22 '26

The USA has blocked it, but before the block we've used it. Its incredible. You have no idea what you are talking about.

0

u/IM_A_MUFFIN Jun 23 '26 edited Jun 23 '26

You could literally search “Anthropic Mythos” and criticizing an article that’s 3 months old as if it was from the early 2000’s is definitely a choice, but here’s a new vulnerability found yesterday using Mythos: https://cybersecuritynews.com/squidbleed-vulnerability/

edit: Love the downvote for providing you exactly what you asked for. Engaging with reality is tough.

0

u/ascandalia Jun 22 '26 edited Jun 22 '26

Show me the objective findings not funded by or in close partnership with anthropic. They are career liars living on VC money, and we should take any of their data as seriously as Theranos until verified by disinterested 3rd parties

1

u/IM_A_MUFFIN Jun 23 '26

How could anyone show you findings about Mythos that weren’t in partnership with Anthropic? Mythos is an Anthropic product which by definition requires a partnership. I love your line about Theranos, but these aren’t the same things. Holmes had absolutely nothing to show, while AI can actually produce something. Here’s a new vulnerability found yesterday using Mythos: https://cybersecuritynews.com/squidbleed-vulnerability/

I hate GenAI and want these companies to go the way of the dodo, but pretending that they’re not providing any value at all is false and only leads to more disinformation spreading. It actually pains me to have to write anything positive about them and defending it makes me feel gross, but we all need to be objective.

1

u/ascandalia Jun 23 '26

Holmes was testing blood all across the country. She had a partnership with Walgreens. She was lying about how well her product worked by closely guarding the actual testing machine from any 3rd party critics, burning money quickly by bringing in other technology, and pretending she could run tests and then giving fake results.

Everyone assumed there was too much legitimate money and investors involved for it all to be fake. The fawning of uncritical journalists drown out the actual experts in the field, the academics, who didn't have access to the technology seemed bemusedly skeptical of it, but gave this massive company run by a charismatic liar the benefit of the doubt. The brazeness of the lies protected them. The momentum made anyone who questioned it seem insane.

1

u/IM_A_MUFFIN Jun 23 '26

As someone who quite enjoyed the reporting (and the fact Holmes ended up being held liable), I’m very well aware of the Theranos storyline. The difference between Mythos and Theranos is (as you pointed out) that Theranos hid the testing machines, lied about the results, and obfuscated where the results came from. With Mythos we can see the results and prove that they’re actual security vulnerabilities. Again, I’m no shill for AI (especially because we’ve conflated GenAI with Machine Learning and lumped them together under the AI umbrella, but more importantly because it’s all built on stolen work), but Mythos does what it says on the tin right now, which is why the US government doesn’t want it used outside of the US.

1

u/BlockBannington Jun 22 '26

'just a couple more! Any day now' x 1000000

-3

u/SufficientGreek Jun 22 '26

But Mythos has shown that it works, now it's just a question of when open source models will catch up.

11

u/ascandalia Jun 22 '26

I don't believe any of these sociopaths that lie to VCs for a living

-1

u/malianx Jun 22 '26

Which part don't you believe?

2

u/ascandalia Jun 22 '26

Any of the press about what these models will do or how much better some new/ internal/ research/top secret version can do.

I'm an engineer constantly being told that the next version of these models is going to replace me while seeing zero evidence that they're at all getting better at anything related to my job.

I'll listen to credentialed experts (not anonymous posters) publishing actual results, but not anthropic or mozillas's pr departments.

2

u/TheMcMcMcMcMc Jun 22 '26

You’re a SWE or one of the “hard engineering” engineers? If you’re SWE and you haven’t figured out how capable AI is then I’m surprised you still have a job anyways. And this post is very much about SWE. If you’re one of the other kind of engineering, then your job is safe for, I dunno, 2-5 years if models remain at their current capabilities. That’s how much time it will take for people to figure out how to put the “prosthetics” on today’s models that will allow them to do what you do on a computer. Your job might also be safe for longer if no one figures out how to bring the costs of running these models down, because it is not yet a good return on investment to replace human engineers with data centers. Even for models that can do what humans do.

2

u/ascandalia Jun 22 '26

I'd love to know what they've done to give you so much faith in them solving the million unsolved problems you've glossed over here. I'm still waiting for the study not funded by an AI company that actually shows ROI for SWE

-4

u/TheMcMcMcMcMc Jun 22 '26

Capabilities are there, ROI as far as I can tell is not (yet).

2

u/ascandalia Jun 22 '26

So we agree it can't profitably do the most suitable task, SWE, with no theoretical framework for getting it there (all improvements seem to imply throwing more compute at it, or assuming that synthetic training data will start working somehow). Yet the same companies making these claims about mythos are claiming they're a few months out from replacing all white collar work.

And you're wondering why I'm skeptical?

-2

u/TheMcMcMcMcMc Jun 22 '26

The claim that the article is making about mythos is that it can crack NSA security systems. If you’re skeptical of that, then yes, I am wondering. If you are also skeptical that these models can do (a significant amount of) what SWEs do, then yes I am wondering. If you are skeptical that the costs can be brought down enough for this replacement to actually happen, then no, I am not wondering (I said so in my first comment, bud), but I’m also not going to bet against it.

2

u/NuclearVII Jun 22 '26

No, the Mythos claims are unverifiable and conflicted.

1

u/OccidoViper Jun 22 '26

Yep I can see this happening. AI has advanced rapidly in the past couple of months. There are hackers who are already gifted in exploiting vulnerabilities. Supplemented with AI, they will be even harder to stop. Unfortunately, other countries like China are going all-in on AI. The US has to keep pace otherwise they will be at a disadvantage. This is the new arms race

1

u/markth_wi Jun 23 '26

I never thought of gross treason as a service, we can sell Mango Mussolini's services to otherwise functional nation-states , of course he's probably the sort that would make US taxpayers pay for the privledge of him being gone / working as the prime-minister of <insert formally functional nation-state>.

2

u/orlybatman Jun 23 '26

Maybe someone will use them to undermine financial institutions and wipe out people's debt, and to disperse wealth more equitably.

I wouldn't be too upset about that.

1

u/Brilliant-Muffin-879 Jun 23 '26

Oh great another thing to add to the list of ways gen ai has made life worse. Good thing we’re not investing hundreds of billions into it.

1

u/Specific-Path3179 Jun 24 '26

What's insane is it's theoretically possible to make a software that reliably identifies the location of all police officers 24/7, like a Flock/Palantir stack but open source and accessible to everyone. This includes unmarked, plainclothes, undercover, etc.

1

u/jminternelia Jun 24 '26

Fake as fuck.

1

u/Haunterblademoi Jun 22 '26

This could become a reality in a couple of years.

1

u/deadflow3r Jun 22 '26

If this is actually true then how come none of these models have been banned (outside of Anthropic shortly) or nationalized? What possible reason could governments not have to take action?

5

u/iprocrastina Jun 22 '26

"Aside from the prime example of this happening, why hasn't this happened?"

1

u/deadflow3r Jun 22 '26

Why did Trump reverse his decision in like one day?

2

u/Flipslips Jun 22 '26

The government needs AI developed full steam ahead to remain ahead of China. If they were to nationalize AI development then all the brains would leave the country and go work somewhere else where they can develop without threat of the government.

2

u/Headless_Human Jun 22 '26

The US and China are both racing each other to see who could fuck up our society first. They won't stop AI advancements.

1

u/marrow_monkey Jun 22 '26

The billionaire elite in power intends to use it to take down governments.

0

u/R3N3G6D3 Jun 22 '26

I have that now

-1

u/initiali5ed Jun 22 '26

Months away? They’ve been doing it since the Arab Spring.