Skip to content

Comment

The Claude AI Model Myth

With the launch of ‘Claude Mythos’ in the spring of 2026, the US company Anthropic has introduced a new standard of AI models into the debate. Unlike traditional large language models, Mythos is specifically designed with cyber security in mind. However, security must not come at the expense of confidentiality and sovereignty.

Code auf einem Bildschirm
7 May 2026 | Essen

Claude Mythos - A Game-Changer in Software Security?

The system can analyse software independently, identify previously unknown vulnerabilities (‘zero-day vulnerabilities’) and, in some cases, even exploit them. According to recent reports, the model has already discovered “thousands of highly critical security vulnerabilities” in operating systems and browsers – some of which are found in code that has been in use for decades. At the same time, access is to remain strictly limited: as part of ‘Project Glasswing’, only selected organisations will be granted access, as the potential for misuse is considered to be significant.


A paradigm shift in security – is a ‘tsunami’ of vulnerabilities on the horizon?

From an audit body’s perspective, one thing is clear: the technological possibilities are impressive. AI models such as Mythos drastically speed up vulnerability analyses – tasks that take human experts weeks can be automated and completed in a matter of hours.

This gives rise to a potential paradigm shift:

  • Proactive, automated identification of vulnerabilities during development
  • Scalable, time-efficient code analysis, even for complex systems
  • Support for secure development and compliance

Some experts are already referring to a ‘turning point for cyber security’, as AI is, for the first time, capable of systematically and comprehensively uncovering security vulnerabilities. However, given the extensive integration and possibilities, some experts fear a tsunami of ‘zero-day’ vulnerabilities this time – not just a simple wave.


When defence becomes a weapon

Yet this is precisely the crux of the ‘Myth’ narrative – the same capabilities can also be used offensively. According to experts, the model is capable not only of finding vulnerabilities, but also of chaining them together and exploiting them. This is a scenario that, until now, was only possible for highly specialised attackers.

ETH security researcher Florian Tramèr sums it up:

“With Claude Mythos, a single hacker suddenly has far more attack options.”

Authorities such as the Federal Office for Information Security are also warning of “radical changes in how security vulnerabilities are handled”.

At the same time, there are voices seeking to put the hype into perspective. Some experts view Mythos less as an immediate threat and more as a logical further development of existing technologies – and thus also as an opportunity for better defence mechanisms. Even the mere integration of existing LLMs would already represent enormous progress.

Read the LinkedIn post on ‘Project Glasswing’

"The crucial question is not whether such models will be used, but how and under what conditions."

Dr.-Ing. Dietmar Rosenthal
Software security expert @TÜVIT

Between hype and reality

From the perspective of an independent audit body, it can be stated that
the Claude myth is neither a pure ‘cyber-apocalypse’ nor merely a marketing tool, but rather a catalyst for existing trends.

The crucial question is not whether such models are used, but how and under what conditions. Of particular importance to code developers are:

  • Data sovereignty and intellectual property protection
  • Controlled operating environments (on-premises)
  • Regulatory integration in Europe

Security researchers and testing laboratories are also a key pillar of digital sovereignty in Europe and must protect their specialist capabilities in order to ensure the security of critical infrastructure. If this expert knowledge were to find its way to attackers around the world via the Anthropic Mythos, that would be a problem in itself. If, in the long term, this expert knowledge were to actually decline in Europe, we would face a much greater problem. Europe must therefore also forge its own path.


Trustworthy AI in software security testing

As a TÜV testing body for software security, we regard the use of AI in vulnerability analysis as a fundamentally sensible and necessary step. However, the framework is crucial: security must not come at the expense of confidentiality and sovereignty.

TÜVIT already uses AI-supported source code analysis, but under clearly defined conditions:

  • Local processing in Germany
  • ISO 27001-certified environment
  • No transfer of sensitive data to cloud infrastructures outside Europe
  • Protection of source code as critical intellectual property

Particularly when compared with US-based models, it is clear that technological capability alone is not enough. Trust is built through controlled, auditable and data protection-compliant implementation. TÜVIT relies on isolated AI laboratories, fully local AI pipelines capable of replacing public AI models whilst maintaining full control, and the targeted further development of tests that integrate and build upon expert knowledge and technological trends.

Conclusion: The ‘Claude myth’ marks a turning point in cyber security. However, the future does not belong to the most powerful models, but to the most secure and trustworthy overall concepts.

Our Position at a Glance

Artificial intelligence now enables a dramatic acceleration in the analysis of software vulnerabilities, on both the attacker’s and the defender’s sides. AI-based models can automatically identify security-related flaws on a large scale.

The consequences are as follows:

  • Cybercriminals are able to carry out attacks on a whole new scale.
  • Organisations no longer have a choice but to identify and rectify vulnerabilities proactively.
  • Reactive security approaches are no longer sufficient.

The use of powerful, AI-powered security tools must not be at the expense of …

  • data sovereignty,
  • the protection of intellectual property,
  • the confidentiality of sensitive source code, and
  • technological and geopolitical sovereignty

.

Particularly in the case of critical infrastructure, industrial IP and security-related software, dependence on non-European cloud and analytics platforms such as Claude Mythos poses a strategic risk.

TÜVIT, as Germany’s largest safety testing laboratory, already carries out …

  • AI-supported source code, binary and protocol analyses
  • in an ISO 27001-certified,
  • intra-European and sovereign testing infrastructure.

This provides a high-performance, trustworthy alternative to foreign providers.

The EU Cyber Resilience Act as a strategic lever

The CRA requires companies to place software free of vulnerabilities on the EU market.
Binding, preventive testing of security-critical software components is particularly necessary for security-relevant systems and critical infrastructure (e.g. energy, healthcare, transport, space, etc.).

Sie haben Fragen?

Unser Experte ist für Sie da.

Dr. Dietmar Rosenthal