Comment
With the launch of ‘Claude Mythos’ in the spring of 2026, the US company Anthropic has introduced a new standard of AI models into the debate. Unlike traditional large language models, Mythos is specifically designed with cyber security in mind. However, security must not come at the expense of confidentiality and sovereignty.

The system can analyse software independently, identify previously unknown vulnerabilities (‘zero-day vulnerabilities’) and, in some cases, even exploit them. According to recent reports, the model has already discovered “thousands of highly critical security vulnerabilities” in operating systems and browsers – some of which are found in code that has been in use for decades. At the same time, access is to remain strictly limited: as part of ‘Project Glasswing’, only selected organisations will be granted access, as the potential for misuse is considered to be significant.
A paradigm shift in security – is a ‘tsunami’ of vulnerabilities on the horizon?
From an audit body’s perspective, one thing is clear: the technological possibilities are impressive. AI models such as Mythos drastically speed up vulnerability analyses – tasks that take human experts weeks can be automated and completed in a matter of hours.
This gives rise to a potential paradigm shift:
Some experts are already referring to a ‘turning point for cyber security’, as AI is, for the first time, capable of systematically and comprehensively uncovering security vulnerabilities. However, given the extensive integration and possibilities, some experts fear a tsunami of ‘zero-day’ vulnerabilities this time – not just a simple wave.
When defence becomes a weapon
Yet this is precisely the crux of the ‘Myth’ narrative – the same capabilities can also be used offensively. According to experts, the model is capable not only of finding vulnerabilities, but also of chaining them together and exploiting them. This is a scenario that, until now, was only possible for highly specialised attackers.
ETH security researcher Florian Tramèr sums it up:
“With Claude Mythos, a single hacker suddenly has far more attack options.”
Authorities such as the Federal Office for Information Security are also warning of “radical changes in how security vulnerabilities are handled”.
At the same time, there are voices seeking to put the hype into perspective. Some experts view Mythos less as an immediate threat and more as a logical further development of existing technologies – and thus also as an opportunity for better defence mechanisms. Even the mere integration of existing LLMs would already represent enormous progress.
Dr.-Ing. Dietmar Rosenthal
Software security expert @TÜVIT
Between hype and reality
From the perspective of an independent audit body, it can be stated that
the Claude myth is neither a pure ‘cyber-apocalypse’ nor merely a marketing tool, but rather a catalyst for existing trends.
The crucial question is not whether such models are used, but how and under what conditions. Of particular importance to code developers are:
Security researchers and testing laboratories are also a key pillar of digital sovereignty in Europe and must protect their specialist capabilities in order to ensure the security of critical infrastructure. If this expert knowledge were to find its way to attackers around the world via the Anthropic Mythos, that would be a problem in itself. If, in the long term, this expert knowledge were to actually decline in Europe, we would face a much greater problem. Europe must therefore also forge its own path.
Trustworthy AI in software security testing
As a TÜV testing body for software security, we regard the use of AI in vulnerability analysis as a fundamentally sensible and necessary step. However, the framework is crucial: security must not come at the expense of confidentiality and sovereignty.
TÜVIT already uses AI-supported source code analysis, but under clearly defined conditions:
Particularly when compared with US-based models, it is clear that technological capability alone is not enough. Trust is built through controlled, auditable and data protection-compliant implementation. TÜVIT relies on isolated AI laboratories, fully local AI pipelines capable of replacing public AI models whilst maintaining full control, and the targeted further development of tests that integrate and build upon expert knowledge and technological trends.
Conclusion: The ‘Claude myth’ marks a turning point in cyber security. However, the future does not belong to the most powerful models, but to the most secure and trustworthy overall concepts.
Artificial intelligence now enables a dramatic acceleration in the analysis of software vulnerabilities, on both the attacker’s and the defender’s sides. AI-based models can automatically identify security-related flaws on a large scale.
The consequences are as follows:
The use of powerful, AI-powered security tools must not be at the expense of …
.
Particularly in the case of critical infrastructure, industrial IP and security-related software, dependence on non-European cloud and analytics platforms such as Claude Mythos poses a strategic risk.
TÜVIT, as Germany’s largest safety testing laboratory, already carries out …
This provides a high-performance, trustworthy alternative to foreign providers.
The EU Cyber Resilience Act as a strategic lever
The CRA requires companies to place software free of vulnerabilities on the EU market.
Binding, preventive testing of security-critical software components is particularly necessary for security-relevant systems and critical infrastructure (e.g. energy, healthcare, transport, space, etc.).