TLDRocket
Sign in

Claude Mythos and misguided open-weight fearmongering

Interconnects Nathan Lambert

Claude Mythos dropped with scary-good cybersecurity chops, and people are already panicking about open-weight clones. The writer says that panic is old news repeating itself and could backfire on real security work.

Based on reporting by Interconnects, Nathan Lambert — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Anthropic's new Claude Mythos model landed this week with cybersecurity abilities strong enough that a familiar chorus started up almost immediately: open-weight versions of this thing will be catastrophic, our digital infrastructure can't handle it, ban the open stuff before it's too late. Interconnects pushes back hard on that framing, and not because the underlying capability is fake. It's because the argument collapses a pile of unknowns into a tidy policy conclusion that might actually leave us less prepared, not more.

This isn't the first rodeo. OpenAI held back GPT-2 weights in 2019 over doom predictions that never fully materialized, and GPT-4's 2023 release triggered similar bio-risk hysteria that mostly fizzled. The mistake, as the piece lays out, is treating the open-closed capability gap as frozen in place and then linking general open-weight viability to one narrow, scary use case. The writer has argued elsewhere that top open models will keep trailing frontier closed ones — and that's fine, even healthy. A 6-to-18-month lag between a closed lab shipping a capability and an open reproduction showing up gives the world time to monitor and adapt without killing the open ecosystem outright.

Where this case differs from GPT-4-era panic is that cybersecurity risk feels less hypothetical than bio-risk ever did. Fair enough. But the actual threat depends on things nobody outside Anthropic currently knows: how big Mythos really is, what tools and harness surround it, and how much compute it takes to run. Interconnects ballparks it at maybe 2x the parameters of Opus with a much less efficient serving setup — something in GPT-4.5 territory, but actually trained well this time. Serving an 8-trillion-parameter MoE model plausibly needs on the order of 100 H100s, roughly $10,000 a day. That is not laptop-and-a-dream territory. Very few actors can afford to run something like that at scale, even if weights eventually leaked or got open-sourced.

The coding angle matters too. Cybersecurity skill likely rides heavily on coding ability, and coding is one domain where open models can train on mountains of public GitHub data and stay closer to frontier performance than in messier fields like law or medicine. That's actually a reason for cautious optimism about narrow-domain competitiveness, not blind panic. The piece also flips the usual argument: if defenders get access to open models near Mythos's level, they could fine-tune them to harden their own systems, rather than only attackers benefiting.

The bigger point is about who gets to decide. Relying entirely on one private company to gatekeep the security assessment of critical global infrastructure isn't a stable arrangement either. The author isn't saying cybersecurity concerns are fake — deepfakes already crossed a similar red line in image models, so it's not like these worries are baseless. But blanket bans on open weights don't erase the technology, they just hand influence over it to whichever country keeps building it anyway.

My take — AI-written commentary, not fact-checked reporting

I'm allergic to any AI-safety argument that conveniently ends in 'so stop open models,' because that's the outcome incumbents wanted before the argument even started. This piece gets it right: the actual policy move should be narrow measurement of cybersecurity capability gaps, not a blanket freakout every time a closed lab ships something scary and calls dibs on deciding what's safe for the rest of us. Ceding all judgment about critical infrastructure security to a single company with obvious commercial incentives is the real risk hiding behind the fear of open weights.

Read more about this at: Interconnects

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.