TLDRocket
Sign in

Rubrik’s lessons from one month with Mythos Preview

The New Stack Meredith Shubel

Rubrik tried Anthropic’s Mythos Preview and found AI was spotting more bugs than its team could handle. The surprise: the bottleneck became humans, not the model.

Based on reporting by The New Stack, Meredith Shubel — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Rubrik’s month with Mythos Preview turned into a stress test for its own security workflow. The model was finding vulnerability chains that Rubrik says its usual tools, and even individual engineers, missed in large codebases. That created a problem the company hadn’t planned for: too many findings, too little human capacity to sort them fast enough.

Arvind Nithrakashyap, Rubrik’s CTO and co-founder, says the first instinct was to treat the flood of issues like a staffing gap. The company even considered hiring more reviewers. Then that idea fell apart. Human-led remediation, he says, simply couldn’t keep pace with AI-speed discovery.

Rubrik joined Project Glasswing in June, when Anthropic expanded the program to roughly 150 organizations across 15 countries. Access to Mythos Preview is limited to vetted partners, and Rubrik responded by assembling a mixed engineering and infosec team around the model. The goal was not to throw more people at the problem, but to build a harness that could manage tool calls, checkpoints, and the surrounding business and security context.

The company’s approach now starts with a whole-repository scan, then uses those results to drive more targeted passes. Those later sweeps are meant to cut the noise and leave only high-quality findings for the right teams. Only after that did Rubrik say its engineers had a workflow that could turn Mythos output into remediation work they could actually absorb.

The bigger lesson was about limits, not just speed. Rubrik chose to automate remediation only for a narrow set of vulnerability classes where machine fixes are reliable and well defined. Everything else still goes to humans. Nithrakashyap’s takeaway is blunt: AI doesn’t reduce the need for engineering rigor. It raises it.

My take — AI-written commentary, not fact-checked reporting

This is the part of AI security everyone keeps bumping into and pretending is new: the model is not the bottleneck, the cleanup is. Rubrik did the sensible thing and refused to turn “maximum automation” into a religion, which is rare enough to count as leadership. The future belongs to teams that can filter, route, and verify fast — not to the ones that brag about letting the machine loose and hope the pager stays quiet.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.