
Anthropic’s Mythos AI model is finding cybersecurity vulnerabilities faster than anyone can patch them, and organisations are being forced to rethink how quickly they can respond, attendees heard at a TEISS dinner briefing at the House of Lords, hosted by Tanium. A group of senior security leaders from a range of sectors discussed what advanced AI models mean for everything from patch cycles to recovery planning.
The challenge of security has changed in recent months, said Dan Jones, Senior Security Advisor at Tanium, but the root cause is still people: those who need to be convinced to change what they are doing, or those who for some reason are resisting change. Everyone is concerned about Mythos, he said, yet it is exacerbating existing problems, not creating new ones.
Patching, for example, had already moved from quarterly to monthly, said Mr Jones, and the goal has shifted to fortnightly. Even that is not enough. The open-source community cannot patch vulnerabilities Mythos is identifying fast enough: on average a patch takes 47 days to become available, when fixes need to arrive in minutes. And the model carries geopolitical risk too, with Anthropic recently being forced to pull Mythos under US export control rules – it’s since returned.
The challenge for organisations, he said, is to act fast enough to match the threat.
The race to patch at machine speed
One attendee said their organisation was moving to fortnightly patches and preparing for a new norm of daily updates, automating what it could with a human in the loop and, above that, gold-tier services kept under human control. Another put it simply: automate what you can and do everything else with people. Perhaps it is better to patch as quickly as possible and fix anything that breaks, one suggested, though that takes confidence in your processes. One attendee had stepped out of the race altogether, outsourcing patching to managed services, due to lack of in-house capacity as experts began to retire.
Preparation matters as much as speed: the military drill and test everything constantly, one attendee observed, and security teams should treat disaster recovery and incident response plans the same way. Almost every tabletop exercise finds gaps in the plan.
Progress is uneven, though. One attendee had tried Microsoft’s Security Copilot but found it needs a solid starting point to be effective. Another was automating vulnerability detection while noting that finding flaws is half the job; somebody still must fix them. Organisations have no choice about speeding up their defences, an attendee argued, so they will figure it out. It will be tough in the short term. After that, we’ll cope.
Longer term, some attendees want to be less reactive. They discussed ’autonomous IT’: automating as much of the estate as possible, starting with the easiest tasks. Developers have more tooling to prevent mistakes, so fewer vulnerabilities should enter code in the first place. Organisations are training developers to understand how flaws creep in, through open-source components for example, and exploring agents to help eliminate errors.
Governance, guardrails and the cost question
Pressure is coming from every direction. Boards are seeing AI security task forces elsewhere and expect their organisations to have one. coverage prompts questions to the IT department: what does this risk mean for us? A crisis often makes the argument for budgets to be increased or diverted, one attendee noted, and something like Mythos, arriving with global ramifications, is an opportunity to make the case for better preparation.
Internal governance is hardening in response. Attendees described AI review boards that must approve any use of AI, training requirements backed by an AI champion in every team, and vibe-coding sandboxes sealed off from company data. Guardrails for agents were a common concern, including agent-to-agent controls such as tool scanning, which checks what AI models are doing and whether they have permission. Cost remains a blind spot. Even developers, one attendee said, don’t always realise that running a single prompt can cost £14.
Resilience over prevention
Mythos has sharpened questions of dependence as well. Are organisations in a different position with AI suppliers than with cloud providers? In the Netherlands, there is widespread concern about a US ’kill switch’ on IT systems, and conversations about de-risking dependencies on the US, in payments for example. In practice, though, unless there is a better option you must use what is available.
That logic points towards resilience. Attacks will happen, so budgets are moving into recovery planning. Automation should always be able to roll back to a human, attendees agreed, and organisations must be able to explain to an auditor or a regulator what an AI agent was doing. When systems go down, people don’t always know how the manual process works. One practical suggestion from Jones was PACE planning: work through your systems and check each one has a Primary, Alternative, Contingency and Emergency option.
Closing the discussion, Mr Jones observed that some of the group were working on autonomous IT but none had arrived yet. What you were doing yesterday won’t be enough tomorrow, he said. How much you change is up to you and depends on your needs. But autonomous IT can start with a single, simple target that shows what else is possible: automating one task frees people to work on others.
To learn more, please visit: www.tanium.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543