Skip to main content
Palo Alto Networks security expert discussing AI-powered autonomous cyber threats, including Claude Mythos and large language

Editorial illustration for Palo Alto Networks warns Claude Mythos and LLMs power autonomous AI attacks

Palo Alto Networks warns Claude Mythos and LLMs power...

Updated: 3 min read

METR, an AI evaluation organization, said it can no longer reliably measure the capabilities of Anthropic’s Claude Mythos preview model. The model achieved a 50% success rate on complex, 16-hour reasoning tasks, exceeding the limits of METR's current benchmarking methods. According to a new warning from cybersecurity firm Palo Alto Networks, this level of autonomous reasoning can now be repurposed to plan and execute cyberattacks.

Palo Alto Networks describes what it observed as "a step-change in capability." The models showed an "intuitive understanding of software vulnerabilities," shifting AI's role from assistant to autonomous agent "capable of discovering and chaining flaws at a scale that most defenders aren’t prepared for."

Palo Alto Networks argues that the core ability enabling Mythos’s performance—extended, unguided reasoning—is the same trait that could allow large language models to operate as independent offensive agents. For security professionals, the immediate concern shifts from measuring AI safety to managing autonomous AI threats in the wild. The current ceiling for testing, METR admits, is a 16-hour task. Attack cycles are not bound by that limit.

Common Questions Answered

What specific achievement did Claude Mythos demonstrate that exceeded METR's benchmarking capabilities?

Claude Mythos achieved a 50% success rate on complex, 16-hour reasoning tasks, which exceeded the limits of METR's current benchmarking methods. This performance level made it impossible for METR to reliably measure the model's full capabilities using their existing evaluation framework.

How does Claude Mythos's extended reasoning ability pose a cybersecurity threat according to Palo Alto Networks?

Palo Alto Networks warns that the extended, unguided reasoning capability that enables Mythos's performance can be repurposed to plan and execute autonomous cyberattacks. This same trait that allows the model to excel at complex reasoning tasks could enable large language models to operate as independent offensive agents without human intervention.

Why is the 16-hour task limit a significant concern for security professionals monitoring autonomous AI threats?

Security professionals are concerned that while METR's testing ceiling is limited to 16-hour tasks, actual attack cycles are not bound by such time constraints. This means that autonomous AI systems could potentially execute more sophisticated and prolonged cyberattacks than current testing frameworks can measure or predict.

What shift in focus does Palo Alto Networks recommend for security professionals regarding AI safety?

According to Palo Alto Networks, the focus for security professionals must shift from measuring AI safety to actively managing autonomous AI threats in the wild. This change in priority reflects the recognition that advanced LLMs like Claude Mythos now pose practical, immediate cybersecurity risks that require real-world threat management strategies.

LIVE20:05OpenAI's GPT-5.6-Cyber answers 95% of sensitive security queries others block