Frontier artificial intelligence (AI) models, such as Anthropic’s Mythos model family, have drawn attention for their reported ability to find software vulnerabilities, develop exploits, and complete multistep tasks with limited human direction. While the precise extent of those capabilities may be difficult to determine, the direction is apparent: advanced AI can reduce the time and technical skill required to identify and exploit weaknesses. National and international bodies now describe this openly. The European Commission has noted that advanced AI can be misused to identify vulnerabilities, automate attacks, and increase the scale and speed of cyber incidents.1 The National Institute of Standards and Technology (NIST) makes a similar point, framing AI-enabled cyberthreats as a core concern for enterprise risk management.2 The operating conditions for cybersecurity are changing rapidly, placing more pressure on organizations to apply a defense-in-depth strategy. As businesses integrate AI tools into software development, customer service, financial processes, and internal operations, the stakes are high. Some systems retrieve sensitive information, connect to critical business systems, and act through an employee’s or AI agent’s permissions. Organizations also may become dependent on AI models whose availability is controlled by an outside provider or affected by government action.3 Business leaders now face two corresponding questions regarding external and internal risks: - How will AI change threats directed at the organization? - What new exposure will the organization create by embedding AI inside its own operations? Vulnerability Discovery Is Getting Faster AI technology didn’t invent software vulnerabilities or zero-day attacks. Researchers and threat actors have long looked for weaknesses in operating systems, browsers, applications, and infrastructure. What frontier models can escalate is the speed and scale of that work. The European Commission observes that frontier capabilities, once concentrated in a few systems, are becoming more accessible as open-source models improve, including to criminal