Companies Have 6 Months to Prepare for Automated Attacks Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon. With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses. On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic's Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model's capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target. In their evaluation, Mythos scored an 80, while the next-closest contender, SpaceXAI's Grok-4.5, scored a 49. However, the current standings are not as important as where we will be in six months, says Brad Medairy, president of Booz Allen's National Cyber practice. "Our view is there's going to be some level of parity, at least between the frontier models and the Chinese models over probably a six-month horizon, and so everyone is in a rapid race to evolve these capabilities," he says, adding that, when facing human attackers, defenders had the advantage, but "in the future, the balance of power shifts to the offense, because the attacker can deliver effects at speed and scale that the traditional defenses can't keep pace with." Booz Allen's findings mirror those of other efforts to benchmark the cyberattack capabilities of frontier models. In June, the AI Security Institute — a research arm of the UK government's Department for Science, Innovation, and
Companies Have 6 Months to Prepare for Automated Attacks
Read the original article
darkreading.com →