AI’s True Cyber Risk: Fable, Mythos, China, and The Rest — With Alex Stamos

The discussion critiques the U.S. government’s abrupt intervention to remove Anthropic’s AI models Fable and Mythos over security concerns, arguing that restricting bug-finding AI hampers cybersecurity by limiting defenders’ capabilities and ceding advantage to foreign, particularly Chinese, AI developments. Experts call for a balanced regulatory approach that preserves essential bug discovery functions while controlling offensive exploit creation to maintain U.S. technological leadership and security.

The discussion centers around the recent government intervention that forced Anthropic to take down its AI models, Fable and Mythos. This action was triggered after Amazon, which hosts Anthropic’s models on its AWS infrastructure, conducted security testing and raised concerns about Fable’s protections. Despite Anthropic’s willingness to address these issues collaboratively, the White House ordered the models to be pulled down and designated as export-controlled, restricting access by foreign nationals, including those who helped build the models. This move has sparked debate about the rationale and legality of such government actions.

A key point of contention is the actual capability and threat posed by Mythos, which is touted as a highly advanced bug-finding AI model. While Mythos is indeed powerful and likely the best bug-finding model publicly known, experts argue that it is not a revolutionary leap beyond other models like Opus 48 or GPT 5.5, which also excel at vulnerability discovery and exploit development. The real breakthrough occurred last year when AI models began outperforming human bug finders, making bug discovery more scalable and accessible. Fable, on the other hand, is a version of Mythos with built-in protections to prevent it from performing offensive tasks, which has been a point of contention with Amazon.

The conversation highlights the broader implications of restricting AI models capable of finding bugs. Bug discovery is essential for writing secure code and defending against cyber threats. Limiting American AI models’ ability to find vulnerabilities could backfire by making them less secure and forcing defenders to rely on foreign models, including those from China. The panelists emphasize that while offensive capabilities like exploit creation should be carefully controlled, bug finding must remain a core function of AI to improve cybersecurity. The current regulatory approach risks undermining the U.S. AI industry’s competitiveness and security posture.

Another significant concern raised is the geopolitical context, particularly the competition with Chinese AI capabilities. Chinese labs have released powerful open-weight models like GLM 5.2, which are nearly on par with top U.S. models and freely available for use and modification. Unlike U.S. labs, Chinese entities are unlikely to publicize their most advanced models, potentially giving them a strategic advantage. The U.S. must balance security concerns with the need to accelerate AI development and deployment to maintain technological leadership and defend critical infrastructure effectively.

Finally, the panelists warn about the political and operational risks introduced by the abrupt government actions against Anthropic’s models. The sudden takedown of Fable created instability and uncertainty for companies relying on these AI tools, prompting many to seek alternative solutions, including open-source models hosted domestically but developed abroad. This situation undermines trust in U.S.-based AI providers and could have long-term negative effects on the industry. The experts call for a more nuanced approach that distinguishes between bug finding and offensive exploit creation, ensuring defenders have the tools they need while managing risks responsibly.