AI arms race hits fever pitch: anthropic’s mythos blurs the line between cyber offense and defense at RSAC 2026

20VC with Harry Stebbings

The gist

At RSAC 2026, Anthropic’s Mythos AI ignited a cyber arms race by blurring the line between offense and defense—forcing the entire industry to rethink how it manages privileged, autonomous AI agents.

What to know

  • Anthropic’s Mythos AI demonstrated the power to automate both complex cyber attacks and defenses across the full kill chain, supercharging both sides of the battlefield.
  • Rapidly proliferating AI agents with privileged access have outpaced existing governance, with Rubrik and Palo Alto Networks sounding alarms over an 82:1 machine-to-human identity ratio.
  • Mythos AI now discovers and exploits decades-old vulnerabilities faster than human experts, compressing the timeline between discovery and exploitation and forcing security teams to patch at breakneck speed.

AI Blurs Battle Lines

Agentic AI like Anthropic’s Mythos is dismantling the traditional divide between attacker and defender, forcing security teams and adversaries alike to rethink their tactics in an era where automation accelerates both offense and defense.

At RSAC 2026, the cybersecurity landscape revealed a profound convergence of AI-driven offensive and defensive capabilities, with agentic AI like Anthropic’s Mythos empowering actors across the entire cyber kill chain—from reconnaissance to effect. Experts such as Ben Buchanan emphasize Mythos’s dual-use potential to enhance both attack sophistication and defense strategies, while Michael Sulmeyer highlights tools like Glasswing as essential for defenders to maintain parity in this escalating arms race. This convergence marks a critical inflection point where AI is not just augmenting but fundamentally reshaping how cyber operations are conducted on both sides.

Agentic AI is revolutionizing security operations centers by automating workflows that once relied heavily on manual triage, thereby elevating analysts to strategic roles focused on threat detection and response. This shift, showcased by companies like HackerOne at RSAC 2026, positions AI agents as frontline defenders capable of closing the gap between detection and automated remediation. As HackerOne CEO Kara Sprague asserts, these adaptive AI-driven defense systems represent the future of cybersecurity, transforming not only threat response but also software development with unprecedented speed and scale.

The rapid proliferation of agentic AI is intensifying the cyber arms race by drastically lowering the cost and increasing the scale of attacks, forcing defenders to abandon reactive postures in favor of continuous, risk-focused strategies. Kara Sprague and Michael Sulmeyer both stress the urgency for CISOs to prioritize fast risk reduction amid expanding attack surfaces fueled by AI-powered autonomous agents. This dynamic compels security teams to integrate real-time threat detection and ecosystem-wide coordination to keep pace with increasingly persistent and adaptive adversaries empowered by AI automation.

AI-driven automation is not only enabling cyber attackers to execute complex persistence and evasion tactics at scale—tasks historically difficult for humans—but also driving defenders to innovate rapidly. Drawing parallels to early automated attacks like Stuxnet and WannaCry, experts like Michael Sulmeyer note that agentic AI enhances attackers' ability to blend in and adapt on the fly, compelling defenders to deploy equally sophisticated AI tools. This technological arms race underscores the necessity of leveraging advanced autonomous agents to sustain effective defense in an environment where AI powers both offense and defense simultaneously.

Sources
CyberWire DailyNew York Stock ExchangeCyberWire DailyChinaTalkNew York Stock Exchange

Governing a Machine Majority

The explosion of autonomous AI agents with privileged access is overwhelming legacy security controls, driving a fundamental shift toward automated, real-time governance to prevent catastrophic misuse and maintain trust in digital infrastructure.

As autonomous AI agents increasingly operate with privileged, task-specific access, treating them as first-class identities within governance frameworks has become essential. Experts emphasize assigning ephemeral, fine-grained credentials limited to each agent’s immediate task to minimize risk, while real-time anomaly detection is critical to promptly identify deviations or malicious behavior, as highlighted in the 2026 Explainer on Enhanced Agent Identity Controls. This approach helps contain the unpredictable nature of agentic systems and ensures continuous operational oversight.

The rapid proliferation of autonomous AI agents with broad system privileges—capable of rewriting firewall rules and modifying IAM policies—has outpaced current governance and security controls, creating a widening attack surface. Palo Alto Networks reports an 82:1 machine-to-human identity ratio in enterprises, underscoring the complexity of managing sprawling AI-driven access. The OWASP Top 10 for Agentic Applications further identifies critical risks like Agent Goal Hijacking and Privilege Abuse, demanding enhanced identity management and robust operational oversight to prevent catastrophic misuse.

Industry leaders at RSAC 2026, including Rubrik’s Arvind Nithrakashyap, stress that securing autonomous AI at scale requires a fundamental mindset shift toward balanced guardrails that enable innovation without sacrificing control. Rubrik’s breakthroughs like the Sage governance engine and Agent Cloud platform automate policy enforcement and real-time monitoring, addressing the escalating crisis of AI agent control. This automated governance and observability are revolutionizing AI systems engineering by enabling safe scaling of agents operating at superhuman speeds.

Effective governance of autonomous AI agents demands a paradigm shift from model optimization to architecting the operational environment, focusing on validation infrastructure, structured orchestration, and durable institutional knowledge embedded within agents. By enforcing explicit permission limits on every external connection and maintaining auditable, predictable workflows, organizations can mitigate risks of unauthorized access and operational drift. This harness engineering approach transforms validation layers into compounding assets that reduce expert human review time and ensure consistent, compliant agent behavior across production deployments.

Sources
Venture BeatGradient FlowN2K NetworksIBM Technology

Vulnerability Discovery at Warp Speed

Mythos AI’s ability to autonomously unearth and exploit decades-old flaws is fueling urgent debates over AI governance and compressing the window for defenders, as organizations scramble to keep pace with threats that now move faster than human response.

Anthropic’s Mythos AI has revolutionized vulnerability discovery by autonomously uncovering and exploiting decades-old software flaws at speeds surpassing top human experts and previous AI models. This unprecedented capability accelerates zero-day and open-source vulnerability detection, revealing thousands of security gaps faster than companies can patch, thereby intensifying a cybersecurity arms race that reshapes market dynamics and risk narratives amid soaring compute costs and strategic AI investments.

The rapid and autonomous nature of Mythos AI’s vulnerability research has sparked urgent debates on AI governance, national security, and critical infrastructure protection. As government bodies including the US Treasury and Commerce engage with Anthropic for early access, experts warn of widening cybersecurity chasms driven by AI-driven reverse engineering outpacing patch cycles, exposing critical gaps in AI model safety, security auditing, and the need to rethink traditional detection methods in favor of behavior-based response strategies.

Mythos AI’s rapid breakthroughs have intensified tensions between security innovation, capitalist interests, and ethical dilemmas around AI model withholding and controlled access. While competition from rivals like OpenAI’s GPT 5.4 Cyber offers multiple defensive tools for security professionals, the compressed timeline between vulnerability discovery and exploitation—highlighted by CrowdStrike CEO George Kurtz’s observation that 'AI is compressing the time between intent and execution'—forces organizations to accelerate patching and compliance enforcement amid evolving workforce dynamics and governance crises.

Sources
Venture BeatThe PrimeTimeChinaTalkChinaTalkCybersecurity HeadlinesThe Skeptic AI Enthusiast

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.