
The brief window of time that cybersecurity defenders thought they had to prepare for AI-powered attacks is closing faster than anyone expected. New research shows that OpenAI's GPT-5.5 has nearly caught up to Anthropic's top security model, Mythos Preview, in its ability to discover and exploit software vulnerabilities.
Tests released this week by the UK AI Safety Institute measured the models' performance on a simulated 32-step enterprise-grade cyberattack. GPT-5.5 succeeded in 2 out of 10 attempts; Mythos managed 3 out of 10. Before Mythos was released last month, no AI model had ever completed the test even once.
GPT-5.5 actually outperformed Mythos on a series of "capture the flag" security challenges, which test a model's ability to find vulnerabilities, reverse-engineer attacks, and exploit flaws in web applications.
When Anthropic launched Mythos, it estimated that other AI companies would need at least 6 to 18 months to produce a model with comparable offensive capabilities. That timeline is now being directly challenged. The finding forces a reassessment of how much time government agencies, critical infrastructure operators, and cybersecurity firms have left to shore up their defenses.
Neither model is available to the public in its full capacity. Anthropic has given access to only about 40 organizations, including 12 members of its information-sharing partnership Project Glasswing. OpenAI has imposed strict limits on the public version of its model, offering a restricted variant only through its "Trusted Access Program" to vetted cybersecurity professionals.
Access control is becoming a political issue. The White House pressed Anthropic last week not to expand Mythos's access further, citing national security concerns. Meanwhile, OpenAI is actively working to bring federal agencies, state and local governments, and international allies into its program, giving defenders access to "cybersecurity-cleared versions" of GPT-5.4 and 5.5. (OpenAI recently made GPT-5.5 Instant the default model in ChatGPT, and is also expanding its reach through partnerships like AWS Bedrock.)
The Trump administration is also considering establishing a security review mechanism for newly released AI models.