“That which destroys the old mythos becomes the new mythos.”

That’s a quote from the 1974 philosophical novel Zen and the Art of Motorcycle Maintenance by Robert M. Pirsig. It argues that it is essential to integrate human judgement and craftsmanship into technical systems to achieve sustainable, high-quality innovation.

There are a lot of things in that book that apply now in the AI era, arguably more so than when the book was written. What is for certain, though, is that AI is the new mythos.

In fact, in some areas (such as the identification of software vulnerabilities), Mythos is the new mythos, i.e., Claude Mythos by Anthropic.

You’ve probably seen the headlines about the ability of Mythos to find software vulnerabilities. But in the real world of operating IT infrastructure in a corporate environment, what happens next is where the real game begins, i.e., wave after wave of vendor fixes that need to be assessed, packaged, tested, and deployed.

As is often the case with AI, it can start something, but most of the work comes after.

So, for this blog, we are looking at Mythos from an application management and operational readiness perspective rather than a purely security conversation.

What is Claude Mythos?

Claude Mythos is Anthropic’s AI model that supercharges AI-assisted vulnerability discovery. It has been proven to find flaws everywhere, some of which have existed undetected for years.

Not only is Mythos finding vulnerabilities, but it is finding them faster and at a scale that dwarfs anything that has gone before it.

Two quick additional things to note before moving on. First, Mythos is likely to be the first. AI model development is moving at pace, so it’s feasible that other models, by Anthropic or other AI vendors, will be able to do the same or better in the near future.

The second point worth highlighting is that while Mythos is great at identifying unknown vulnerabilities, that’s where its capabilities stop. It doesn’t patch, package, test, or deploy anything.

Why Vulnerability Discovery Is Only the Start

Mythos finding a software vulnerability starts a response chain that is long and complex. For the software vendor, that response chain includes:

  • Validating the vulnerability and quantifying the impact.
  • Coordinating the disclosure without increasing security risks for users.
  • Building the fix.
  • Regression testing the fix.
  • Shipping the patched version.

That takes time, and that time will vary from vendor to vendor.

Plus, they are not one-time events. Uneven and unpredictable waves of updates will roll into corporate IT environments as vendors respond to what Mythos finds.

And we are not just talking about a single type of software, either. It applies to everything, from operating systems and browsers to frameworks and middleware to endpoint agents, developer tools, and everyday business applications.

This is where the pressure point becomes acute. Normal practice is to prioritise security updates ahead of feature updates. That’s okay when security updates are the exception. By increasing the volume of security updates, which Mythos is likely to do, bottlenecks will become inevitable.

The Real Pressure Point is Deployment, Not Detection

In the real world, finding software vulnerabilities doesn’t reduce risk on its own. Instead, it is one piece of a much bigger puzzle. The risk to enterprises only decreases once the fix is assessed, packaged, tested, and deployed.

Mythos can be fast at detecting the vulnerability.

The vendor can be fast (or relatively fast) at releasing a patch.

The next part is the challenge, where packaging, testing, and deployment capacity in corporate environments is typically fixed. The answer is usually not more people to increase capacity. It’s automation.

What Is Good Application Management in the New Mythos

  • Full app estate visibility – you need to know where you stand.
  • Clear ownership – update decisions should be accountable.
  • Automation – to reduce manual effort so the skilled resources on your team can focus on the genuine exceptions that need their expertise.

The New Mythos Is Only as Good as What Comes Next

Claude Mythos has rewritten the rules for identifying software vulnerabilities. However, it doesn’t replace the judgement and craftsmanship needed to safely turn a fix into a deployed update.

Enterprise risk only goes down when the update is assessed, tested, and deployed. That requires process (both automated and manual) and people.