The UK AI Security Institute has determined that OpenAI's GPT-5.5 is the second AI model capable of autonomously solving full network attack simulations, with performance nearly matching Anthropic's Claude Mythos, which was the first to demonstrate such capabilities. While Anthropic has restricted Claude Mythos to a small group, OpenAI is shipping GPT-5.5 through ChatGPT and making it available through its API, representing a significantly broader deployment approach. The standardized testing by the UK AI Security Institute reveals that both models possess advanced offensive cybersecurity capabilities that can complete complex network penetration scenarios without human intervention. This development marks a significant milestone in AI capabilities while raising questions about the security implications of widely deploying models with autonomous cyber attack abilities.
GPT-5.5 and Claude Mythos Autonomous Cyber Attack Capabilities
- ▪Anthropic's Claude Mythos is capable of autonomously solving a full network attack simulation
- ▪OpenAI's GPT-5.5 performance in autonomous network attack simulations is nearly on par with Anthropic's Claude Mythos
UK AI Security Institute Testing and Findings
- ▪The UK AI Security Institute found that OpenAI's GPT-5.5 is capable of autonomously solving a full network attack simulation
- ▪The UK AI Security Institute found that OpenAI's GPT-5.5 performance is nearly on par with Anthropic's Claude Mythos in autonomous cyber attack capabilities
Model Availability and Access Differences
- ▪OpenAI's GPT-5.5 is available through the API
- ▪Anthropic's Claude Mythos is only available to a small group
- ▪OpenAI's GPT-5.5 is shipping in ChatGPT
Perspective of AI safety researchers
- ▪The autonomous cyber attack capabilities demonstrated by GPT-5.5 and Claude Mythos represent a significant escalation in AI-enabled security threats
- ▪OpenAI's decision to ship GPT-5.5 through ChatGPT and API despite its autonomous cyber attack capabilities raises concerns about responsible deployment practices
- ▪The UK AI Security Institute's testing reveals that advanced AI models now possess offensive capabilities that could be exploited by malicious actors
Perspective of Anthropic
- ▪Claude Mythos was the first AI model to demonstrate autonomous full network attack simulation capabilities before GPT-5.5
- ▪Anthropic's decision to limit Claude Mythos availability to a small group reflects a more cautious approach to deploying AI models with offensive cybersecurity capabilities
Perspective of Cybersecurity professionals
- ▪AI models like GPT-5.5 and Claude Mythos could be used by cybersecurity professionals to identify and patch network vulnerabilities more efficiently
- ▪The widespread availability of GPT-5.5 through ChatGPT and API could lower the barrier to entry for conducting sophisticated cyber attacks
Story comments
Loading comments…