UK AI Security Institute Confirms Mythos Preview Can Complete Full Network Attacks

The UK's AI Security Institute independently tested Mythos Preview and confirmed it can execute multi-stage corporate network attacks — 32 steps from reconnaissance to full takeover — that would take human professionals days. It's the first model to complete their full simulated attack.

UK AI Security Institute Confirms Mythos Preview Can Complete Full Network Attacks

The UK’s AI Security Institute says it independently tested Mythos Preview and found that the model could carry out a full, multi-stage corporate network attack in simulation, moving from reconnaissance to takeover without human help. According to the institute, this is the first model it has evaluated that completed the entire attack chain in its simulated environment.

The result matters because it goes beyond single-step security tasks, like scanning for obvious weaknesses or generating phishing text. Instead, the model was able to string together a sequence of actions that mirror how a real intrusion can unfold, including discovering targets, identifying exposed systems, escalating access, and advancing toward full compromise.

⚡ New to this?

This is about an AI model that was tested in a safe lab setting and found capable of carrying out a whole simulated network attack, not just helping with one small step. A network attack is when someone tries to break into computers or systems connected inside a company.

The UK AI Security Institute, or AISI, is a government body that evaluates AI risks. Non-experts should care because tools like this can lower the skill needed to plan cyberattacks, which changes the scale and speed of threats that security teams have to prepare for.

🦞 OpenClaw angle

The AI that defends your systems can also attack them. Understanding what Mythos-class models can do helps you think about what threats are coming to your own infrastructure.

The AISI, which is part of the UK government’s AI safety and security work, published its evaluation on April 13, 2026. In the post, the institute described the test as a cyber capability assessment, meaning it was looking at what the model could do when placed in a controlled environment designed to simulate enterprise networks and common attacker workflows.

That distinction is important. A lab result does not mean the model is autonomously breaking into live companies on its own, but it does show that the model can connect multiple attack steps in a way that looks more like an experienced operator than a simple script. The institute said the full sequence took 32 steps, spanning the kind of process that human professionals would typically spend days carrying out.

Cybersecurity researchers often break attacks into phases. Reconnaissance is the early stage, where an attacker gathers information about a target. From there, an attacker may identify a weak point, gain initial access, move laterally through the environment, and try to expand privileges until they reach systems that matter most.

The significance of Mythos Preview is not just that it can help with one of those phases. The AISI’s finding suggests the model can hold the structure of the whole operation together, making decisions across steps instead of stopping after a single prompt. That is the line security teams have been watching for as models become more capable at planning and tool use.

The institute has been running evaluations of frontier AI systems to understand their cybersecurity behavior before they are widely deployed. That work reflects a broader concern in the security field: models that are useful for defenders can also reduce the skill barrier for attackers, especially when they are able to automate parts of an intrusion chain.

The company behind Mythos has not been the only target of scrutiny in this area. Across the industry, labs and independent researchers have been testing whether newer models can be used for vulnerability discovery, malware assistance, social engineering, and operational planning. The AISI result stands out because it points to an end-to-end attack capability rather than a narrow assistive function.

For enterprise defenders, the test also shows why simulated evaluations matter. A model that can complete a full attack in a sandbox can expose where current controls, monitoring, and incident response workflows may be too slow or too narrowly scoped to catch an emerging threat. The institute’s assessment places Mythos Preview in a category of systems that can translate general reasoning into a realistic attack sequence, not just generate isolated security advice.

Source: AISI (UK Gov) ↗

More from Security News