On this page
The short version
- 01OpenAI and Anthropic both say their newest models are highly capable at cyber security work, including finding software weaknesses.
- 02Both restricted the most capable access: Claude Mythos 5.1 and early access to GPT-6 Astra went to vetted security programmes first.
- 03For a small business, the response is the basics done faster — patching, MFA, backups and knowing what’s exposed to the internet.
Two of September’s biggest AI launches came with an unusual warning attached. OpenAI said GPT-6 Astra’s ability to identify and develop exploits for previously unknown vulnerabilities could help defenders, and gave early access to organisations in its cyber security programme. Anthropic released Claude Mythos 5.1 — the same model as Claude Fable 5.1, with different safeguards — only through a verification programme for defensive security professionals.
Headlines about ‘AI that can hack’ are easy to write. Here’s what it actually changes for an ordinary business.
Why the companies are restricting access#
The ability to find weaknesses in software is useful to both sides. Defenders use it to discover and fix problems before they’re exploited; attackers would use it to find a way in. Gating the most capable versions behind vetted programmes is how the AI companies are trying to get that capability to defenders first.
OpenAI put it plainly: Astra’s ability to identify and develop zero-day exploits ‘can help defenders find and patch weaknesses’. Anthropic’s Mythos 5.1 is offered through its Cyber Verification Program, initially to organisations in the United States.
What changes for small businesses#
Nobody needs to panic about a particular AI model targeting a particular office. The broader shift is about speed: as tools for finding vulnerabilities get faster, the gap between a flaw being discovered and it being exploited is likely to keep shrinking.
That makes the unglamorous basics more valuable, not less. The Australian Signals Directorate’s Essential Eight already covers most of what matters.
Five things to tighten this quarter#
- 01Patch faster. Automate updates for operating systems, browsers and business apps, and confirm they actually install — especially on anything facing the internet.
- 02Switch on multi-factor authentication everywhere. It’s the focus of the Australian Government’s cyber security campaign this September for good reason: stolen passwords remain one of the most common ways in.
- 03Know what’s exposed. Firewalls, VPNs, remote desktop, websites and the old server someone forgot about. You can’t patch what you don’t know exists.
- 04Retire what can’t be updated. Unsupported software — like Windows 10 without extended updates — stays vulnerable for good.
- 05Test your backups. If something does get through, a clean, separate backup turns a disaster into a bad week.
Questions to ask your IT provider#
- How quickly are critical security updates applied — and how do we know?
- Which of our systems can be reached from the internet?
- Is multi-factor authentication enforced on every account that supports it?
- When did we last restore something from backup?
If those answers aren’t quick and confident, that’s where to start. A security assessment gives you them in writing.
Common questions
What is Claude Mythos 5.1?
It’s the same underlying model as Claude Fable 5.1, with different safeguards. Anthropic offers it only through trusted access programmes, including a Cyber Verification Program for defensive security professionals.
Can AI models like GPT-6 Astra hack my business?
The companies restrict their most capable cyber features to vetted security organisations. The practical risk for small businesses is that vulnerabilities get found and exploited faster overall — which is why prompt patching and multi-factor authentication matter more than ever.
What should a small business do about AI-driven cyber threats?
Focus on the fundamentals: fast patching, MFA on every account, knowing what’s exposed to the internet, retiring unsupported software and testing backups.
Sources
- 01Anthropic — Introducing Claude Fable 5.1 and Claude Mythos 5.1
- 02TechCrunch — OpenAI launches Astra, its powerful (and controversial) new model
- 03CNBC — OpenAI begins rolling out Astra model after warning of its advanced cyber capabilities
- 04Cyber.gov.au — Implementing multi-factor authentication
- 05National Office of Cyber Security — Campaigns and events






