No offense to the members of the media, but the media tends to blow this stuff up.
That’s how Jim Williamson, president and chief executive officer of insurer and reinsurer Everest Group Ltd., prefaced his answer to a question about managing cybersecurity risks in the age of AI during the S&P Global Ratings 42nd Annual Insurance Conference last week.
“On cyber risk, we are in the same arms race we were before AI,” Williamson believes, chiding the media for exaggerating the Mythos model story and the ability of bad guys to get into companies and exploit faults at a pace.
Warnings from Anthropic that its Claude Mythos model was too dangerous to release to the public spawned the media articles. In an April 7 post on its webs
ite, Anthropic said the “Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Given the rate of AI progress, it will not be long before such c
apabilities proliferate, potentially beyond actors who are committed to deploying them safely.”
“The fallout—for economies, public safety and national security—could be severe,” the statement warned, also disclosing the launch of Project Glasswing, restric
ting access to a limited group of major tech, finance and security organizations to use in cybersecurity work to identify and repair vulnerabilities in critical software infrastructure.
More recently, after Williamson spoke at the S&P conference, the U.S. government “issued an ex
port control directive to suspend all access” to Mythos and to a more heavily secured AI model, Claude Fable, “by any foreign national, whether inside or outside the Unit
ed States,” according to a June 12 statement from Anthropic. Effectively, the government order forced Anthropic to abruptly disable the models for all its customers to ensure compliance, the tech giant said.
Two days before the government action, Williamson delivered his answer to a question about insurer cyber risk management posed by Taoufik Gharib, director a
See more beautiful photo albums Here >>>
nd lead analyst for S&P Global Ratings, during an “Executive Perspectives” session of the S&P conference.
While the media focused on the ability of Anthropic’s AI model to exploit risk management deficiencies, “they don’t tell you in the story, or at least it’s maybe buried in the story, that that’s only true where there are no defenses in place.
All of those case studies are based on a completely [defenseless] enterprise that takes no remedial action. That is not how the world works,” Williamson said, adding that Everest and its clients are “deploying excellent tools at scale.”
“And AI is one of the best defensive trends happening in the cyber defense market. So, I think where we are on cyber risk is we’re in the same arms race we were bef
ore AI, which is bad guys want to exploit vulnerabilities to make money, good guys want to stop them from doing that, and there’s a constant one-upmanship to get ahead of that curve one way or the other.”
“My personal view right now—and this is a very fluid situation—is the good guys are holding a lot more of the cards in this environment.”
He reasoned: “Think about what it takes to build a capability like Mythos at scale. A bad actor can leverage what others are developing, but they can’t build it on their own.”
What that means is “yes, phishing exercises will get a little easier… But [what] everybody was afraid of when they started hearing about Mythos—that they’d wake up one day and find out that some AI capability allowed hackers to
bring down Azure or something—I just think that’s way, way, way out of the tail. [There’s] a lot of infeasibility around that.”
Williamson concluded: “I think AI will do as much to improve cyber hygiene and security and opportunity as it will be a threat.”

























