AIApr 24, 2026
Too dangerous for you. Fine for the government and a bank.
TL;DR Anthropic withheld Claude Mythos from the public on 7 April, citing cyber- and bio-weapon risk. Forbes has since reported active White House discussions to grant Mythos access to US federal agencies. Axios has confirmed BNY Mellon (~$50T custody) and roughly 40 other vetted enterprises already have early access.
TL;DR
- Anthropic withheld Claude Mythos from the public on 7 April, citing cyber- and bio-weapon risk.
- Forbes has since reported active White House discussions to grant Mythos access to US federal agencies. Axios has confirmed BNY Mellon (~$50T custody) and roughly 40 other vetted enterprises already have early access.
- The same week, unauthorised users reportedly accessed Mythos through means Anthropic has not disclosed.
- Result: a de facto three-tier access structure — federal, vetted enterprise, everyone else — with no published criteria and no external audit.
- Mandatory disclosure of early-access programmes belongs in the next serious AI bill on either side of the Atlantic.
What happened, sequenced
On 7 April, Anthropic announced Claude Mythos and declined to release it. The stated reason: the model could meaningfully lower the barrier to building biological and cyber weapons. Dario Amodei framed the decision as the company's safety framework working as designed.
Two weeks later the picture looks different.
Forbes reports the White House is in active discussions to grant Mythos access to US federal agencies. Axios has confirmed that BNY Mellon — the world's largest custodian bank, $50 trillion under custody — already has early access, alongside roughly forty other vetted enterprises. And the same week, unauthorised users reportedly accessed Mythos through means Anthropic has not disclosed.
The position, today: too dangerous for the public, available to the government, available to a handful of banks, and already out the door to people who should not have it.
This is the story that isn't getting the coverage it deserves, and it has the longest tail.
The three-tier stack we now appear to have
Tier one — federal and national security. The administration's pitch, per Forbes, is that the US government needs frontier-model parity with anything adversary nations might access. Mythos access would sit inside classified environments. The argument is serious and has been made before about every dual-use technology from satellite imagery to cryptography. It is also the argument that normalised the post-9/11 surveillance stack. Worth remembering.
Tier two — vetted enterprise. BNY Mellon and ~40 peers. Criteria for inclusion have not been published. Commercial logic is defensible — sophisticated buyers with compliance infrastructure, seven-figure sums for early access, workloads (fraud detection, regulatory reporting, sanctions screening) where frontier capability is arguably justified. Governance logic is less clean. A bank's compliance team is not the same as a national security clearance.
Tier three — everyone else. Blocked on safety grounds. Told to wait.
The problem is not that tiers exist. Tiers always exist in frontier technology. The problem is that this tier structure was set unilaterally by a private company, is not externally audited, has no published criteria, and was justified to the public with a safety argument the company has now selectively overridden for its largest customers and a presidential administration.
The framing critique
Anthropic will say — and be partially right — that "withheld from public release" never meant "withheld from everyone." Every frontier lab runs early-access programmes. BNY Mellon's presence is not remarkable in itself.
What is remarkable is that the 7 April announcement led with cyber- and bio-weapon risk. If the model is dangerous enough to withhold from a PhD researcher at a public university, the case for a commercial bank running it in production is not self-evident. It may be defensible. But it has not been defended, because the public positioning was never that there would be a client list. The public positioning was that the model was simply not for release.
Those are two different positions that require two different public explanations. Only one has been given.
The hype to deconstruct
The dominant narrative this week frames this as "Anthropic's bad week" — a story about competitive embarrassment. It isn't. It is a story about how the governance frame of frontier AI just quietly shifted. The vendor-competition angle is the fig leaf; the access-tier question is the body.
The unauthorised-access compound
The timing of the reported incident makes the tier question sharper, not softer.
If the lab's own controls failed before Mythos cleared any external safety review, the argument that controlled enterprise access is safer than public release loses force. The real comparison is not controlled enterprise vs. public release. It is controlled enterprise plus unauthorised access vs. public release plus bug-bounty access. Reasonable people can disagree about which is actually safer.
Anthropic has not disclosed the scope of the incident, the mechanism, the parties involved, or whether any of the 40 vetted enterprises were affected. That silence is doing more damage than the incident.
Who gains, who loses
- The US administration — frontier-model capability inside classified systems without legislating for it. Strong incentive to keep the current arrangement unlegislated.
- BNY Mellon and peers — a measurable competitive edge in fraud detection, compliance, and risk modelling, the workloads where Mythos's reasoning advantages matter most.
- Anthropic — revenue and a political patron, at the cost of narrative coherence on safety.
- Smaller enterprises, researchers, the public — lose ground. By the time Mythos reaches general availability, the frontier will have moved again, and the gap between tier-two access and everyone else is structural.
- Non-US governments — lose the most. A US administration with frontier-model access changes the intelligence calculus for every other country. The lack of equivalent EU, UK, or Japanese arrangements is now visible.
Cross-layer implications
This story reaches into export controls (Mythos would not be exportable at this tier to several treaty allies), into AI safety research (the "voluntary withholding" frame was the empirical anchor for the industry's self-regulation pitch), and into competition policy (tier-two early access operates functionally as preferential pricing for scale incumbents). None of those are currently on any regulator's dashboard for this class of product.
The question nobody in Washington is asking on the record
If Mythos is too dangerous for a researcher at MIT to evaluate independently, on what basis is it safe for a bank's quant desk? And if the answer is "because the bank signed an NDA and a usage policy," the safety argument has quietly collapsed into a commercial licensing argument. Those are not the same argument. They should not be funded by the same political capital.
What this means for you
- AI governance, policy, or standards: this is the case study of the decade. Mandatory disclosure of early-access programmes — buyer list, use cases, safety attestations — belongs in the next serious AI bill on either side of the Atlantic. Start drafting now. Australia's forthcoming AI assurance framework should watch the US response closely.
- Enterprise procurement not on the early-access list: you are buying the previous generation. Ask your vendor of record when your tier gets parity access, and what the governance terms are for the tier above you. The answers will be uncomfortable. Get them anyway.
- Researcher or journalist: the published criteria for Mythos inclusion are the FOI request worth filing. Start with the White House Office of Science and Technology Policy.
- General reader: you have just watched a quiet, permanent shift in how frontier technology is distributed. What to watch: whether any government requires public disclosure of early-access programmes within twelve months. If one does, the two-tier era gets shorter. If none do, it becomes permanent.
Uncertainty ledger
- Full composition of the ~40-enterprise list. Only BNY Mellon has been confirmed on the record.
- Whether federal-access discussions have progressed to a contract or MOU.
- Scope and mechanism of the unauthorised-access incident.
- Whether similar early-access programmes exist for GPT-5.4-Cyber (reportedly yes, overlapping enterprise list) or Google's forthcoming Gemini frontier tier.
Bottom Line
Anthropic withheld Mythos on safety grounds and then sold it to a bank and was days from selling it to the White House. That is not hypocrisy; it is what happens when a private company is allowed to set access policy for a dual-use national-capability technology with no external audit. The news this week is not that Mythos is a two-tier product. It is that we have accepted a world where a private company runs the tiering.
Written in the tradition of — E.
Sources
- Tier 1: Forbes — White House / federal-access reporting (16–22 April 2026); Axios — BNY Mellon early access, Mythos incident reporting (23 April 2026); Anthropic — Claude Mythos announcement and safety rationale (7 April 2026)
- Tier 2: TechCrunch — Altman commentary, Anthropic week-in-review (21 April 2026)