Skip to ContentSkip to Navigation
founded in 1614  -  top 100 university
About us Latest news News

A digital game of cat and mouse

31 August 2026

It came as a shock earlier this year: the US AI company Anthropic, based in San Francisco, claims to have developed a generative language model called Mythos. The model exposes a multitude of vulnerabilities — i.e. software flaws — in computer operating systems, browsers, and servers. ‘You can compare it to a situation in the physical world where you can no longer lock anything,’ says Aline Klingenberg. Her colleague Evgeni Moyakine adds: ‘After all, an AI model like this can also be misused.’

Text: Jurgen Tiekstra

Klingenberg is in the Röling building in the heart of the city of Groningen. Sitting next to her is Evgeni Moyakine, associate professor of IT Law and Cyber Security. Moyakine is researching the legal avenues for holding states accountable for cyberattacks carried out by governments and their organizations. For him and Klingenberg, it is extremely relevant that the advance of artificial intelligence is creating new gaps in the security of computer systems.

decorative image
Evgeni Moyakine

Enhancing cyber resilience

AI is a double-edged sword, explains Evgeni Moyakine. ‘Whilst an AI model such as Anthropic’s is actually intended to detect vulnerabilities and help companies respond promptly to cyber threats, it can also be misused. I often discuss this in my lectures.’ One of the most important European directives, the NIS2 Directive, states that cybersecurity experts must use AI to detect vulnerabilities. The NIS2 Directive is intended to enhance the cyber resilience of certain critical organizations within the European Union. These include sectors such as healthcare, energy, transport, and education.

Anthropic has decided for the time being to only release this AI model, called Mythos Preview, to a select number of companies, including Google, Apple, Amazon, Cisco, Microsoft, and NVIDIA. This will allow them to investigate the implications for their systems. ‘However, a small group of users on the Discord chat platform also claim to have gained access to Mythos. They say they have no malicious intentions, but you never know exactly who has got their hands on it and what they might do with it.’

decorative image
Moyakine: ‘Companies and organizations want to protect their systems and networks as effectively as possible. But how do you do that when you know that hackers have access to AI systems and can strike effectively?’
decorative image
Aline Klingenberg

Swiss-cheese security

What could the consequences be? Mythos is considered more dangerous than other models due to its exceptional ability to discover and exploit unknown cyber vulnerabilities, thereby increasing the risk of large-scale cyberattacks and abuse. Klingenberg reflects on the recent hack of the Canvas learning management system, claimed by the hacker group ShinyHunters. This group was also behind the earlier hack at telecom company Odido. ‘Fortunately, we do not use Canvas at the university,’ says the professor. ‘But I have heard of degree programmes that are now unable to award degrees because they cannot mark the exams or assignments. That has all sorts of consequences for further study and for job applications.’

In theory, a company like Anthropic has no interest in disrupting the internet with a disruptive AI model that turns digital security into Swiss cheese. That is why the company has entered into a partnership with the major US tech firms, under the banner of ‘Project Glasswing’. ‘But you suddenly find yourself dependent on the morality of such a company when it comes to who is allowed to use that system,’ Klingenberg counters. ‘Whilst this is comparable to a company marketing specialized burglary equipment.’

America vs Europe

Underlying this is a fundamental difference between the American and European market structures. ‘In America, the system works differently than in Europe: there, everything is permitted unless it is explicitly prohibited. In Europe, we tend to ask ourselves earlier on: is this actually desirable, and what sort of society do we actually want? That way of thinking stems from the period after the Second World War, when we began to base our approach more on human rights. In America, the free entrepreneurial spirit prevails much more, and is only curbed later in the process by court rulings on large damages awards, for example in the case of Facebook. In Europe, new technologies are generally assessed earlier on in terms of privacy, security, and social consequences.’

Digital regulation is difficult to enforce globally. ‘We can certainly say: we do not want chlorinated chicken on the market, or certain types of meat treated with hormones. But with digital products, something like that is more difficult. It is a real struggle. The European Commission is trying all sorts of things, through supervision and the imposition of fines. I am thinking, for example, of the GDPR (the EU’s General Data Protection Regulation). The European Commission has imposed fines on WhatsApp for collecting and using data. A company like that faces fines in Europe that it would not be subject to in the US.’

decorative image
Klingenberg: ‘After the recent hack of the Canvas learning management system, some degree programmes were unable to award degrees because they cannot mark the exams or assignments. That has all sorts of consequences for further study and job applications.’

Staying one step ahead of hackers

It is clear that language models such as Mythos pose a major challenge for the world of cybersecurity. Evgeni Moyakine: ‘Companies and organizations want to protect their systems and networks as effectively as possible. But how do you do that when you know that hackers have access to AI systems and can strike effectively? In that case, you need to adapt your business processes. The National Cyber Security Centre has also responded to the news about Anthropic’s Mythos, stating: take these kinds of AI developments into account and incorporate them into the technical measures you put in place, for example in patch management (plugging holes in your security). After all, you want to stay one step ahead of hackers. If there is a vulnerability, these malicious attackers can strike immediately, because they are much faster and more efficient than organizations with slow decision-making processes.’

‘It remains a game of cat and mouse,’ Klingenberg concludes. ‘Regulation, by its very nature, lags behind societal developments. Otherwise, you would end up with a Soviet-style planned economy. Lawmakers cannot predict in advance: ‘In two years’ time, this will happen in the digital world, so I will have a law drafted now.’

This article has been taken from our alumni magazine Broerstraat 5.

More information

Last modified:26 August 2026 1.07 p.m.
Share this Facebook LinkedIn
View this page in: Nederlands