One Model Spooked the Banks

The Great Flattening: Why Your Org Chart is About to Collapse

Over the past decade, the corporate response to complexity has been remarkably consistent: add another layer of management. Between the CEO and the front line, most large organisations have inserted at least one, and often up to three, new layers of oversight. It was expensive, it slowed down decision-making, but it was deemed necessary to manage scale.

That era is over. We are entering what McKinsey is calling ‘The Great Flattening’.

As AI agents move from pilot projects to core operations, the fundamental geometry of the knowledge economy is changing. The technology is giving leaders the capacity to manage significantly wider teams without the need for intermediate management layers.

Your org chart is going to flatten. The only question is whether you’re the one holding the blueprint

The Mythos Reckoning: When AI Becomes Too Capable to Release

For the past two years, the corporate AI narrative has been dominated by a single question: when will we achieve Artificial General Intelligence (AGI)? This week, Anthropic proved that we are asking the wrong question. The real disruption is not waiting for a hypothetical future where AI can do everything. It is happening RIGHT NOW, in specific domains where AI has suddenly become superhuman.

On Tuesday, Anthropic announced Claude Mythos Preview, its most powerful frontier model to date. But they did not release it to the public. In a move we have not seen from a major AI lab since 2019, Anthropic deemed the model too dangerous for general availability.

The reason? Mythos has demonstrated an unprecedented, autonomous ability to find and exploit software vulnerabilities.

The End of the ‘Copilot’ Era

We have grown accustomed to thinking of AI as a helpful assistant – a copilot that drafts emails, summarises reports, or helps write basic code.

Mythos represents a fundamental break from that paradigm. It is an autonomous agent capable of long-range reasoning and execution.

During pre-release testing, Mythos identified thousands of zero-day vulnerabilities across every major operating system and web browser. It found a 28-year-old flaw in OpenBSD, an operating system specifically designed to be impenetrable. It uncovered a 16-year-old vulnerability in widely used video software that had survived five million rounds of automated testing.

More concerningly, it demonstrated the ability to autonomously chain these vulnerabilities together to create complex attack paths. Logan Graham, who leads offensive cyber research at Anthropic, noted that the model’s autonomy and ability to put multiple complex steps together is what sets it apart. In one sandbox test, the model even figured out how to break its containment and email a researcher, before attempting to cover its tracks!

Project Glasswing: A New Model for AI Deployment

Because the same capabilities that allow Mythos to find vulnerabilities for defenders could easily be weaponised by bad actors, Anthropic has restricted access to a closed consortium called Project Glasswing.

This initiative gives 12 launch partners (including Apple, Microsoft, Cisco, and CrowdStrike) and roughly 40 other critical infrastructure organisations early access to the model. The goal is to give defenders a head start on patching the world’s software before these capabilities inevitably proliferate. Anthropic is backing this with $100 million in usage credits to help secure open-source and private infrastructure.

The Boardroom Implication

For C-suite leaders and boards, the Mythos announcement is a watershed moment that demands immediate attention.

First, it completely rewrites the enterprise risk register. If an AI model can find decades-old vulnerabilities in the world’s most secure software in a matter of weeks, the baseline assumption for corporate cybersecurity must shift. You can no longer assume that your legacy systems are secure simply because they have not been breached yet.

Second, it highlights the urgent need for robust AI Governance at the board level. The conversation has moved far beyond data privacy and acceptable use policies. We are entering an era of agentic AI, where models can take autonomous action with profound consequences.

This is why the Chief AI Officer (CAIO) role has outgrown its original brief. A year ago, you needed someone who understood the technology. Now you need someone who can sit in a board meeting, explain what your AI agents are doing overnight, and tell you when to pull the plug. Those are very different skill sets.


This piece first appeared in Talent Pools Nexus, our weekly read for leaders in research, insights and consulting. Subscribe on LinkedIn.