News
UK AI Safety Institute Exposes GPT-5 Flaws, Warns on Claude Mythos

The UK's AI Security Institute has tested more than 30 leading AI models, uncovering serious security flaws before GPT-5's launch and warning governments about the cyber-offensive capabilities of Anthropic's experimental Claude Mythos model.
Contents
The UK's AI Security Institute (AISI) has become, in under three years, one of the world's most influential AI safety bodies, despite holding no formal regulatory powers. An analysis published on July 22, 2026 by the CEPA think tank shows how the institute earned the trust of both Washington and Brussels through testing that regularly uncovers dangerous vulnerabilities in the latest models before their public release.
The institute was founded in 2023 in the wake of the AI safety summit at Bletchley Park, the first meeting of its kind between governments and tech companies. Since then it has built a team recruiting talent from, among others, Google DeepMind's London lab, and signed early-access agreements with OpenAI, Microsoft, Anthropic and Google DeepMind, letting it test systems before they reach the public.
Testing ahead of GPT-5's launch
The institute's best-known success story remains GPT-5. Before OpenAI released the model, British researchers found more than a dozen flaws in it that could theoretically have let users obtain help building biological weapons. All were fixed before launch, and the collaboration with OpenAI continues, including red-teaming safeguards against biological misuse in ChatGPT Agent.
The AI Security Institute really is an important part of the AI ecosystem - Jack Clark, co-founder of Anthropic
Evaluating Claude Mythos
In July 2026, within a week of gaining access, the institute published an evaluation of Anthropic's experimental model, Claude Mythos Preview, warning of its ability to carry out multi-stage cyberattacks with minimal human involvement. On expert-level capture-the-flag tasks, the model achieved 73 percent success, even though no earlier system had been able to complete such tasks before April 2025.
In a more realistic test, a simulated attack on a corporate network made up of 32 stages called The Last Ones, Mythos Preview completed the full simulation in 3 of 10 attempts, averaging 22 of 32 stages. By comparison, Claude Opus 4.6 averaged 16 of 32 stages. Completing the full simulation would take a human an estimated 20 hours; the model was given a budget of 100 million tokens and network access.
Early political backing, freedom to operate, funding, and the ability to attract top talent - Herbie Bradley, a Cambridge PhD student who helped set up the institute
The race for offensive capability
Based on a series of tests run since 2023, including chat-based probing, capture-the-flag challenges and multi-stage attack simulations, AISI concluded that AI's offensive cyber capabilities are doubling every four months, twice as fast as previously estimated. In response to these findings, the UK government sent an open letter to companies across the country urging boards to treat cybersecurity as a board-level priority, not just an IT department matter.
International network and the Polish angle
AISI operates within the International Network of AI Safety Institutes, established in 2024 and now bringing together more than 17 countries, from the United States and Japan to Kenya and Brazil. The institute's unique position is reinforced by Britain's membership in the Five Eyes intelligence alliance, which makes its cooperation with its American counterpart, CAISI, described as very strong.
For Polish companies and public institutions still learning to deploy AI systems, the British model offers an alternative to the purely legal regulation of the EU's AI Act: an independent, well-funded team that tests models before launch and publishes results in an open tool rather than keeping them behind closed doors. The open letter to British companies urging them to treat cybersecurity as a board-level priority also matters directly for Polish branches of global corporations that use the same models as British firms.
The institute itself recognizes that its influence rests more on reputation than on hard legal powers. But the accelerating pace at which ever more capable models, such as Claude Mythos, keep appearing means pressure to formalize similar oversight mechanisms elsewhere, including in the European Union, is likely to grow in the coming months.

