Pyyan / News / 3 September 2026

SafetyBooz Allen · Anthropic

Booz Allen ranked 18 AI models as cyber attackers, then showed the ranking barely holds

67point gap closed by tooling, not by a better model

Booz Allen scored 18 AI models on how far each could break into a real network on its own. Then it gave a piece of ordinary software to the model that came fifteenth, and the model that came fifteenth performed like the one that came first.

Claude Mythos, unaided80Claude Sonnet 5, unaided13Claude Sonnet 5, with a harness800100
Cyber Weapon Index scores. The third bar is the same model as the second, given an attack harness. Booz Allen reports that run as rivalling Mythos rather than as an exact number, so it is drawn level with the score it was compared to.

The Cyber Weapon Index ran 18 US and Chinese models against production grade enterprise networks, with every action checked against network telemetry and intrusion detection sensors rather than taken from the model's own account of itself. Claude Mythos was the only model to complete the full kill chain, the whole sequence from first access through to control of the network, scoring 80. Claude Sonnet 5 scored 13 and ranked fifteenth. Adding an attack harness, which is software that connects a model to existing hacking tools it did not have to write itself, lifted Sonnet 5 to rival Mythos. Booz Allen puts the finding in one line: the model is no longer the unit of risk, the system is.

Why this one is different

Every cyber benchmark published this year ranks models. This one ranks models and then shows its own ranking coming apart under a change of tooling. The 67 points between first and fifteenth were closed by software anybody can obtain, which means the index measures a model stripped of the equipment an actual attacker would bring. It is unusual for the limit of a benchmark to be demonstrated by the people who published it.

The model is no longer the unit of risk. The system is.

How we got here

  1. 10 Aug 2026OpenAI ships GPT-5.6-Cyber to a vetted tier only, after training raises its completion of exploit chain tasks from 1.5% to 95%.
  2. 1 Sep 2026OpenAI rates GPT-6 Astra Critical for cybersecurity under its own Preparedness Framework, the first model it has ever so rated.
  3. 1 Sep 2026Anthropic ships Claude Mythos 5.1, the same weights as Fable 5.1 with the safety classifiers removed, to vetted US organisations only.
  4. 2 Sep 2026Google ships a cyber variant of Gemini 3.8 Flash behind an application form.
  5. 3 Sep 2026Booz Allen publishes the index. The model at the top of it is the Mythos line, the one that ships with its classifiers off.

What it does and does not mean

This does not show that one lab's model is uniquely dangerous. Booz Allen tested every model bare, with no curated tool menu and no added scaffolding, and its own harness result shows that is not the condition anyone would be attacked in. The company also notes that safeguards shift with configuration and context, so a score describes a setup rather than a model. What it does show is narrower and harder to answer. Every response the industry has made to offensive cyber capability this year has been to gate a model, and the one public measurement of that capability says the model is not the thing that decides. Booz Allen expects most of the other 17 to reach full kill chain autonomy within six months.

Booz AllenThe Next Webfrom the source itself

Related

← All the news, newest first