Advanced AI like Claude Mythos represents a watershed moment, automating and scaling vulnerability discovery and exploit development to a level that is comparable to or better than top-tier human experts.
The immediate, unrestricted proliferation of these AI capabilities would dangerously tilt the cybersecurity landscape in favor of attackers.
A proactive, collaborative defense among key technology companies is essential to secure systemic vulnerabilities before offensive AI tools become widespread, as exemplified by Project Glasswing.
Government policy, specifically export controls on high-end computing hardware, is a critical, if temporary, tool to constrain the ability of adversaries to develop their own powerful AI models.
The plausible, next-generation threat is the use of AI to successfully execute cyberattacks against industrial control systems to cause kinetic, real-world physical damage.
~2012
Cites Iranian DDoS attacks against US banks as a past 'galvanizing moment' that forced a sector to significantly upgrade its cybersecurity, drawing a parallel to the current moment with AI.
2016
References Russia's 'Crash Override' attack on Ukraine's power grid as a key historical data point demonstrating nation-state intent to use automated tools for kinetic effects.
2017
Points to the NotPetya cyberattack, attributed to Russia, as the most destructive in history by monetary value, setting a benchmark for the potential scale of cyber disruption.
Pre-Biden Administration
As a researcher at CSET, contributed to the intellectual groundwork that would later inform the Biden administration's AI chip export controls.
Biden Administration
Served as an AI policy advisor in the Biden White House, directly involved in shaping national policy on artificial intelligence.
Present
Advises AI company Anthropic and publicly discusses the implications of their model, Claude Mythos, framing its development as a pivotal moment requiring a new approach to cybersecurity and collaborative defense through initiatives like Project Glasswing.
▶The 'Post-Mythos' Cybersecurity ParadigmMay 2026
Buchanan argues that the arrival of AI like Claude Mythos marks a new era in cybersecurity. This era is defined by a dramatic acceleration of the entire cyber lifecycle, from automated vulnerability discovery that surpasses top human experts to the potential for AI-assisted exploit chains. This shift necessitates a corresponding acceleration in defensive measures, from discovery to patching.
Analysts should anticipate a compression of timelines for both cyber attacks and defense, placing a premium on automated security solutions and rapid response capabilities, as the 'human-in-the-loop' becomes a bottleneck.
▶The Precarious Offense-Defense BalanceMay 2026
A core theme is the dual-use nature of advanced AI in cyberspace. While Buchanan champions Anthropic's goal to arm defenders, he explicitly warns that these tools inherently favor the offense in the near term. This creates a delicate balance where defensive tools, if they proliferate, could become powerful offensive weapons for adversaries.
The development of advanced AI for cybersecurity is not a simple arms race; it's a proliferation risk where the very tools created for defense could catastrophically empower attackers if they fall into the wrong hands.
▶From Digital Intrusion to Kinetic ImpactMay 2026
Buchanan elevates the threat conversation from data breaches to physical-world consequences. He connects the dots from past failed attacks on infrastructure, like Crash Override, to a future where a more capable AI could succeed in manipulating industrial control systems to cause kinetic effects. This frames the AI cyber threat as a national security issue with tangible, physical risks.
Investors and risk analysts in critical infrastructure sectors must re-evaluate their threat models to include AI-driven attacks capable of causing physical disruption, a scenario Buchanan now considers plausible.
▶Governing AI Proliferation: Policy and Private Sector Action
Buchanan's discourse highlights a two-pronged approach to managing powerful AI. He points to the government's role in using policy levers like export controls to slow down adversaries. Simultaneously, he emphasizes the private sector's responsibility, showcased by Project Glasswing, to form collaborative consortiums to address systemic risks before capabilities proliferate widely.
The governance of powerful AI will not be solely a government function; it will rely on a hybrid model where strategic public policy (like chip controls) is complemented by proactive, private-sector-led defensive alliances.