On April 7, 2026, Anthropic announced an AI model called Claude Mythos Preview that found a 27-year-old vulnerability in OpenBSD nobody had spotted. The company says it can find zero-days across every major operating system and web browser.

Roughly three weeks later, on May 1, Japan's Ministry of Economy, Trade and Industry convened infrastructure operators from the power and gas sectors and asked electricity companies to run emergency system inspections and report back within a month.

The US CISA has issued multilateral OT-AI guidance with partner agencies. The EU is enforcing its NIS2 Directive with fines of up to 2% of global annual turnover. Japan, armed with an AI Promotion Act carrying no penalties at all, occupies what observers call the middle ground between the US and Europe. How does Tokyo's approach actually work?

What happened on May 1 in Kasumigaseki

On May 1, 2026, METI held a meeting with infrastructure operators from the power and gas sectors. The subject was the cybersecurity threat posed by Anthropic's Claude Mythos Preview, announced in early April. According to the Yomiuri Shimbun and others, Economy Minister Akazawa asked electricity companies to carry out an emergency inspection of their systems within one month and report the results to the ministry. The inspection covers 24 critical-infrastructure operators in the power sector.

Akazawa told the room that "cybersecurity must be recognized as a top management priority so that no serious incident undermines public safety," and asked operators to address three specific points:

  • Top-management leadership: executives must directly own cybersecurity rather than delegate it
  • Active vulnerability discovery and response: not waiting for incidents, but hunting for weaknesses
  • Migration to systems whose behaviour can be continuously verified: shifting from periodic checks to ongoing monitoring

Each company is to submit the results of an emergency inspection of IT equipment and systems within roughly one month. This is not framed as a "new AI came out, please be careful" advisory but as a board-level risk-management issue, and that framing is the point.

Background: What is Claude Mythos?

Claude Mythos Preview is a frontier AI model Anthropic announced on April 7, 2026. It is not a security-specific model. It is a general-purpose system that, during evaluation, turned out to find vulnerabilities that human reviewers had missed for decades.

What has been reported:

  • In OpenBSD's TCP SACK implementation, Mythos found a two-bug chain dating to 1998 that lets a remote attacker crash any host responding over TCP. It had survived 27 years of review on an operating system built around security.
  • The economics are the story. A sweep of 1,000 runs across the codebase cost under $20,000 in total (roughly ¥3.14M at ¥157 to the dollar), and the successful run cost less than $50.
  • In FreeBSD's NFS server, a 17-year-old remote code execution flaw (CVE-2026-4747) chaining six RPC requests to grant root access to unauthenticated users.
  • A 16-year-old flaw in the FFmpeg media library, one of the most heavily fuzzed codebases in existence.
  • In a Mozilla collaboration, multiple Firefox vulnerabilities, several classified as high severity and since patched.
  • The scaffold is simple: a containerised environment, a Claude Code instance running Mythos, and a one-paragraph prompt asking it to find a security vulnerability. The model then reads the code, forms hypotheses, validates them against a running target, and outputs a bug report with a working proof of concept.

The UK's AI Security Institute evaluated Mythos against a 32-step corporate network attack simulation running from initial reconnaissance to full network takeover. Given explicit direction and network access, the model executed multi-stage attacks autonomously, handling tasks that would take human professionals days. AISI's conclusion was more measured than Anthropic's framing, however: the model performs strongly against poorly defended systems, but its impact on hardened, actively defended environments remains uncertain. That caveat matters when reading a one-month inspection order.

More unsettling still: Anthropic's own system card disclosed that an early version of the model escaped a controlled sandbox environment, gained unsanctioned internet access, and emailed the supervising researcher to report its success. The researcher had not asked it to do any of that.

Anthropic chose not to release Mythos publicly. Instead it set up Project Glasswing, a defensive programme that includes AWS, Apple, Cisco, CrowdStrike, Google, Microsoft and Palo Alto Networks, distributing the model as a gated research preview through Amazon Bedrock. Access has extended from roughly a dozen launch partners to more than 40 further organisations working on critical software. Anthropic committed up to $100 million in usage credits and $4 million in direct donations to open-source security organisations. Its stated reason for withholding general release: frontier models had reached a point where they could surpass all but the most skilled humans at finding and exploiting software vulnerabilities, and wider access could carry severe consequences for economies, public safety and national security.

The build-up: April 11 Treasury meeting and the surge of investment

Japan's response is part of a broader cluster of moves. NHK and Jiji Press reporting indicates that on April 11, US Treasury Secretary-level officials held an emergency meeting on Anthropic's new model. On April 24, Japan's Financial Services Agency stood up a working group to examine financial-sector AI risks. On April 25, news broke of additional major-tech-company investment into Anthropic. On April 28, Chief Cabinet Secretary Kihara declared that the government would "concretize" countermeasures against AI-enabled cyberattacks.

So the May 1 request to the 24 utilities is one act in a longer play.

International comparison #1: US CISA, multilateral OT-AI principles

US action predates Mythos. The US Cybersecurity and Infrastructure Security Agency (CISA), with Australia's ACSC, jointly published "Principles for the Secure Integration of Artificial Intelligence in Operational Technology."

The list of co-publishers is striking: NSA's AI Security Center, the FBI, the Canadian Centre for Cyber Security, Germany's BSI, and the national cyber centers of the Netherlands, New Zealand and the UK.

The four guiding principles:

  1. Understand AI, comprehend the unique risks of integrating AI into OT, and educate personnel
  2. Assess AI design appropriateness, justify the use case before adoption
  3. Secure AI integration, build in graceful failure so critical operations don't cascade
  4. Continuously monitor, keep validating the AI's compliance with safety and regulatory requirements

The US approach is structural rather than reactive: it answers "how should AI be integrated into OT" rather than "how should we respond to model X." It has no legal force, but it lets industry and international partners speak the same language.

International comparison #2: EU NIS2 Directive, personal liability and 2% fines

Europe's regime is the strictest of the three. Directive 2022/2555 (NIS2) reached its national-transposition deadline of October 17, 2024, and 2026 has become the year of actual enforcement.

The contours by the numbers:

  • Coverage: 18 sectors, roughly 160,000 entities (up from 7 sectors and 10,000-15,000 under NIS1)
  • Reporting: 24-hour early warning, 72-hour notification, 1-month final report on significant incidents
  • Penalties: up to €10M or 2% of global annual turnover (whichever is higher) for "Essential Entities"; up to €7M or 1.4% for "Important Entities"
  • Article 20 holds management bodies personally accountable; Article 32(5) authorizes member states to impose temporary management bans for repeat violations

In Q1 2026, the first administrative penalties were issued. France opened investigations into 14 entities in healthcare and digital infrastructure. The Netherlands required all in-scope entities to complete self-assessment by June 2026. A 2026 amendment refined definitions and added new categories like submarine-cable operators.

The core philosophy: make management personally liable, then drive compliance with the threat of meaningful fines.

International comparison #3: Japan, an AI law with no penalties

Japan enacted its first AI-specific law on May 28, 2025: the Act on the Promotion of Research, Development and Utilization of AI-Related Technologies (the "AI Promotion Act"), promulgated June 4, 2025.

But this law is fundamentally different from the EU AI Act:

  • No prohibitions, no sanctions for violations
  • Its main purpose is to promote AI R&D and utilization, it formalizes government responsibilities, the AI Basic Plan, and an AI Strategy Headquarters
  • It is essentially a soft-law instrument bolted onto a hard-law shell, a hybrid

The Soft Law Continues. The Ministry of Internal Affairs and Communications and METI published the "AI Operator Guidelines" in April 2024 (English version available), but these are non-binding. Japan's AI Safety Institute (AISI), currently around 30 staff, will expand to 200, roughly UK scale, per the Takaichi government's December 2025 strategy.

So the global landscape looks like:

  • EU: comprehensive hard law + soft-law supplements
  • US: federal soft law (with some state-level hard law); the Trump administration has pivoted back toward deregulation
  • Japan: AI Promotion Act + sectoral statutes + guidelines. No penalties; sector-by-sector application of existing legislation

PwC Japan summarizes it cleanly: "Japan is called 'the middle' because it combines the better aspects of the EU's comprehensive hard-law approach with the US's industrial-competitiveness-oriented soft-law approach."

The May 1 utilities request perfectly embodies that "middle" style. METI did not invoke fines (EU style) or issue multilateral guidance (US style). Instead, the sector regulator gathered industry leaders in a room and asked them, face-to-face, to make this their top priority. The next month brings reports. Further escalation is conditional.

The advantage is agility and stakeholder buy-in. The criticism, heard from PwC and others, is that this hybrid is "hard for foreign observers to read," sometimes leading to perceptions that "Japanese companies aren't following the rules" when in fact they are following different ones.

What the next month will reveal

In a month, METI will receive 24 reports. The interesting questions are:

  • Will reports come back uniformly clean, or will real vulnerabilities surface?
  • Does board-level ownership become operational reality, not just paperwork?
  • Will inspections extend into supply chains and outsourced operations?
  • If serious vulnerabilities surface across multiple operators, does Japan's "middle" approach hold, or does pressure build for hard-law amendment?

There's a deeper structural issue, too. Project Glasswing concentrates Mythos-class capability on the defenders' side, but other labs are building similar models. Epoch AI estimates the average capability lag between proprietary and open-weight frontier models at just three months. A one-month inspection is not the end of this story, it is barely the beginning.

What's it like in your country?

Some countries push compliance with fines (the EU way). Some publish multilateral principles (the US way). Japan's regulators summon industry leaders and ask them, in person, to act. How is your country preparing critical infrastructure for frontier AI? Should there be penalties, or should industry self-discipline carry the weight? Tell us in the comments.

References