- Anthropic's alarm signal: what has changed
- Problem architecture: why AI finds bugs faster
- The immediate impact on Italian SMEs
- The high-risk transition period: an operational perspective
- What to do now: concrete priorities for those managing digital infrastructures
- The work still in progress: no one has the definitive solution
- Outlook: where the market is heading in the next 18 months
Anthropic has issued a public warning: its model Claude Mythos Preview , used in Project Glasswing with about 50 partners, has identified over 10,000 critical vulnerabilities in system software. However, the pace of discovery exceeds the operational capacity of development teams to produce adequate patches. This creates what Anthropic itself calls a high-risk transition period .
Specifically, the company openly admits that no company — including itself — has yet built sufficient safeguards to prevent misuse of these models. Consequently, the risk is not theoretical: it is operational and immediate. For Italian SMEs using third-party software or managing digital infrastructure, this scenario necessitates an urgent review of patch management policies and a concrete assessment of AI-related risk exposure.
We at SHM Studio we constantly monitor the evolution of AI tools and their implications for B2B and retail companies. Therefore, in this article, we analyze what has changed, what concrete impact it can have on SMEs, and what priority actions to consider immediately.
Anthropic's alarm signal: what has changed
On May 23, 2026, Anthropic issued a warning that struck the international tech community. The model Claude Mythos Preview , operating within the Project Glasswing , has surpassed 10,000 critical vulnerabilities identified in system software. However, the most worrying figure isn't the absolute number. It's the speed.
The pace of bug discovery systematically outstrips the ability of development teams to produce and deploy corrective patches. Therefore, a time gap is created — potentially weeks or months long — during which vulnerabilities are known but not yet fixed. This timeframe represents a concrete attack window for malicious actors.
According to reports by The Decoder , Anthropic has explicitly stated that no company — including itself — has sufficient safeguards today to prevent the misuse of these advanced models.
Problem architecture: why AI finds bugs faster
State-of-the-art language models like Claude Mythos Preview operate on a scale of source code analysis that is impossible to replicate manually. In fact, they can examine millions of lines of code in parallel, identifying known vulnerability patterns and novel variants.
Furthermore, these systems don't just look for already cataloged exploits. They apply contextual reasoning to identify combinations of conditions that, individually, would seem harmless. Consequently, classes of vulnerabilities emerge that traditional SAST and DAST tools do not intercept.
The structural problem is that the human patch management process is sequential and subject to organizational constraints. In contrast, an AI model works asynchronously and is unaware of bureaucratic bottlenecks. This asymmetry is at the heart of the risk described by Anthropic.
The immediate impact on Italian SMEs
Large companies have dedicated Security Operations Centers and budgets to respond quickly to new threats. Italian SMEs, on the other hand, often operate with limited IT resources and extended software update cycles. Therefore, the exposure gap is structurally wider.
In particular, three categories of SMEs are more vulnerable in this scenario:
- Companies using unattended open source software : third-party libraries integrated into their technology stacks may contain vulnerabilities already known to Claude Mythos but not yet patched by maintainers.
- Retailers with e-commerce infrastructure : payment and order management systems represent high-value targets. Therefore, any uncorrected vulnerability window is a direct risk to customer data.
- B2B SMEs with access to enterprise supplier systems : they often serve as an attack vector towards larger organizations. Consequently, their security is also relevant to the ecosystem in which they operate.
According to the analyses of McKinsey Digital , SMEs that don't update their cybersecurity practices in response to the evolution of AI tools risk becoming the weak link in entire supply ecosystems.
The high-risk transition period: an operational perspective
Anthropic uses the expression high-risk transition period to describe the current phase. This definition deserves attention. It's not a future or speculative risk. It's a present condition, documented by real data.
Similarly to what happened with the spread of the first automated fuzzing tools in the 2000s, the introduction of advanced AI in vulnerability research shifts the balance between attackers and defenders. However, the current scale and speed have no comparable historical precedent.
Gartner has already included the AI-accelerated threat discovery among the main technological risks for organizations in the 2026-2027 biennium. Therefore, this is not an isolated alarm from Anthropic, but a trend recognized by the entire analyst community. You can learn more about this context in the research by Gartner Top Technology Trends .
What to do now: concrete priorities for those managing digital infrastructures
Faced with this scenario, the response cannot be to wait. We at SHM Studio we suggest that SMEs address the problem on three distinct but interconnected levels.
First level — Inventory and visibility: It is necessary to know precisely which software components are in use, including third-party dependencies and open-source libraries. Without an updated inventory, any patch management strategy is structurally blind.
Second level — Response speed: Software update cycles need to be compressed. Furthermore, emergency patching procedures for critical vulnerabilities must be defined, separating them from normal release cycles. This requires a minimum of IT governance, even in small business contexts.
Third level — AI exposure assessment: If a company uses or integrates AI models into its processes, it's necessary to map the points of contact between these systems and critical infrastructures. Subsequently, a clear policy must be defined regarding which data and systems can be exposed to third-party AI tools.
For SMEs wanting to learn more about securely integrating AI tools into their digital processes, our team offers dedicated consulting through the SHM Studio AI services .
The work still in progress: no one has the definitive solution
It's worth highlighting an element that is often overlooked in public debate. Anthropic did not present this warning as someone else's problem. On the contrary, it included itself among the companies lacking adequate safeguards.
This admission carries considerable weight. It means the AI sector as a whole is operating in a regulatory and technical gray area. Therefore, blindly trusting the safety claims of AI vendors—even the most reputable ones—is a risky stance today.
Therefore, the correct answer isn't to give up on AI, but to adopt it with critical awareness. SMEs that are considering integrating AI tools into their workflows — from digital marketing management to the SEO optimization — must include the security dimension in the decision-making process, not treat it as a separate issue.
Outlook: where the market is heading in the next 18 months
Anthropic's Glasswing project involves about 50 partners. This number will grow. Furthermore, other AI labs — OpenAI, Google DeepMind, Meta AI — are developing similar automated vulnerability research capabilities.
Consequently, the cybersecurity market will face increasing pressure towards automation on the defensive side as well. Tools for AI-assisted patch management and automated remediation will become standard components of enterprise security stacks, no longer premium options reserved for large organizations.
For Italian SMEs, this means the cost of accessing advanced security tools will decrease over time. However, in the short term — the next 12-18 months — the gap between the speed of vulnerability discovery and response capability will remain critical.
Finally, regulatory interventions are to be expected. The NIS2 directive, already in force in Europe, imposes cyber risk management obligations also on SMEs operating in sectors considered essential. The context created by Claude Mythos Preview will likely accelerate the enforcement of these obligations.
To stay updated on the evolution of these scenarios and their implications for SMEs' digital strategies, you can consult the SHM Studio blog or contact our team directly .
Further technical insights on the topic are available in the analysis of MIT Technology Review dedicated to the impact of AI on cybersecurity.
For those managing digital campaigns and wanting to understand how to protect data collected through tools like Google Ads or LinkedIn Ads , API integration security is a topic that deserves specific attention. Similarly, those investing in SEO copywriting AI-assisted must carefully evaluate what company data is processed by the models used. The web design security remains, finally, a fundamental prerequisite for any sustainable digital strategy.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.