CLAUDE MYTHOS · DORA · Q2 2026

Anthropic built the attacker.

DORA puts the bill on your desk.

Q2 2026 · 4 min read ·

Anthropic built the attacker.

On 8 April 2026, Anthropic introduced Claude Mythos: AI that autonomously finds vulnerabilities and builds the corresponding exploits. Available via AWS Bedrock and Microsoft Azure. The threat landscape has fundamentally shifted as a result.

01 — From guideline to liability

The 30-day patch window was a guideline. It is becoming a matter of liability. The model scans more than a thousand systems at once and builds usable exploits within 24 hours. The burden of proof shifts: patch within 72 hours and document who did it, when, and why.

02 — The new calculus

1,000+systems scanned simultaneously
<24hfrom exploit to breach
3 daysthe new patching standard

It is no longer about patching faster, but about being able to prove that you can patch.

03 — DORA sets four requirements

  • Art. 5–16 (ICT risk management): the risk framework must be demonstrably up to date; the board is accountable for this itself.
  • Art. 28–44 (Third-party providers): contracts with suppliers must be tightened; trust on paper is not enough.
  • Art. 24–27 (Resilience testing): AI-driven attacks must become the standard in penetration testing and red teaming.
  • Art. 19 (Incident reporting): the first report must be ready within 4 hours of classifying an incident.

Why this is different: the CISO versus the board

The CISO wants

  • A workable patch window of 24–72 hours
  • Tighter SLAs with third-party providers
  • The mandate to take systems offline

The board wants

  • Continuity and planning
  • Predictable costs
  • Services that keep running

Both are right. But the real solution demands that governance be redesigned — and that begins at board level.

The question for your board meeting

Will cyber sit structurally at your board table — or only make the agenda after the incident? Who has the authority to change that tomorrow? And: is that person already in place?

How VigIT People helps

We help healthcare institutions, governments and regulated organisations find the security leaders who make the difference — before the regulator comes knocking.

Get in touch

Marc Magrijn MSc LLM CISM — marcmagrijn@vigitpeople.tech

Source: Anthropic announcement 08-04-2026 · Regulation (EU) 2022/2554 (DORA) · NIS2 · NEN 7510 · Cyberbeveiligingswet · ENISA aligned