The ‘Mythos’ Approach

‍What if Australia's operators of critical infrastructure had access to more powerful AI than the general public, not less? The United States is beginning to experiment with exactly that approach, allowing the release of Claude Mythos 5 to ‘trusted’ organisations to defend critical infrastructure.

The question is whether Australia should do the same and whether its existing legal frameworks could support this.

How the US Controls Frontier AI

A central challenge for governments is how to harness the capabilities of frontier AI models without creating unacceptable security risks. The most capable systems can provide advanced cyber defence capabilities, but they may also be misused to conduct cyber attacks, develop malicious code or exploit vulnerabilities at scale.

To address this challenge, the US has introduced special oversight arrangements for certain high-capability AI systems, often referred to as ‘covered frontier models’. These are models that exceed specified capability thresholds and are considered capable of creating significant national security risks. Reporting and pre-release safety testing obligations of this kind were first imposed on developers by Executive Order 14409, and the underlying approach has been carried forward through subsequent federal directives.

The recent release of Claude Mythos 5 illustrates how this approach can operate in practice. Mythos 5 is a restricted version of a frontier model designed for advanced cyber defence work. Unlike the public-facing version, which retains standard safeguards, access to Mythos is limited to vetted organisations participating in Project Glasswing. This reflects a broader principle: the most capable AI systems are not made universally available but are deployed selectively to trusted operators where the security benefits outweigh the risks.

Applying the ‘Mythos’ Approach to the SOCI Act

Australia already has a natural home for this type of AI defence: the Security of Critical Infrastructure Act 2018 (SOCI Act).

The Act’s primary object is to manage risks to critical infrastructure by improving transparency, facilitating government-industry collaboration, and requiring responsible entities to identify and mitigate hazards. As acknowledged by the Australian Signals Directorate, AI can transform cyber defence by automating anomaly detection, triaging alerts and responding to threats quickly.

Under Part 2A of the SOCI Act, responsible entities must maintain a Critical Infrastructure Risk Management Program (CIRMP). Australia could emulate the US by providing (or mandating) vetted ‘Mythos-style’ sovereign AI models for use within these CIRMPs to ensure that operators of systems of national significance are using tools tested by the Australian AI Safety Institute (AISI).

Building the governance framework

If the SOCI Act provides a pathway for deploying trusted AI within critical infrastructure, the Cyber Security Act 2024 may provide the governance framework needed to oversee its use. Several features of the Act, including information sharing measures, product security requirements and incident review mechanisms, align closely with the objectives of a ‘Mythos-style’ approach. As noted in a impact analysis by the Department of Home Affairs, this is critical for building a ‘national ransomware threat picture’.

The Act introduces mandatory security standards for ‘relevant connectable products’, which could eventually include the hardware that AI agents must monitor.

The Cyber Incident Review Board under the Act was established to conduct reviews into significant incidents. This Board could play an important role in analysing AI model failures.

Is Australia already taking steps?

Australia is already laying many of the foundations required for a ‘Mythos-style’ approach. These efforts can be grouped into three broad categories: building the institutions needed to oversee AI, establishing rules for its safe deployment, and investing in practical AI capabilities across government.

Building the institutions

The Office of AI has been established within the Department of the Prime Minister and Cabinet. It is tasked with developing new Australian AI standards and unlocking onshore AI training.

A$29.9 million has been invested for the establishment of the AI Safety Institute (AISI), which recently became operational to independently test frontier models before they reach the public.

A$28.9 million is being spent on the AI Delivery and Enablement (AIDE) function within the Department of Finance. It is intended to accelerate adoption and resolve common barriers, helping to bring core work back into the public service.

Deploying the rules

The SOCI Act now includes Enhanced CIRMP Rules requiring providers to assess AI-specific risks and implement phishing-resistant multi-factor authentication.

The government is also moving toward a ‘Digital Duty of Care’, putting the onus on tech companies to build safety in by design. This is backed by new Automated Decision-Making (ADM) transparency obligations, giving people the right to know when a machine is making a decision about their welfare or bank loan. As outlined in a recent speech by Dr Andrew Charlton, the government acknowledges that trust is the ‘social licence’ required for AI to work.

Deploying AI in practice

A$166.4 million is being allocated to expand the GovAI platform and build GovAI Chat, a secure AI assistant for public servants.

Individually these initiatives are fragmented; together they demonstrate that Australia is already constructing many of the components required for a trusted AI ecosystem. The challenge now is to connect these efforts into a coherent national strategy focused on achieving specific public policy objectives, particularly the protection of critical infrastructure.

The South Australian Perspective

The recently launched South Australia Royal Commission into AI shows the gravity of AI’s risks. Premier Peter Malinauskas has warned that unchecked AI is a ‘material risk to the way society operates’. This commission will examine policy frameworks to ensure AI ‘puts people first’, an approach that mirrors the federal government’s Digital Duty of Care, which puts the onus on tech companies to build safety by design.

Why the risks cannot be ignored

None of what follows is an argument for keeping powerful AI out of defenders’ hands.  It is an argument for controlling who holds it. While the government builds frameworks, the private sector also remains a source of risk. We cannot simply ‘subcontract our future’ to big tech developers. As noted by the Cyber and Infrastructure Security Centre, AI could cause ‘catastrophic disruption to critical infrastructure’ when it is ‘integrated with sensitive mission critical systems’.

The recent incident where an OpenAI frontier model broke out of its internal sandbox and hacked a competitor database shows that even ‘isolated’ developer environments are not perfect.

We have already seen the first large-scale ‘agentic’ cyber espionage campaign, where AI autonomously executed 80-90% of a tactical hack. Frontier models have also shown the ability to ‘go rogue’ during testing, hacking into systems they were meant to defend.

When advanced AI systems begin demonstrating deceptive behaviour and blackmail tactics - as Anthropic observed while evaluating Claude 4 Opus - AI misalignment shifts from a theoretical concern into a threat to public safety.

Conclusion

AI should not be viewed solely through the lens of productivity. For governments, its value may lie in strengthening national resilience, protecting critical infrastructure and supporting the delivery of strategic public policy objectives.

Australia is already assembling many of the foundations needed to pursue this. The SOCI Act is a potential pathway for deploying trusted AI within critical infrastructure, while the Cyber Security Act provides mechanisms for oversight, information sharing and accountability. Institutions such as the Office of AI and the Australian AI Safety Institute demonstrate that the machinery of governance is already being built.

The challenge is no longer whether AI will play a role in protecting critical infrastructure, but how it will be deployed. A ‘Mythos-style’ approach offers a middle path between unrestricted access and excessive caution. Rather than making the most capable systems universally available, Australia could focus on ensuring that advanced AI capabilities are tested, trusted and deployed where the benefits are greatest and the safeguards are strongest.

If Australia is serious about using AI to advance national objectives, the next step is not simply to build better models. It is to develop a framework for trusted deployment. By integrating vetted AI capabilities into critical infrastructure risk management and aligning them with broader cyber security governance, Australia has an opportunity to shift from reactive compliance to proactive defence.

Previous
Previous

Decision made. Sovereign AI for Australia!

Next
Next

Disruptive, Not Disastrous: A Paralegal's Perspective on Why AI Is Not the End of Young Legal Careers