The Indian government is prioritizing access to Mythos, an advanced AI model developed by Anthropic, for detecting software vulnerabilities.
IT Secretary S Krishnan stated that negotiations are underway with the U.S. and relevant companies to secure access to Mythos and similar frontier AI models.
In the interim, the Indian Computer Emergency Response Team (CERT-In) has established a "sandbox" using alternative AI models with 60-70% of Mythos's capabilities to identify and fix vulnerabilities.
The government emphasizes the need for on-premises deployment for highly sensitive code, rather than relying on overseas cloud services.
Detailed Insights:
Mythos, formally known as Claude Mythos Preview, is an AI model designed for autonomous security research, capable of finding and exploiting zero-day vulnerabilities.
This advanced AI can reason over source code, form hypotheses about exploitable conditions, and generate working proof-of-concept exploits.
Anthropic launched Project Glasswing to deploy Mythos defensively, partnering with various technology companies to find and patch security flaws in critical software.
The Indian government's pursuit of such models aligns with its broader National Strategy for Artificial Intelligence, developed by NITI Aayog, which aims to position India as a global AI leader.
This strategy focuses on leveraging AI for economic growth, improving social outcomes, and addressing national challenges across sectors like healthcare, agriculture, and education.
The use of alternative AI models in a sandbox environment by CERT-In allows for continuous testing and development of secure workflows while formal access to Mythos is being negotiated.
Key Concepts Involved:
Artificial Intelligence (AI): The simulation of human intelligence processes by machines, especially computer systems.
Frontier AI Models: The most advanced and capable AI systems currently available, often characterized by their large scale and broad applicability.
Zero-day Vulnerability: A software flaw unknown to the vendor, for which no patch exists, making it highly exploitable by attackers.
Sandbox Environment: An isolated testing environment that enables users to run programs or open files without affecting the application, system, or platform on which they run.