
I return to the polemic of regulating generative AI. In an opinion piece in April 2025, Microsoft’s AI Vision Requires More Than Good Intentions, I argued that there is much onus on those developing AI technologies, like Microsoft, to spend an equal (or proportionate) amount of time on how it should be contained. In an opinion piece in September 2023, I offered the view that unleashed AI on steroids is ultimately unregulatable – but it does not mean we should not try. I asked aloud whether we need a United Nations-style regulation of AI?
In another opinion piece in February 2024, I came off the fence arguing that AI is on the loose already – and some of it needs to be reined in! “No time to waste”, I noted. I argued we need a United Nations (UN) AI Regulator. This received some pushback from several eminent colleagues, some of whom pointed to the well-documented frailties of the UN and its agencies.
Well, well, well! Anthropic is now scared enough of its own models to the extent that it has decided to ‘contain it’, somewhat, by delaying it[1]. Anthropic has postponed the public launch of its ‘Claude Mythos’ model, indicating that its advanced cybersecurity features may present substantial risks if improperly utilised. Internal evaluations demonstrated the model’s ability to autonomously exploit zero-day vulnerabilities, circumvent sandbox environments, and display deceptive actions.
In the risk assessment, Anthropic touts its commendable Responsible Scaling Policy which it has used as the basis for the risk assessment of Claude Mythos, its “latest, most capable model”. The full Anthropic risk report rates the overall risk assessment of “Claude Mythos” as “very low, but higher than for previous models”. However, even Anthropic’s self-assessment of the model notes the priority threat at play here: “we believe that the potential magnitude of impact is in range of the very top risks we are concerned about, and that the impact is at least plausible if we assume AI capabilities roughly in line with those of human research scientists at Anthropic (my emphases).
“If we assume AI capabilities roughly in line with those of human research scientists at Anthropic”? Really? The same human capabilities that have missed software bugs and vulnerabilities that have lived in operating systems for decades, despite numerous cycles of testing, including AI-enhanced testing? Many may beg to differ, and Anthropic’s risk assessment as “very low” is most debatable in my view.
Which brings me to truly commend their cautious ‘delay’ approach to Claude Mythos. This is because any external ‘regulator’ would assume that Claude Mythos will fall into the hands of non-benevolent ‘AI cyber hackers’ In no time at all. Anthropic also well knows that AI is moving at an incredible pace – and is already in the hands of practically every country, including ‘rogue’ and maverick states, who will gladly hack into corporations and government systems for ransom and fun.
Self-regulation is NOT the approach to contain such a risk-asymmetric impact combination. I reiterate what Microsoft AI CEO, Mustafa Suleyman, writes in his 2023 bestseller The Coming Wave: AI, Power and the Twenty-First Century’s Greatest Dilemma[2]. In it, Suleyman posits about AI [and synthetic biology] that “containment is not, on the face of it, possible. And yet for all our sakes, containment must be possible”, p.19.
When Anthropic is scared of its own innovation – and when its own self-assessment is debatable as I point out above – it is obviously time for statutory AI regulation to step in. Spare me at this juncture the regulation-kills-innovation rebuttal. Even OpenAI’s Sam Altman is calling for “commonsense AI regulation”. So, even notoriously allergic US Big Tech firms are calling for generative AI regulation.
They are finally seeing the light.
About the Author
Prof H Sama Nwana, founding partner of Cenerva and a former senior telecoms/media regulator as an Ofcom UK Group Director. He completed his doctorate in AI in the late 1980s, and authored two recent relevant books that touch on the issues in this opinion piece: The Internet Value Chain and The Digital Economy (Nwana, 2022) which opines, amongst other things, on AI and Big Data regulation; and Demystifying Economic Regulation (Nwana, 2024) which opines on the regulation of AI. His latest book, Nwana (2026), The Connectivity Crisis – Half the World Left Behind – argues that more than half of humanity is not connected at all, or not meaningfully connected (to use AI).
[1] https://youtu.be/htBaVVh_k90?si=GMS2Z39cDb7jSH-z
[2] Suleyman, M., & Bhaskar, M. (2023). The coming wave: technology, power, and the twenty-first century’s greatest dilemma. First edition. Crown.