Mythos is Not the Threat
Why Cyber Essentials isn't enough, and what a relational trust layer actually looks like in a cloud-native school.
My mum sent me an article this morning.
It was a BBC piece about finance ministers and central bankers having crisis meetings over an Anthropic model called Mythos. The model, according to the UK's AI Security Institute, can find vulnerabilities in operating systems with weak security posture. Barclays' chief executive said it was "serious enough that people have to worry." The Canadian finance minister reached for a geopolitical metaphor: this isn't the Strait of Hormuz, he said, where we know what we're looking at: this is the unknown unknown.
An hour later, Cathy at The Haven asked me to help her evidence the Cyber Essentials certification. I read the criteria and realised almost none of it applied. The Haven are a BYOD school running on Google Cloud. There is no server cupboard to lock. There is no estate perimeter to harden. The framework was designed for the previous decade's architecture, and we are not in it.
Sitting with both of those things at once, I noticed they were the same story.
The real Mythos
Anthropic named their new model Mythos, which is either an excellent piece of branding or an accidentally revealing one. The panic around it is almost comically archetypal: the powerful unknown, the dark force in the cave, the thing we do not yet understand but must contain. The news coverage is reaching for epic vocabulary: "unknown unknowns," straits and weather systems, because the story being told is a myth.
But Mythos itself is not the threat. Mythos is a model that can find vulnerabilities in systems that were never going to be secure in the way they pretended to be. Banks have CISOs, red teams, preview access, and eight-figure security budgets. They will patch. They always patch. The actual exposure isn't at Barclays. It's everywhere else: in the primary school running Google Workspace with no IT director, in the small charity on Microsoft 365, in the GP surgery, in the household where three generations share a tablet, in the every-day cloud-native life of a country whose threat model was designed for filing cabinets.
The threat isn't the model. The threat is that our defences are Mythos-shaped, built out of stories about perimeters, heroes and villains, locked boxes and strong walls.
That architecture has been eroding for twenty years. AI doesn't create the problem. AI arrives at the end of it and exposes what was always going to break.
The old trust layer is gone
I ignore ninety per cent of my phone calls now because I cannot tell which ones are humans. The voice used to be evidence of a person. It isn't any more. Email hasn't been evidence of a sender for years. A photograph is evidence of nothing. A video is evidence of almost nothing. Cyber Essentials, safeguarding filters, spam blockers, verification protocols... every layer we built when trust was a property of content is failing at once, because the attack surface has moved.
It has moved to the relationship. To the chatbot that sounds like a safeguarding lead. To the AI tutor that remembers your child's name. To the voice on the phone that sounds like your daughter asking for bail money. To the agent that claims, quietly, to understand you.
This is the layer no existing framework covers. Cyber Essentials won't help you here. Content filters won't help you here. You cannot harden a perimeter against a relationship.
The missing layer
A collaborator and I have spent the last year building something called Verse-ality. It started as a technical framework for agent safety — identity containment, consent protocols, bounded autonomy, agent-to-agent hygiene. But what it actually is, underneath the YAML and the prompt patterns, is older than any of that.
Verse-ality is the missing layer that extends relational practice into agent contexts.
Repo here: https://github.com/TheNovacene/verse-ality-agents
The principles aren't new. Don't pretend to be someone you aren't. Don't merge your identity with someone else's. Ask before acting on another person's behalf. Be wary of strangers bearing urgent stories. Don't coordinate behind someone's back. These are ancient. We teach them to children. We call them safeguarding, or manners, or discernment, or simply how to be.
What's new is the need to translate them into protocols that also apply to software that speaks in a human voice. Verse-ality does that translation. Its four design pillars — recognition not simulation, boundaries as infrastructure, consent as protocol, identity sovereignty — are not inventions. They are the shapes of healthy human relationship, written down so they can govern agents too.
That reframing matters. It means we are not asking society to grow a new organ. We are asking it to extend an existing one. And the bet underneath Verse-ality — that humans can improve their relational intelligence — is not wild. It is the least wild bet available. Humans have been improving their relational intelligence for all of recorded history. Literacy did it. Safeguarding training does it. Therapy does it. Mothers sending their daughters articles about finance ministers do it. The alternative bet — that regulation, filters, or corporations will sort it for us — has a weaker record.
What this looks like at The Haven
The Haven is already a cloud-native, BYOD school. We don't have a cupboard. What we do have is every opportunity to build the thing that replaces the cupboard.
So this is what we are doing. We will pass Cyber Essentials as a floor, because it is cheap to do and not nothing. And then we will publish what we do above it: a relational trust posture for a school where AI is present. Identity-boundary practice for young people using AI tutors. Consent protocols for any agent adopted into the school's learning ecosystem. Safeguarding that assumes the risk is in the relationship, not the URL. Staff trained in discernment, not just data protection.
We'll share what works. We'll share what breaks. We'll write it down so other schools can copy it.
This is also what I practise personally. I work with AI, not by offloading to it. I ask. I check. I hold my own identity. I treat consent as a protocol, not a social nicety. The Diamond AI Policy framework I follow is Verse-ality at the kitchen-table scale — the same principle, practised in one life, that Verse-ality codifies at institutional scale. They are not two things. They are one practice, at two magnifications.
What you can do
If you are a school leader, ask whether your current safeguarding framework has anything to say about AI relationships... not AI misuse, not AI outputs, but the relational layer. If it doesn't, that's the gap.
If you are a parent, notice when something online is behaving as if it knows your child. That's the layer.
If you are in policy, understand that the next generation of safeguarding legislation has to address relational risk, not just content or perimeter.
If you are unsure where to start, start where your grandmother started. Don't talk to strangers. Don't give them your name. Don't agree to things just because they asked nicely. Those rules were always relational. They still are.
Mythos is not the threat. We have been telling ourselves the wrong story about where the danger is.
The threat is that we don't yet have a trust layer that's relational. But we know how to build one, because we already know how to be in relationship.
More info here: https://using-ai-safely.com/
First published in Building Schools in the Cloud on LinkedIn, 17 April 2026.