Frontier AI security starts with identity

Frontier AI models uncover hidden vulnerabilities. To reach your assets, an attacker still needs either a single compromised credential or standing access left in place.
72.4%
Mythos exploit success rate, unmatched by any human red team
Anthropic, 2026
10,000+
vulnerabilities found by Mythos across real-world systems
Anthropic, 2026
73%
of organizations agree standing access for non-human identities and AI agents raises risk
Delinea 2026 Identity Security Report

What frontier AI means for your attack surface
Frontier AI models, such as Anthropic's Claude Mythos, are the most capable AI systems available.

  • Autonomy is the security event.

    Frontier models find vulnerabilities that survived decades of human review and turn a finding into a working exploit, with no human team behind it.                                                     

  • The exploit window collapsed.

    The time from disclosure to working exploit has dropped from years to hours.

     

  • The risk runs in both directions.

    An attacker's AI still needs a credential or standing access to reach your assets. Your own AI agents introduce a new problem: authorized access doing unauthorized things.

What security leaders should do now

  • Authorize every AI agent action at runtime, not just at connection

  • Eliminate standing privilege with just-in-time access

  • Govern AI agents as privileged identities

  • Broker and scope every credential

Frontier AI security knowledge hub
Explore Delinea research and guidance on frontier AI models, updated as the threat evolves.

  • Preparing for Mythos’ Impact

    The CISO playbook for frontier AI risk: five identity security controls and a four-phase roadmap

    Get the whitepaper
  • Every credential was a read: Dissecting the Hugging Face agent intrusion

    Hugging Face published the actual commands from a 4.5-day autonomous agent intrusion.

    Read the blog post
  • AI agent authorization: Why access at the door is not enough

    Authentication vs authorization: how to govern what an AI agent does after it connects

    Read the blog post
  • Mythos: Five Best Practices for Identity Security Leaders

    How fast can AI find vulnerabilities in your systems? The on-demand session on staying ahead of autonomous attacks.

    Watch the webinar
  • In the Mythos era, identity is the last line of defense

    What attackers do after AI finds the vulnerability, and why credentials are still the prize.

    Read the blog post
  • Mythos: Five Identity Security Best Practices

    The five best practices for securing AI agents in enterprise environments, on one page your team can act on.

    Download the brief
  • Runtime Authorization for AI Agents

    How runtime authorization checks every AI agent action before it runs and records each one under a named identity.

    Get the whitepaper
  • Secure AI with Delinea

    AI agent identity security with Delinea: govern every agent as the privileged identity it already is.

    Learn more
  • What Is Agentic AI Security?

    What is agentic AI security? The plain-language introduction, from definitions to where the risk concentrates.

    Learn more

See how Delinea secures AI

Frontier AI changes how fast attacks move, not what they need: a credential and standing access.
Delinea removes both and authorizes every AI agent action at runtime.
Already a Delinea customer? Ask your account team about enabling just-in-time access under your current license.

Frequently asked questions

What is a frontier AI model?

Frontier AI models are the most capable general-purpose AI systems available at a given time, such as Anthropic's Claude Mythos. In security terms, they enable agentic attacks: discovering vulnerabilities and turning them into working exploits autonomously, work that once took skilled human teams weeks.

If frontier AI can find any vulnerability, why does PAM still matter?

A vulnerability is a way in. Identity security decides what happens next. PAM removes the standing privilege and exposed credentials an agent could inherit. Runtime authorization then evaluates every action against policy the moment it happens, and session recording captures what the agent did inside the session. That combination leaves an agentic attack far less room to operate.

Do AI agents need Privileged Access Management?

Yes, PAM is still a good place to start. AI agents authenticate, hold secrets and can act autonomously. The PAM foundation applies: discovery, brokered credentials and just-in-time access remove the standing privilege and inherited credentials that an agent could abuse. Because agents can act autonomously and behave non-deterministically, they also need runtime authorization to evaluate every action against human-set policy as it happens, plus session recording to prove what the agent did.

What should security leaders do about frontier AI models and the risks they pose?

Start with the controls already proven in production: authorize every AI agent action at runtime and eliminate standing privilege. From there, broker and scope every credential. The whitepaper walks through each control in depth.