2026 will have been the year offensive security turned into a race for the headlines. On one side, Mythos, Anthropic's model presented as capable of uncovering thousands of critical vulnerabilities across every major operating system, with claims that sound almost unbelievable, such as remote root access on FreeBSD1 or rumors of a full NSA compromise in a matter of hours2. On the other side, OpenAI, which on 26 June revealed GPT-5.6 Sol, billed as its most powerful model for cybersecurity. Between the two, spectacular leaks keep alive the myth of offensive capabilities able to bring any system to its knees.
This progression is all the more striking because, until only a few months ago, artificial intelligence applied to offensive work was a mere extension of human capabilities. Writing a phishing email, developing an exploit, it let a rank beginner mount effective attacks by acting as a personalized assistant. With the rise of agentic AI, the assistant AI is promoted to the role of operator and even orchestrator.
From its arrival in April, Mythos was reserved for a closed circle, 11 founding partners and 40 hand-picked organizations, gathered under the banner of Project Glasswing alongside giants such as Amazon Web Services, Apple, Google, Microsoft, NVIDIA and the Linux Foundation3, around a single watchword, securing the most critical software in the age of AI. Europeans, for their part, were not invited.
The question then becomes: can we do without Mythos and GPT-5.6? The gap between a frontier model, the most advanced of the moment and reachable only through its maker's API, and an open-weight model, whose parameters you download to run yourself, is no longer measured in years but in months. Roughly four on average, according to the Epoch Capabilities Index4. While Mythos was being blocked, frontier-grade open-weight models such as GLM-5.2 or DeepSeek V4 were arriving.
Moreover, because these weights are open, the community turns out so-called abliterated5 versions, freed from their guardrails by manual or automatic ablation techniques that neutralize the model's refusal mechanism. Where a closed model would refuse to write an exploit or analyze a piece of malware, its abliterated variant carries out the request more readily, which makes it valuable for legitimate offensive research. That said, it is better to keep in mind that it also tends to hallucinate more. For the European pentester kept away from Mythos, the stakes shift. Reaching the “ultimate weapon” matters less than knowing how to wield, on infrastructure under your control, the agentic capability already within reach.
Anatomy of a local agent
Let us start by making one distinction: an agent is not a chatbot. A chatbot is a language model, an AI trained to predict the most plausible continuation of a text, which answers once and then stops. An agent is that same model augmented with three faculties, tools it can trigger, a loop (think, run a tool, read the result, start over) and a memory. Where the assistant answers, the agent pursues a goal across several steps. The simplest way to think of a local agent is as a tireless teammate: fast, reliable, and capable of handling the thankless tasks, while you remain in command of the mission.
The word local is important. In pentesting, running the model on your own infrastructure rather than through a provider's API answers two imperatives. First the risk of leakage, since a client's code, addresses, credentials and findings have no business passing through a third-party service. Then sovereignty, since a proprietary model hosted abroad can be cut off from you overnight, as the abrupt withdrawal of Mythos by the U.S. administration showed, whereas models downloaded locally stay in your hands.
The stack comes down to a few building blocks. An inference engine, the software that runs the model on the machine, such as Ollama, vLLM or llama.cpp. An open-weight model, which can be downloaded and run entirely on your own machine. An agent framework such as Strix6, which orchestrates the think-act loop. The pentesting tools, nmap, ffuf, nuclei, Burp or Ghidra, exposed to the agent through MCP, a standard protocol that acts as a universal socket between the model and the tools. Finally, a knowledge base queried through search (RAG), a store from which the agent retrieves past findings, CVEs and reports to feed into its reasoning, which turns a generic model into a domain specialist.
The end of the hardware lock
Memory capacity and bandwidth are what really decide, far more than raw compute power. To run a model you have to store its weights somewhere, and it is the available memory that caps the size of the model you can run. The break comes from unified memory, where the CPU and GPU share one large pool of memory, vast and relatively fast, instead of being confined to a cramped and expensive VRAM. A unified-memory workstation today offers anywhere from 128 to over 500 GB accessible to the model for a few thousand euros7, enough to run locally the kinds of models that only prohibitively expensive servers could handle yesterday. What once demanded an enterprise cloud budget now fits on a machine sitting under the desk.
The human & AI collaboration model
An AI-assisted pentest rests on a simple rule, the agent proposes, the human decides. A real shift in the trade is under way. The pentester stops being the craftsman who makes every move, launches the scan, writes each payload, and becomes a manager of agents to whom the tedious and repetitive tasks are handed off. The pentester's time ends up split between orchestrating and focusing on high-value tasks.
This shift does not erase expertise. A manager unable to spot a false finding would sign off on flawed reports and lose all credibility. The craftsman pentester knew how to do the work, and the new manager pentester knows how to have it done, keeping enough of the craft to tell a genuine result from a well-dressed false positive.
Keeping a human in the loop is less a matter of caution than of technical constraint, for two reasons. First, hallucination. The model asserts a nonexistent flaw with the same confidence it shows when it is right. It is not seeking the truth, it is seeking to close out its task. Then, non-determinism. For an identical input, the output varies, even with the model's temperature set to zero. Yet reproducibility is the bedrock of any proof, because what cannot be replayed has not been demonstrated.
A useful way to think about this human-AI collaboration is in terms of levels of autonomy, without treating it as a formal standard. First, the AI suggests and the human executes. Secondly, it acts but asks for approval before any sensitive action. Thirdly, it runs through an entire phase within a defined scope, typically reconnaissance and triage, subject to human validation. Finally, full autonomy but it remains the risky exception.
One risk is specific to agents, their very autonomy. An agent given too much freedom can step outside the scope and scan an unauthorized address, turning the mission into an incident8. More insidiously, it processes untrusted content, banners, web pages, files, without distinguishing the data it analyzes from the instructions it executes, so a target that knows it is being audited can hide instructions there that hijack the agent, an indirect prompt injection. Guardrails must then be imposed. The human defines not only what the agent discovers but also what it is allowed to do.
The mission
So where does the agent fit into a typical pentest, reconnaissance, enumeration, vulnerability analysis, exploitation, post-exploitation, reporting?
On reconnaissance and enumeration, the gain is immediate and the risk manageable. The agent digests large volumes, drives the scanners, reads their output and decides what to explore next. This is where the agentic loop truly comes into its own.
On vulnerability analysis, it sorts the results, clears out a share of the false positives, matches services to known CVEs, and ranks the flaws most worth exploiting while flagging whether their exploitation prerequisites are met.
Exploitation is the tricky point. The agent can adapt a PoC to the target, but the human keeps control, because the risk of breaking a production system or straying outside the legal frame is too heavy to delegate to the machine.
Post-exploitation again benefits from the agent, first for internal reconnaissance, spotting misconfigurations and lateral-movement paths, then for the loot, extracting and sorting the relevant information once access is obtained.
As for reporting, this is where the time saving is biggest, as long as you keep two layers apart. The technical part delegates without difficulty, writing up the finding, CVSS scoring, generic remediation, consistency of style. The part that calls for judgment resists, real impact on the client's business, prioritization against their exposure, feasibility of the fix in their environment, executive summary.
Has the timeline changed?
First, the task compresses. Reconnaissance, enumeration, triage and write-up often make up half of a classic engagement. By shrinking them, the agent does not shorten the window that was sold, it shifts a larger part of it toward high-value work, complex exploitation, business logic, the chaining of flaws. Then, parallelism drives up the volume handled. The agent enumerates and sorts several targets at once while the human reviews, and coverage per mission rises. For the expert, AI brings speed of execution rather than skill and drops to a few hours what used to take weeks.
The real turning point is here, the move from the point-in-time snapshot to continuous testing. A classic pentest is a snapshot, to be reproduced as soon as the environment changes. Since the agent collapses the marginal cost of a scan-triage cycle, one can then leave the annual engagement behind for continuous models, whether the CART (Continuous Automated Red Teaming, an offensive simulation replayed on a loop and automated), the BAS (Breach and Attack Simulation, the simulation of known flaws to probe the defenses), or the PTaaS (Pentest as a Service, penetration testing delivered as a standing service rather than a one-off engagement). At the same time, reproducing an n-day, meaning a vulnerability that is known and fixed upstream but not yet patched on the target, becomes a matter of minutes, matching an exploitation window (the Time-to-Exploit) now measured in hours.
What it brings to the pentester and the client
For the pentester, the agent speeds up reconnaissance, enumeration and triage, leaving more time for exploitation.
For the client, the benefit is tangible, more coverage per billed day, faster reporting that shortens the time to remediation and therefore the window of exposure.
Decision-making remains the auditor’s prerogative
The machine now knows how to aim, it can also fire on its own, but it still does not know whether the shot should be taken.
The right question is therefore no longer whether AI will replace the pentester. It is deciding, mission after mission, at what level of autonomy to let it operate, and keeping control where judgment cannot be delegated.
Sources
- Foster Nethercott, « Agentic AI: The Weapon That No Longer Needs a Warrior », The Hacker News, 23 juin 2026 : https://thehackernews.com/2026/06/agentic-ai-weapon-that-no-longer-needs.html
- Patrick Ventuzelo (FuzzingLabs), « Pas besoin d'être un Mythos pour faire de l'offensif », keynote, leHACK 2026, Paris, juin 2026.
- « Souveraineté numérique : après Mythos, GPT-5.6d'OpenAI se voit déjà restreint par les États-Unis avant même sa sortie »,L'Usine Digitale, 26 juin 2026 : https://www.usine-digitale.fr/intelligence-artificielle/openai/souverainete-numerique-apres-mythos-gpt-56-dopenai-se-voit-deja-restreint-par-les-etats-unis-avant-meme-sa-sortie.4LPXLHK4CRA2XJBO5KZE4QCSTY.html
- Korben, « Heretic - Virer la censure d'une IA enune commande », korben.info, 26 mai 2026. https://korben.info/heretic-decensure-modeles-ia.html
- Daniel Stenberg, « Mythos finds acurl vulnerability », daniel.haxx.se, 11 mai 2026 : https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/.
- Jack Edwards et Luke Emberson, «Open models lag state-of-the-art closed models by 4 months », Epoch AI, 29 mai2026 : https://epoch.ai/data-insights/open-closed-eci-gap
- Anthropic, « Claude Mythos Preview », anthropic.com, avril 2026 : https://www.anthropic.com/research/mythos-preview.
- « Non, l’IA Mythos d’Anthropic n’a pas piraté la NSA, voici ce qui s’est vraiment passé », Frandroid, 2026 : https://www.frandroid.com/culture-tech/3153725_non-lia-mythos-danthropic-na-pas-pirate-la-nsa-voici-ce-qui-sest-vraiment-passe.
- Anthropic, « Project Glasswing », anthropic.com, avril 2026 : https://www.anthropic.com/glasswing.
- Usestrix, Strix: https://github.com/usestrix/strix.
- Hugging Face, « Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident. » Hugging Face Blog, 28 juillet 2026 : https://huggingface.co/blog/agent-intrusion-technical-timeline.
Footnotes
1. https://www.anthropic.com/research/mythos-preview?utm_source=tldrai
3. https://www.anthropic.com/glasswing
4. https://epoch.ai/data-insights/open-closed-eci-gap
5. https://korben.info/heretic-decensure-modeles-ia.html
6. https://github.com/usestrix/strix
7. https://julsimon.medium.com/what-to-buy-for-local-llms-april-2026-a4946a381a6a
8. https://huggingface.co/blog/agent-intrusion-technical-timeline






