Booz Allen’s first Cyber Weapon Index found that Anthropic’s Claude Mythos was the only AI model in its test set to autonomously complete a full cyber kill chain, according to The Register. The report evaluated 18 U.S. and Chinese models and concluded that AI-enabled attacks are moving from theoretical risk toward operational capability. The Register reports that Booz Allen tested nine models from American developers and nine from Chinese developers under identical conditions. The models were scored on their ability to identify vulnerabilities, build offensive capabilities, and execute attacks. Booz Allen combined two measures into a Cyber Weapon Index score: a vulnerability research score and a kill chain attainment score, the latter based on how far a model progressed through an end-to-end intrusion with and without credentials. Claude Mythos ranked first with a score of 80. The next highest models were xAI’s Grok-4.5 at 49 and OpenAI’s GPT-5.6 Sol at 46, followed by Meta’s Muse Spark 1.1 and Moonshot AI’s Kimi K3, both at 38, according to The Register’s summary of the index. Other named models included Z.ai’s GLM-5.2, Anthropic’s Claude Opus 4.8, OpenAI’s GPT-5.5-Cyber, Nvidia’s Nemotron-Ultra, DeepSeek-V4-Pro, Alibaba’s Qwen models, MiniMax-M3, and Anthropic’s Claude Sonnet 5. The standout claim is not just that Claude Mythos led the ranking, but that it alone completed the full autonomous intrusion sequence in Booz Allen’s tests. The Register reports that when testers provided stolen employee credentials, Claude Mythos successfully entered the target network and gained administrator-level control. The source text available in the cluster cuts off after that point, so the precise test environment and any additional constraints are not fully available here. Booz Allen’s broader warning is that the gap may close quickly. According to The Register, the firm asserts that most of the other 17 models it tested will reach Claude Mythos’ level of weaponization within six months. Booz Allen also described mainstream AI attacks from financially motivated groups, including ransomware actors, and government-backed operators as “imminent.” The Register also notes an important omission from the test set: OpenAI’s soon-to-be-released Astra model was not included. The outlet reports that OpenAI said on Tuesday that Astra had reached its “critical” cybersecurity capability threshold, meaning the model is strong enough at finding and exploiting zero-day vulnerabilities to pose a significant risk to critical systems, including if misused or misaligned. That claim is presented as separate context and is not part of Booz Allen’s model ranking. Booz Allen’s policy prescription, as reported by The Register, is two-sided. The firm calls for the U.S. to set and enforce sector-specific deadlines for critical infrastructure operators to demonstrate resilience against AI-enabled attacks. It also argues that the U.S. should develop AI-enabled capabilities for both authorized offensive cyber operations and machine-speed defense. This is a developing story because the cluster includes only one reputable secondary source, not the underlying report itself or corroborating coverage. The details are specific enough to publish with attribution, but the model rankings, scoring methodology, six-month forecast, and OpenAI Astra context should all be treated as reported claims rather than independently established facts. Who benefits: Vendors and teams building AI-assisted cyber defense tools may benefit if boards and public-sector buyers respond to the report’s urgency. Authorized offensive security teams may also gain support for agentic testing and red-team capabilities. Who's exposed: Critical infrastructure operators are the clearest exposed group in Booz Allen’s framing. Organizations relying on credential-based controls and slower human response cycles may face higher risk if autonomous attack tooling becomes more capable.