A large global bank got early access to a Mythos-class model expecting it to make vulnerability hunting easier. Instead, it surfaced more findings than the security team could act on, work that would normally take twenty separate workflows and a week the team didn’t have. Already running Itential, they turned to two kinds of agents to close the gap: one to reason through the findings and decide what actually needed to change, another to generate the deterministic workflows to make each change safely, fast enough to meet a window no human team could hit alone.
A Mythos-class model surfaced enough vulnerabilities to require roughly 20 workflows inside a one-week remediation window, more than any team could hand-build in time.
Operate agents reasoned through the findings and decided what to fix. Build agents generated the deterministic workflows to fix it, safely, from a plain-language spec.
Roughly 20 governed workflows delivered inside the window, with zero added headcount, on the same execution engine every other change runs through.
In April 2026, Anthropic announced Claude Mythos and Project Glasswing, giving major technology vendors AI-driven vulnerability discovery ahead of general availability. A large financial services institution gained early access to a Mythos-class model in mid-2026, expecting it would help identify security vulnerabilities more efficiently. What it found exceeded expectations, and created an urgent operational challenge.
Within days of deployment, the bank’s security team uncovered a significant number of previously unknown vulnerabilities across their network topology, architecture deployment, and device configurations. The AI model was finding security holes faster than the team could possibly address them. Itential, working with the bank’s team, saw firsthand what that gap looked like in practice: a security team that could suddenly see every hole in its topology, architecture, and configuration, but had neither the time nor the headcount to build the workflows needed to close them.
The remediation requirements were steep. The bank needed to build approximately 20 distinct workflows within a single week to address the most critical vulnerabilities, a cadence consistent with the seven-day remediation windows other Mythos-driven engagements have reported. Its existing orchestration approach worked well for planned changes, but it could not scale to match the velocity and volume of AI-discovered issues.
This is the deployment gap that Anthropic’s Project Glasswing and OpenAI’s Daybreak initiative have opened across the industry. AI finds vulnerabilities in minutes. Most enterprises still take weeks to deploy fixes across a multi-vendor estate. This bank’s experience is a concrete instance of that gap, not an edge case.
Dozens of new vulnerabilities surfaced almost immediately, more than any team could triage manually.
Roughly twenty critical workflows needed to exist within days, not the weeks or months a normal build cycle requires.
Remediation had to span multiple vendors and device types, each with its own workflow logic.
Regulatory scrutiny and board oversight left no room to leave known vulnerabilities unaddressed.
The bank was already an Itential customer, using the platform to orchestrate infrastructure operations. When the new wave of vulnerabilities emerged, the team turned to two distinct agentic capabilities, each doing a different job. They worked in sequence, not in place of one another: the operate agent decided what needed to change, and build agents produced the deterministic workflow to change it.
FlowAgents that decide what needs to change.
Build how to change it, safely with Itential Builder Skills.
FlowAgents that decide what needs to change.
Build how to change it, safely with Itential Builder Skills.
The two capabilities worked in sequence, not in place of one another. The operate agent decided what needed to change. Build agents produced the deterministic workflow to change it safely, and that workflow then executed through the Itential Platform, carrying the same pre-checks, post-checks, and rollback discipline as every other change. What would normally be a week of manual, finding-by-finding, workflow-by-workflow work became a matter of days because both halves of the problem, deciding what to do and building how to do it, moved at agent speed instead of human speed, on top of execution that never stopped being deterministic and governed.
This combination delivered advantages neither capability could have produced alone:
The operate agent triaged dozens of findings against live topology and configuration context in a fraction of the time manual review would take.
Build agents generated each remediation workflow from a plain-language spec instead of an engineer writing it from a blank editor.
The resulting workflows executed across multiple vendors and device types without hand-written logic for each platform.
Every agent and every workflow, however it was built, ran through the platform’s existing pre-checks, post-checks, and audit trail.
The bank ended up with roughly 20 real, reusable, deterministic workflows. Not one opaque agent trying to do everything, and not twenty hand-maintained one-offs either.
The operate agent’s decisions were inspectable before any workflow ran. The team approved what would change rather than trusting a black box.
The team moved fast, and it moved fast in two places at once. Discovery-to-decision time collapsed because an operate agent reasoned through the findings instead of a person working through them one at a time. Decision-to-deployment time collapsed because build agents generated each workflow from a spec instead of an engineer writing it from scratch. What stayed exactly the same underneath both was the platform’s governed execution: every one of those roughly 20 workflows ran with the same pre-checks, post-checks, rollback, and audit trail as any other change on the Itential Platform.
Frontier AI models are changing the pace of vulnerability discovery faster than most security teams can keep up. The discovery itself is not a new problem. Exploiting vulnerabilities is old news. It is simply happening faster now.
That increased speed creates a real gap, and it is a gap with two parts: finding what matters, and building the fix. Traditional automation cannot keep pace with AI-powered discovery, and traditional workflow development cannot keep pace with AI-powered discovery either.
Two different kinds of agents closed both parts of that gap here, and the Itential Platform is what makes both possible on the same foundation. Operate agents, FlowAgents, reason about a live environment and decide what needs to happen. Build agents generate the deterministic workflows that make those decisions safe to execute, directly from a plain-language spec. Both run on top of the same governed execution engine Itential has hardened in production for over a decade, so a workflow carries identical pre-checks, post-checks, rollback, and audit trail whether a human, a build agent, or an operate agent produced or triggered it. That shared foundation, not either kind of agent alone, is what let this bank move at machine speed without losing control of production.
This story is one concrete example of the deployment gap described in Itential’s guide, “Operating at Machine Speed: The Infrastructure Guide to AI-Discovered Vulnerabilities & Continuous Compliance,” which lays out the full operating-model shift across CVE impact analysis, governed remediation, continuous compliance, and certificate lifecycle management. For a deeper take on why the Mythos moment is a call to modernize infrastructure operations, see our blog on “Claude Mythos Is Not the Watershed.”
Contact us to learn how Itential’s build and operate agents can help your organization respond to vulnerabilities at the speed of discovery, not the speed of manual workflow development.