This month, Australia was granted access to one of the most capable AI systems ever built. The new AI model, Claude Mythos Preview, is a model that Anthropic has deliberately kept out of public hands because of its potential for harm.
That’s worth sitting with for a moment. Not because the access itself is alarming, but because of what the restriction tells us. When a leading AI company decides a model is too dangerous for general release, and when Australia’s own cybersecurity agency endorses that decision, the underlying logic extends well beyond government systems. It applies to every organisation already running AI.
Most professional services firms aren’t paying attention to that logic. They should be.
What actually happened this week — and why it matters beyond the headline?
On Wednesday, Anthropic expanded its “Project Glasswing” program to approximately 150 additional organisations across 15 countries, including the Australian government and a number of Australian private companies. The model in question, Claude Mythos Preview, had previously only been available to the UK and US governments and around 50 American companies.

The reason for the restriction is specific: Mythos is capable of identifying software and network flaws at a level that poses a significant cybersecurity risk if it falls into the wrong hands. Anthropic’s position is that this capability requires careful, vetted deployment, not open access.
The Australian Signals Directorate (ASD) welcomed the expansion, signalling government-level alignment with the principle that powerful AI tools require controlled deployment. Anthropic’s own statement noted that new Project Glasswing partners share one thing in common: “a successful attack on their code base could be catastrophic.”
The headline story is about Australia gaining access. But the more important story is about the reasoning behind the restriction, and what that reasoning implies for organisations nowhere near the Mythos program.
Does a national-level restriction have anything to do with your business?
On the surface, no. Your business isn’t running a frontier AI model capable of identifying zero-day vulnerabilities. You’re using tools like ChatGPT, Microsoft Copilot, or one of dozens of AI-assisted research, drafting, or document management products that have become part of everyday work.
But the category of risk that triggered the Mythos restriction — AI tools with access to sensitive systems, data, and workflows, deployed without adequate oversight — is exactly the category that applies to how most professional services firms are using AI right now.
Consider what’s actually happening inside the typical accounting, legal, or financial planning firm today. Staff are using AI assistants to draft client correspondence. They’re uploading documents to summarise contracts, tax positions, or financial statements.
They’re running queries through publicly available tools with no visibility into how that data is stored, processed, or used for model training.
Some of this formally approved. Most of it isn’t.
The Mythos restriction exists because capability without governance creates risk. That principle doesn’t stop applying at the frontier. It applies at every point where AI is processing information that matters.
What does “shadow AI” actually look like inside a professional services firm?
Shadow AI is unsanctioned AI tool use. This is staff adopting and using AI products that haven’t been reviewed, approved, or integrated into the firm’s risk and compliance framework. In professional services, it tends to look like this:
- A senior associate uses a free-tier AI tool to summarise a client file because it saves two hours.
- A partner dictates notes into a voice-to-text AI product during a client meeting.
- An admin assistant uses an AI writing tool to draft engagement letters, pasting in client details to give it context.
- A graduate uses a public AI model to research regulatory positions, not knowing that the model’s training data or outputs may be unreliable.
None of these actions are malicious. Most of them genuinely well-intentioned.
But every one of them represents a data exposure, a client confidentiality risk, or a professional obligation that the firm has no visibility over.
For firms operating under the Privacy Act, the Australian Privacy Principles, AFSL obligations, the TPB Code of Professional Conduct, or CAANZ and CPA Australia standards, that lack of visibility isn’t just an internal management issue. It’s a potential compliance breach. The Privacy Act’s Notifiable Data Breaches scheme requires disclosure when sensitive information is likely to result in serious harm. Feeding client data into an unvetted AI tool, even inadvertently, can trigger exactly that exposure.
Most firms don’t know what their staff are running. That’s the shadow AI problem.

What governance are firms required to have in place, and when?
The regulatory clock is moving faster than most firms realise.
The December 2026 reforms to the Privacy Act introduce mandatory automated decision-making transparency obligations. Where AI is involved in decisions that affect individuals — and in professional services, that line is crossed more often than firms acknowledge — firms will be required to disclose that involvement and, in some cases, explain the basis on which automated processes reached a conclusion.
That’s a concrete obligation with a hard deadline. From 10 December 2026, firms covered by the Privacy Act will be required to update their privacy policies to disclose where automated decision-making is used in ways that could significantly affect an individual’s rights or interests. This disclosure includes what personal information feeds into those processes and what kinds of decisions they inform. Meeting that disclosure obligation assumes a level of internal AI visibility that most firms currently lack. You can’t disclose how AI is used in client-affecting decisions if you don’t have a clear picture of where AI is involved in those decisions in the first place.
Beyond the Privacy Act, ASIC’s REP 798 went further than a routine flag — it warned financial services and credit licensees directly that they are adopting AI faster than they are updating their risk and compliance frameworks, and that this lag creates a real risk of consumer harm. The TPB has put AI use on the radar for registered tax practitioners. For legal practices, the Law Council of Australia has been explicit that professional duty obligations — including duties of competence and confidentiality — apply fully in AI-assisted work.
The common thread across all of these is the same: regulators are not waiting for firms to self-organise. They are defining expectations now, and enforcement will follow.
The firms that will be best positioned aren’t the ones that react to the first enforcement action. They’re firms that implement AI governance before they’re tested.
If you’re already using AI, where do you actually start with AI governance?
The most common question I hear from partners at professional services firms is some version of: “We know we should be doing something about this, but we don’t know where to begin.”
The starting point isn’t a policy document or an ISO certification. It’s a clear picture of what’s actually happening inside the firm right now.
That means answering the following questions honestly:
What AI tools are your staff currently using?
Not just the ones IT has approved, all of them. Consider:
- The tools people have downloaded on their own,
- the third-party integrations embedded in the software you’re already paying for,
- the consumer apps used when the approved tools feel slow or limited.
What data is passing through those tools?
Client names, matter details, financial positions, medical information, legal privilege material.
The information your staff feed into AI tools to make them useful is often your most sensitive professional obligation.
What does your firm’s liability exposure look like if something goes wrong?
Not in the abstract, but specifically: if a staff member’s use of an unsanctioned AI tool resulted in a client data breach, what’s the notification obligation?
What’s the professional conduct exposure?
What’s the reputational consequence?
—
Most firms that work through those three questions discover that their AI adoption has outpaced their governance infrastructure.
That gap is what a governance assessment is designed to map, and what an implementation framework is designed to close.
The Anthropic news this week is significant, but not primarily because of what it says about frontier AI. It’s significant because of the gap revealed between AI use and the existence of AI governance.
Australia’s cybersecurity agency endorsed Anthropic’s decision to restrict access to a powerful model because capability without oversight creates risk. That’s a principle that applies to every organisation using AI today, including yours.
The question isn’t whether your firm needs AI governance. The question is how far behind the eight ball you want to be when the first regulatory test arrives.