National Cyber Director Yoichi Iida told Kyodo the June 2026 U.S. suspension of Anthropic's Claude Mythos showed Japan's cyber defenses cannot depend on any single AI model.
Japan's cyber chief says AI-driven defense is "inevitable." The more telling line is the one about not trusting any single model, because in June, another government showed the switch can be pulled.
National Cyber Director Yoichi Iida told Kyodo News that frontier AI is now a structural input into how Japan plans to defend itself online, and the lesson from June is that the frontier itself is a dependency that can be turned off. Under Prime Minister Sanae Takaichi, the cabinet decided in March 2026 to let the government take "active cyber defense" measures from Oct. 1, 2026, defined as pre-strike steps to eliminate the possibility of serious cyberattacks on critical infrastructure, economic activity, and people's livelihoods.
The window between a vulnerability being discovered and exploited has collapsed, Iida told Kyodo News, to "a fraction of a hundredth or a thousandth of what it used to be." The premise underneath the policy is that the offense is already running on AI, so a defense that waits for human analysts to triage will arrive after the damage is done.
The model Iida cited is Anthropic's Claude Mythos, a frontier AI system Anthropic unveiled in April 2026 and initially limited to IT companies, including Google, and to certain financial institutions, over concerns about cyber misuse. Anthropic published a red-team preview of the system (Anthropic red-team preview), and the Cloud Security Alliance published an independent analysis of its vulnerability-discovery and containment profile (Cloud Security Alliance analysis). The model's value to a defender is the same as its value to an attacker: it can find security vulnerabilities at machine speed.
In June, a U.S. government export-control directive suspended access to Mythos-class models, Iida said, and the move also disrupted security vulnerability scanning for key Japanese government systems (Kyodo News via Japan Today). The directive's specific legal text and scope have not been independently verified in public reporting, and the U.S. side of the action is described here as Iida characterized it.
Iida told Kyodo News Japan should not rely on any one particular AI model, citing the U.S. suspension as evidence of supply-chain risk. The point, in his framing, is that defensive frontier AI is not a vendor-consolidation question; it is a sovereign-dependency question. If the U.S. government can switch off the model Japan scans with, then the model is part of the threat surface, not part of the perimeter.
Iida declined to specify concrete operational steps. He said the government must "advance automation" while keeping humans in the final decision loop, a position that fits the active-defense vocabulary in the March cabinet decision but does not name which decisions would be automated, which would be human-confirmed, and which would remain human-only. Oct. 1, 2026 is the date the framework takes effect, not the date any specific AI tool goes live in any specific system.
The next test is whether Japan names the alternative model set before October, and whether the diversification principle survives the first time a frontier vendor restricts access to a security customer. Iida's "inevitable" line tells readers the direction of travel. The unanswered question is which frontier model Japan is willing to bet its critical-infrastructure scans on, and what it does when the vendor of that model becomes a geopolitical variable.