Skip to Content

The Device Update Imperative: Legal Obligations of Technology Manufacturers Prior to the Public Deployment of Claude Mythos and the Regulatory Framework Governing Legacy Device Compatibility

The Device Update Imperative: Legal Obligations of Technology Manufacturers Prior to the Public Deployment of Claude Mythos and the Regulatory Framework Governing Legacy Device Compatibility

I. Background and Factual Context

On April 7, 2026, Anthropic announced “Claude Mythos Preview,” described as a new class of intelligence built for ambitious projects focusing on cybersecurity, autonomous coding, and long-running agents.  However, this announcement came with a notable legal and commercial caveat. Anthropic explicitly stated it will not make Claude Mythos Preview generally available due to cybersecurity risks, instead releasing it through Project Glasswing, which brings together major technology companies including Amazon, Apple, Google, Microsoft, and Nvidia for defensive cybersecurity work exclusively. 

Anthropic has stated directly: it does not plan to make Claude Mythos Preview generally available, but its eventual goal is to enable users to safely deploy Mythos-class models at scale.  This statement, though prospective, raises an immediate and pressing legal question for the global technology industry, including device manufacturers operating in India and across the European Union: prior to any future public deployment of a system of this class, what are the pre-existing obligations of manufacturers to ensure that consumer devices, whether old or new, Android, macOS, or Windows, are adequately prepared to safely and lawfully receive and operate such systems?

The answer is not merely technical. It is, in large measure, a legal obligation arising from data protection legislation, product safety regulation, and emerging AI governance frameworks.

II. The Foundational Question: Do Manufacturers Owe Existing Customers an Update?
The short answer is yes, under applicable law, and the obligation is more demanding than many manufacturers have historically acknowledged. The deployment of an AI system of the capability class represented by Claude Mythos onto a device that has not received appropriate security patches, compatibility updates, or data processing safeguards would expose both the manufacturer and the deployer to significant regulatory liability.
This obligation arises from three converging legal frameworks, examined below.

III. India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025
The DPDP Rules, 2025 transform India’s data protection framework, demanding foundational changes in governance, technical operations, and risk management. 
At the core of this framework is a requirement that organisations processing personal data, including those deploying AI systems that interact with users on personal devices, must ensure those systems do not create risks to the rights of data principals. Significant Data Fiduciaries must ensure that any technical systems they deploy, including algorithmic tools used for hosting, displaying, uploading, modifying, publishing, transmitting, storing, updating, or sharing personal data, do not create risks to the rights of Data Principals. This places explicit accountability on organisations using AI-driven or automated data-processing technologies. 
The practical consequence for device manufacturers is substantial. A manufacturer that deploys an AI-integrated application on a device running an outdated operating system, one which lacks the security architecture required to isolate personal data processed by such an application, may be treated as a Data Fiduciary whose technical measures are inadequate. The failure to issue security updates to older devices before deploying AI capabilities would, in such circumstances, constitute a breach of the data security obligations prescribed under the Act.
India’s DPDP Rules, 2025 were notified on November 13, 2025, bringing approximately 800 million internet users in India under the ambit of the privacy law. The Act becomes applicable for all entities and government departments 18 months from notification, being May 13, 2027.  This timeline provides manufacturers a finite window within which to bring their device ecosystems into compliance. The deployment of a Mythos-class AI system on Indian user devices before the completion of mandatory security updates would, after the May 2027 deadline, constitute a cognizable failure under the Act.
Organisations that treat the DPDP Act as merely a privacy-policy exercise will fall short of the required compliance standard. Organisations that treat it as the foundation of broader AI governance and build role clarity, dataset discipline, human oversight, bias controls, provenance safeguards and incident response around it will be better positioned for both present compliance and future regulatory change. 
For manufacturers of Android devices in particular, the update obligation is especially acute. Devices that have reached their manufacturer-declared end-of-support date receive no further security patches. Where such devices are nonetheless used to access AI systems that process personal data, the manufacturer’s decision to discontinue updates while enabling continued AI-integrated service access may constitute a violation of the reasonable safeguards obligation under Section 8(5) of the DPDP Act.

IV. The EU General Product Safety Regulation (GPSR) and AI-Integrated Consumer Devices
The General Product Safety Regulation (Regulation (EU) 2023/988, “GPSR”), which entered into force on June 12, 2023 and became applicable from December 13, 2024, is another AI-specific product safety law in the EU. It aims to address the integration of AI technology into existing product safety frameworks and introduces AI-specific requirements. 
The GPSR introduces a principle of direct relevance to the question of legacy device updates. Modifications to AI-based products can involve changes to software, algorithms, or data processing capabilities, which can have a substantial impact on the product’s behaviour and performance. Third-party software developers, data providers, system integrators, or service providers may be involved in these modifications.  Under the GPSR, where such a modification substantially alters the product’s risk profile, the entity introducing that modification may be treated as the manufacturer for the purpose of safety obligations.
What does this mean in the context of Claude Mythos? When Anthropic or any API partner integrates a Mythos-class model into a consumer-facing application distributed across devices, and the integration substantially upgrades the AI capabilities available on those devices, the question of who bears the obligation to ensure the underlying hardware and operating system are safe for that upgrade becomes a matter of regulatory significance. The GPSR does not permit a manufacturer to disclaim liability simply because the upgrade originates from a third-party software provider.
The obligation, therefore, runs across the value chain. A device manufacturer that ships hardware incapable of safely running a Mythos-class AI workload, without issuing appropriate firmware or OS-level updates, cannot shelter behind the argument that the AI developer bears sole responsibility for unsafe outcomes.

V. The EU Artificial Intelligence Act and General-Purpose AI Obligations
Under the EU AI Act, rules for General-Purpose AI models became applicable on August 2, 2025.  These rules impose transparency, documentation, and risk-mitigation obligations on providers of systems capable of performing a wide range of tasks at scale, which a Mythos-class model unambiguously would be.
General-Purpose AI models that were already on the market before August 2025 must now be fully compliant, with providers of existing AI models required to bring those systems into compliance by August 2027. 
For the purposes of this analysis, the relevant provision is the systemic risk framework. For models that may carry systemic risks, providers must assess and mitigate those risks.  Where a provider seeks to deploy a Mythos-class system to general consumers, the Act would require comprehensive risk assessment that includes the security posture of the devices on which the system will operate. A deployment strategy that ignores the population of legacy devices running end-of-life operating systems would, on its face, fail to satisfy this standard.
There is an important grace period for existing AI models that were already on the market before August 2025: those providers have until August 2, 2027 to bring legacy models and their documentation into full compliance. This two-year transitional window acknowledges that updating already-deployed AI systems takes time.  However, this grace period applies to the AI provider, not to the device manufacturer. The device manufacturer’s obligation to maintain device safety under both the GPSR and the EU AI Act’s product safety integration provisions operates independently and on its own timeline.

VI. Do Companies Release Updates for Old Customers? The Legal Position
This is the operative commercial and legal question. The prevailing industry practice has been that manufacturers provide security updates for a fixed period, typically two to three years for budget Android devices and five to seven years for premium devices or enterprise Windows systems, after which the device is declared end-of-life and updates cease.
This practice is legally sustainable only so long as the device is not being actively used to deploy new services of enhanced risk. The moment a manufacturer, or a partner operating through the manufacturer’s app ecosystem, deploys a service of materially elevated capability on a device that has received no updates, the legal calculus changes. The lack of an update is no longer a passive omission. It becomes an active failure to maintain the safety of a product placed on the market.
Under the DPDP Act, the obligation to maintain reasonable data security safeguards is ongoing and not time-limited by the manufacturer’s internal support calendar. Under the GPSR, the safety of a product is assessed at the time it is in use, not merely at the time it was placed on the market. Under the EU AI Act, the risk assessment framework for GPAI deployment is forward-looking and must account for the deployment environment.
The legal answer to whether companies must release updates for old customers prior to deploying Mythos-class AI is: yes, or they must disable Mythos-class AI functionality on unsupported devices. There is no third option that is legally defensible under the frameworks described above.

VII. Recommendations for Legal Practitioners Advising Technology Clients
Practitioners advising manufacturers, platform operators, or AI deployers should consider the following in the period preceding any public release of Claude Mythos or systems of comparable capability.
First, a device compatibility audit should be conducted at the earliest opportunity. Clients must identify the population of active devices on which AI-integrated services are offered, segment those devices by OS version and security patch level, and assess whether each segment can safely process the personal data flows that a Mythos-class AI system would generate.
Second, clients should be advised that the DPDP Act’s compliance deadline of May 13, 2027 is not a future problem. The architecture required for compliance, including updated privacy notices, breach notification protocols, and algorithmic safeguards, must be built now. Waiting until the deadline to begin implementation will not be treated as a mitigating factor by the Data Protection Board of India.
Third, contracts with AI providers and API partners should be reviewed and revised to allocate responsibility for device-level compliance clearly. The GPSR’s treatment of substantial modification means that an AI integration partner who upgrades device capabilities without the device manufacturer’s prior update may inadvertently expose both parties to shared liability.
Fourth, practitioners should note that Anthropic has confirmed access to Claude Mythos Preview is invitation-only and currently restricted to Project Glasswing partners for defensive cybersecurity purposes.  The window between now and any prospective general release is the appropriate period for manufacturers to discharge the update obligations described in this article. It would be legally imprudent to treat that window as dead time.


VIII. Conclusion
The emergence of Claude Mythos Preview as a category-level advance in AI capability is not merely a product announcement. For legal practitioners advising the technology industry, it is a regulatory trigger. The DPDP Act, the GPSR, and the EU AI Act each impose obligations that, taken together, require device manufacturers to ensure their installed base of consumer hardware is updated and secured before any system of this capability class is deployed to the public.
The question of whether old customers are entitled to updates is therefore not one of commercial generosity. It is a question of legal obligation. Manufacturers that discharge this obligation in advance of a general Mythos-class deployment will be positioned for compliance. Those that do not will face concurrent exposure under three separate legal regimes on two continents.

 

This article is intended for legal professionals and does not constitute legal advice. Applicable obligations vary by jurisdiction, entity type, and the specific nature of data processing activities undertaken.

🔗 Share this post: https://llmadvocates.com/blog/claude-mythos-legal-world

About LLM Advocates

LLM Advocates is a specialized law firm registered with the Punjab & Haryana High Court, focusing on cyber law, AI governance, data privacy, and technology-related legal services. Our advocates hold LLM degrees in Cyber Law and are ISO 42001:2023 Certified Lead Auditors.

Meet Our Advocates →
Bot Avatar

LLMbot

Online