An Anthropic artificial intelligence model reportedly identified vulnerabilities in systems of the U.S. National Security Agency (NSA) during an authorized internal security test, according to reporting by Tom's Hardware and coverage in The Economist. U.S. senators were said to have been briefed on the findings.
Political reaction
Senator Mark Warner, vice chair of the Senate Intelligence Committee, was reportedly told by the heads of the NSA and U.S. Cyber Command that the Mythos model had penetrated "almost all of our classified systems, not in weeks but in hours," a claim cited in media reports. The remark circulated widely on social media and was often summarized as "Anthropic hacked the NSA."
Company position and nature of the test
The author of the original story later clarified that the vulnerability emerged in an authorized, internal test conducted in a simulated environment. Anthropic says the experiment was limited in scope: the model was asked to analyze a codebase and suggest fixes. According to the company, that process uncovered a few minor, previously known bugs rather than constituting a real, autonomous intrusion or data-theft event.
Export restriction and immediate consequences
The internal test reportedly occurred one day before the U.S. government ordered Anthropic to suspend access to its most advanced models, Fable 5 and Mythos 5, for all foreign governments, companies and citizens. The Trump administration did not publish a detailed written justification explaining the precise national-security concerns underlying the restriction.
Axios, citing a government official, reported that the decision was partly influenced by a claim from another company that it could compromise Mythos, posing a national-security risk. Anthropic says it received only verbal notice indicating the issue involved a "limited-scope, non-universal" method by which Fable 5 could be induced to identify software vulnerabilities, and that similar behavior could be seen in rival models as well.
Tensions between government and company
Tensions between Anthropic and the Trump administration had eased somewhat before the export restriction but later deteriorated after the company refused to allow the U.S. military to use its models for domestic surveillance and fully autonomous weapons. As a result, the Pentagon officially blacklisted Anthropic, although the NSA reportedly continues to use some Anthropic technology.
Legal response
Anthropic has said it will pursue legal action against the sanctions. The company maintains it did not receive a detailed written rationale for the export controls and argues that enforcing restrictions on the basis of citizenship raises practical challenges.
Why this matters
The episode highlights how quickly AI tools can surface security weaknesses and how such findings can trigger government regulatory responses. It also raises questions about balancing restrictions intended to mitigate national-security risks with the realities of global access and commercial operations for advanced AI systems.



