Safety

CISA used Anthropic’s Mythos to scan U.S. government code, sources say

The U.S.

CISA used Anthropic’s Mythos to scan U.S. government code, sources say

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been using Anthropic’s AI model Mythos to review government software and code repositories, three people familiar with the matter told Reuters. The aim of the inspections is to find defects that could open attack paths for foreign intelligence services or cybercriminals.

The reviews are being carried out by CISA’s attack-surface assessment team, which conducts digital security evaluations and simulated attacks across the government. Two sources said the scans have already uncovered multiple vulnerabilities, but they did not provide details: it is unclear how much government code was inspected or the types and severity of the flaws found.

Neither Anthropic nor CISA responded to requests for comment.

Background: strained relations with the U.S. government

Anthropic’s relationship with the U.S. government has been tense. In February last year the company refused to remove safety constraints that would have prevented its models from being used in autonomous weapons or for domestic surveillance. As a result, the Department of Defense designated Anthropic as a supply-chain risk—a designation previously used mainly against foreign companies suspected of espionage.

A judge suspended that extraordinary placement in March, and tensions eased after Anthropic released a closed version of Mythos; reports suggest the model has been highly effective at finding and exploiting security weaknesses. According to the sources, the National Security Agency (NSA) used Mythos in April despite the blacklist: its analysts tested the model in a secure, closed environment and found its capabilities impressive.

When Anthropic released a public version called Mythos Fable with cybersecurity safeguards, the White House at one point demanded that access be blocked for foreign users. That request led to a global shutdown of the model, which sources say was only lifted last week.

Why it matters

CISA’s use of a third-party advanced language model highlights that federal agencies are willing to deploy external AI tools to strengthen cybersecurity, even when the vendor’s relationship with the government has been fraught. At the same time, the lack of public detail about the number, nature, and severity of discovered vulnerabilities limits public understanding of the extent of risk reduction achieved.

According to Reuters, the review is ongoing and observers are awaiting responses from CISA and Anthropic.