CISA Is Quietly Using Anthropic's Mythos to Hunt Bugs in Federal Government Code
The US Cybersecurity and Infrastructure Security Agency has been using Anthropic's Mythos AI model to scan federal government software for security vulnerabilities, Reuters reported this week, citing three people familiar with the programme.
The work is being led by CISA's Attack Surface Evaluation team, a unit that runs digital defence assessments and simulated intrusion exercises across federal systems. According to two sources, the AI-assisted audits have already turned up a 'large number' of software flaws. What kinds of flaws, how severe, which agencies were affected, how much code was reviewed: none of that has been disclosed. Anthropic and CISA both declined to comment on record.
The NSA is also believed to be using Mythos internally. Last month, a US official separately told the Associated Press that an Anthropic model had identified vulnerabilities in highly sensitive government systems during a testing exercise. So the pattern here is fairly clear, even if the details remain classified.
All of this is happening against a notably fractious political backdrop. Anthropic earlier this year refused administration demands to strip out safety restrictions preventing its models from being used for autonomous weapons or domestic surveillance. The Pentagon's response was to classify Anthropic as a supply-chain risk, a designation normally reserved for foreign firms suspected of spying. Awkward, given that the intelligence community appears to be happily running the company's models on sensitive government infrastructure at the same time.
The public side of Mythos has been equally messy. When Anthropic launched the consumer-facing version of the model in early June under the name Fable, White House concerns about foreign nationals accessing the tool triggered demands to restrict availability. The standoff ended in a temporary global shutdown of Fable, which was only lifted last week.
So the current situation is this: the US government is simultaneously treating Anthropic as a security risk, using its AI to secure federal systems, and periodically shutting down its public products over national security concerns. Perfectly coherent.