← BACK TO FEED
CISAAnthropiccybersecurityfederal governmentAI policy

CISA Is Quietly Using Anthropic's Mythos to Hunt Bugs in Federal Government Code

CISA is reportedly using Anthropic's AI model, Mythos, to scan federal government code repositories for security vulnerabilities, with sources indicating the effort has already uncovered a large number of software flaws. The initiative is led by CISA's Attack Surface Evaluation team, with the NSA also believed to be utilizing the model. Despite this growing government reliance on Mythos, Anthropic has faced political tensions with the administration over its refusal to remove safeguards against autonomous weapons and surveillance use, and its public-facing model, Fable, experienced a temporary global shutdown following a dispute over foreign access.

The US Cybersecurity and Infrastructure Security Agency has been using Anthropic's Mythos AI model to scan federal government software for security vulnerabilities, Reuters reported this week, citing three people familiar with the programme.

The work is being led by CISA's Attack Surface Evaluation team, a unit that runs digital defence assessments and simulated intrusion exercises across federal systems. According to two sources, the AI-assisted audits have already turned up a 'large number' of software flaws. What kinds of flaws, how severe, which agencies were affected, how much code was reviewed: none of that has been disclosed. Anthropic and CISA both declined to comment on record.

The NSA is also believed to be using Mythos internally. Last month, a US official separately told the Associated Press that an Anthropic model had identified vulnerabilities in highly sensitive government systems during a testing exercise. So the pattern here is fairly clear, even if the details remain classified.

All of this is happening against a notably fractious political backdrop. Anthropic earlier this year refused administration demands to strip out safety restrictions preventing its models from being used for autonomous weapons or domestic surveillance. The Pentagon's response was to classify Anthropic as a supply-chain risk, a designation normally reserved for foreign firms suspected of spying. Awkward, given that the intelligence community appears to be happily running the company's models on sensitive government infrastructure at the same time.

The public side of Mythos has been equally messy. When Anthropic launched the consumer-facing version of the model in early June under the name Fable, White House concerns about foreign nationals accessing the tool triggered demands to restrict availability. The standoff ended in a temporary global shutdown of Fable, which was only lifted last week.

So the current situation is this: the US government is simultaneously treating Anthropic as a security risk, using its AI to secure federal systems, and periodically shutting down its public products over national security concerns. Perfectly coherent.

READ NEXT
Anthropic Plans Public Release of Mythos Bug-Hunter, Admits Nobody Has the Safeguards to Do It YetAnthropic's Claude Mythos Is Finding Bugs Faster Than Anyone Can Fix ThemFlagged as a Pentagon Supply Chain Risk, Anthropic Is Probably Getting the NSA Contract Anyway