The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is utilizing Anthropic's advanced artificial intelligence model, Mythos, to proactively identify vulnerabilities within federal government code. This initiative aims to detect and address security weaknesses before they can be exploited by malicious actors, including foreign intelligence services and cybercriminal organizations.
Sources familiar with the matter indicated to Reuters that CISA's Attack Surface Evaluation team is running Mythos against government code repositories. This team is responsible for conducting security assessments and simulated attacks across federal agencies. While CISA and Anthropic have not officially commented on the deployment, the agency representative previously stated they would check for information to share but did not respond further.
Reports suggest that the audits conducted using Mythos have already uncovered a significant number of vulnerabilities. However, specific details regarding the scope of these audits, the agencies involved, and the severity of the discovered flaws have not been publicly disclosed.
Mythos is described as Anthropic's most capable AI model, not available through standard subscriptions. When privately released to select government partners, it was characterized as exceptionally proficient at discovering and exploiting security vulnerabilities.
The National Security Agency (NSA) has reportedly been using the same AI model since at least April, with analysts reportedly impressed by its performance in classified testing environments.
This deployment by CISA follows a period of strained relations between Anthropic and the U.S. government. In February, the Pentagon designated Anthropic as a supply-chain security risk after the company refused to remove safeguards that prevented Mythos from being used for autonomous weapons or domestic surveillance. This designation, previously applied only to foreign entities, was blocked by a federal judge in March.
The relationship appears to have thawed following the private release of Mythos. The current deployment by CISA is seen as a significant shift in the dynamic, suggesting that providing government access to the most capable version of the tool has been more impactful than prior negotiations.
Further complicating the situation, Anthropic launched a public version of Mythos called Fable in early June, which included cybersecurity safeguards. The White House subsequently demanded that the company prohibit foreign nationals from using it, leading to a temporary global shutdown of the model. This shutdown was lifted only recently, highlighting differing approaches to private versus public deployments of the same underlying technology.
A U.S. official noted in late June that Mythos had successfully identified vulnerabilities in highly sensitive government systems during a testing exercise, a result that typically encourages agencies to expand such programs.
Separately, testimony before a Senate Intelligence Committee hearing cited by The Economist indicated that Mythos had breached nearly all classified systems managed by the NSA and U.S. Cyber Command within hours. Senator Mark Warner stated that General Joshua Rudd, who leads both agencies, confirmed this penetration, emphasizing the speed of the breach.






