US Cybersecurity Agency CISA Deploys Anthropic's Mythos AI to Scan Government Code for Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has begun using Anthropic’s artificial‑intelligence model Mythos to audit federal software code. The agency’s Attack Surface Evaluation team is scanning government code repositories for bugs that could be exploited by foreign intelligence services or cybercriminals, and sources say the audits have already uncovered a large number of vulnerabilities, though details on severity were not provided.
Anthropic’s relationship with the U.S. government has been turbulent. After the company refused to remove safeguards that would permit its AI to be used for autonomous weapons or domestic surveillance, the Pentagon labelled Anthropic a supply‑chain risk—a designation that was later blocked by a federal judge. The National Security Agency has been using Mythos since at least April, and the model’s public version, Fable, was briefly shut down worldwide after the White House demanded a ban on foreign access. The shutdown was lifted last week. Neither CISA nor Anthropic commented further.
The deployment underscores a growing reliance on frontier AI models for cyber‑defense tasks, as U.S. agencies seek faster ways to identify and mitigate software flaws that could be weaponised by state‑backed hackers or criminal groups.