CISA Uses Anthropic's Mythos to Hunt Bugs in US Government Code
WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic's advanced AI model Mythos to audit government software, three sources familiar with the matter told Reuters — the latest sign of government enthusiasm for the AI startup's tools even as the company navigates an ongoing standoff with the White House.
Scanning for Vulnerabilities
CISA's Attack Surface Evaluation team is using Mythos to scan government code repositories for bugs that could leave the door open for foreign spies and cybercriminals, the sources said. The audits have already uncovered a large number of vulnerabilities, two of the sources confirmed, though the nature and severity of the bugs discovered remain undisclosed.
A Rocky Relationship
Anthropic's relationship with the U.S. government has been tumultuous. In February, the Pentagon slapped the company with a formal supply-chain risk designation — a label typically reserved for foreign firms suspected of espionage — after Anthropic refused to remove safeguards preventing its AI from being used for autonomous weapons or domestic surveillance.
A judge blocked the blacklisting in March, and tensions have since eased following the private release of Mythos, described as exceptionally capable at finding and exploiting cybersecurity vulnerabilities. The National Security Agency (NSA) has reportedly been using Mythos since April, despite the blacklist, and NSA analysts came away impressed with its capabilities in classified settings.
The Fable Controversy
When Anthropic rolled out a public version of Mythos called Fable — which included cybersecurity safeguards — the White House demanded the company ban foreigners from running it. This triggered a global shutdown of the model that was only lifted last week.
Broader Implications
The CISA deployment represents a significant milestone: the U.S. government's primary cyber defense agency now relies on the very AI model it had previously tried to blacklist. It underscores the growing dependency of national security infrastructure on cutting-edge AI — and the increasingly blurred lines between regulation and necessity in the age of autonomous cyber threats.




