U.S. Cyber Agency Deploys Anthropic’s Mythos Tool to Review Government Code, Sources Say

0
37

Key Takeaways

  • The Cybersecurity and Infrastructure Security Agency (CISA) is deploying Anthropic’s AI model Mythos to scan government code repositories for vulnerabilities that could be exploited by foreign spies or cybercriminals.
  • CISA’s Attack Surface Evaluation team is conducting the audits, which have already uncovered a large number of bugs, though specifics on volume and severity remain undisclosed.
  • Despite a tumultuous relationship with the U.S. government—highlighted by a Pentagon supply‑chain risk designation in February—Anthropic’s Mythos has been quietly adopted by other agencies, notably the National Security Agency (NSA), which began testing the model as early as April.
  • The White House intervened after Anthropic released a public version of Mythos called Fable, demanding restrictions on foreign users; this triggered a temporary global shutdown of the model that was lifted only last week.
  • The episode underscores both the growing appetite within federal circles for advanced AI‑driven cybersecurity tools and the ongoing tensions over AI safety, export controls, and national‑security concerns.

CISA’s Use of Mythos for Government Code Audits
The Cybersecurity and Infrastructure Security Agency (CISA) has begun employing Anthropic’s AI model Mythos to automate the review of government software repositories. According to three sources familiar with the initiative, Mythos scans code for bugs that could serve as entry points for foreign intelligence services or cybercriminals. The effort is being led by CISA’s Attack Surface Evaluation team, a unit tasked with performing digital security assessments and conducting controlled hacking exercises across federal networks. While the sources confirmed that the audits have already revealed a substantial number of vulnerabilities, they declined to detail the exact quantity, nature, or severity of the flaws uncovered. Reuters was unable to verify how much of the government’s codebase has been processed or whether any critical patches have resulted from the findings.

Anthropic’s Mythos Model and Its Capabilities
Mythos is positioned by Anthropic as a highly capable large‑language model optimized for cybersecurity tasks, particularly the detection and exploitation of software weaknesses. Unlike general‑purpose chatbots, Mythos is fine‑tuned to understand code semantics, recognize common vulnerability patterns, and suggest remediation steps. Its strength lies in processing vast repositories quickly, flagging subtle logic errors that might elude manual review. The model’s deployment by CISA signals confidence in its ability to augment traditional static analysis tools and penetration‑testing workflows, potentially reducing the time required to secure critical government applications.

The Rocky History Between Anthropic and the U.S. Government
Anthropic’s relationship with federal authorities has been fraught. In February, the company refused to lift safeguards that prevented its AI from being used for autonomous weapons or domestic surveillance. In response, the Pentagon issued a formal supply‑chain risk designation—a label normally reserved for foreign firms suspected of enabling espionage—to Anthropic. The designation would have barred the company from receiving federal contracts and restricted its access to certain government data. A federal judge blocked the blacklisting in March, citing procedural concerns, which allowed tensions to ease somewhat. Nevertheless, the episode highlighted the government’s wariness about AI systems that could be repurposed for harmful applications.

NSA’s Early Adoption Despite the Blacklist
Even as the Pentagon’s sanction loomed, the National Security Agency (NSA) began experimenting with Mythos. Reports from Axios and later the New York Times indicated that NSA analysts had been testing the model in classified environments since at least April. Analysts reportedly praised Mythos’s proficiency at uncovering deep‑seated vulnerabilities and generating exploit prototypes, which could be valuable for both defensive and offensive cyber operations. The NSA’s use demonstrates that, despite official reservations, certain intelligence components see substantial operational value in Anthropic’s technology.

The White House’s Intervention Over Fable
Anthropic later released a public variant of Mythos dubbed Fable, which incorporated additional cybersecurity safeguards intended to mitigate misuse. Shortly after the launch, the White House abruptly demanded that Anthropic prohibit foreigners from running Fable. This directive triggered a global shutdown of the model, affecting users worldwide who relied on the API for legitimate research and development. The restriction was lifted only last week after negotiations and clarification about the scope of the ban. The episode underscored the administration’s sensitivity to AI proliferation and its willingness to wield export‑control levers even against domestic firms perceived as crossing national‑security lines.

Implications for Federal AI Adoption
The CISA initiative illustrates a broader trend: federal agencies are increasingly turning to advanced AI models to bolster cyber defenses, even as they grapple with policy and safety concerns. By automating vulnerability discovery, Mythos could help close the gap between the speed of threat actors and the pace of manual code review. However, the episode also reveals the fragility of trust between AI developers and government stakeholders. Clear guidelines on model usage, transparency about safeguards, and robust oversight mechanisms will be essential if such collaborations are to scale without provoking further confrontations.

Looking Ahead: Balancing Innovation and Security
Moving forward, the interplay between AI innovation and national‑security regulation will likely remain a focal point. Agencies like CISA and the NSA stand to benefit from AI‑driven tools that can analyze massive codebases in near real‑time, yet policymakers must ensure that these tools cannot be easily repurposed for espionage, warfare, or surveillance without adequate checks. Anthropic’s experience—marked by a brief blacklisting, covert agency adoption, and a high‑profile White House intervention—serves as a case study in how swiftly the landscape can shift. Sustainable progress will hinge on establishing mutually agreeable frameworks that protect both technological advancement and the security interests of the United States.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here