The US cyber defense agency CISA is reportedly using Anthropic’s Mythos model to scan government code for security flaws, three sources tell Reuters. The audits have already flagged a significant number of vulnerabilities. It’s a striking sign of government appetite for Anthropic’s tools despite a rocky White House relationship.
Key Takeaways
- CISA is reportedly using Anthropic’s Mythos to audit government code
- The scans hunt bugs exploitable by foreign spies and cybercriminals
- CISA’s Attack Surface Evaluation team is running the work
- Audits have already flagged a significant number of vulnerabilities
- The NSA has reportedly used Mythos since April as well
What CISA Is Reportedly Doing
The report comes from Reuters. On July 6, three people familiar with the matter said the Cybersecurity and Infrastructure Security Agency is using Anthropic’s Mythos to audit government software, calling it another sign of government enthusiasm for the startup’s tools.
The task is defensive. According to the sources, CISA is using Mythos to scan government code repositories for bugs that could leave the door open for foreign spies and cybercriminals, the kind of hidden flaws that turn into breaches.
A specific team is doing the work. The scanning is being run by CISA’s Attack Surface Evaluation team, a group within the agency that conducts digital security assessments and hacking exercises across government networks.
The early results are notable. Two sources told Reuters the audits had already identified a significant number of vulnerabilities, though they didn’t detail the specific flaws or how much code had been examined.
The agencies stayed quiet. Anthropic did not respond to questions about the initiative, and a CISA representative said last month he would check whether there was anything to share but did not answer follow-up emails.
Why Mythos Specifically
Mythos isn’t a general-purpose assistant. It’s an Anthropic model described as extremely capable at finding and exploiting cybersecurity vulnerabilities, which makes it a natural fit for hunting bugs in code.
That capability cuts both ways. A tool good enough to spot exploitable flaws for defenders is, by definition, good at the same task an attacker would want, which is exactly why its rollout has drawn so much scrutiny.
The model reached the public in a guarded form. When Anthropic released a public version of Mythos called Fable, it included what the company described as cybersecurity safeguards meant to limit misuse of those same abilities.
That safeguarded release sits at the center of the government tension, and it helps explain why a model this powerful ended up caught between an eager cyber agency and a wary White House.
The NSA Connection
CISA isn’t the only agency reportedly reaching for Mythos. The National Security Agency, the government’s powerful eavesdropping arm, has been using the model as far back as April, according to Axios reporting cited by Reuters.
The testing reportedly went deep. Late last month, The New York Times said NSA analysts had been putting Mythos through its paces in classified settings and came away impressed with what it could do.
The timing raises eyebrows. The NSA’s reported use began in April despite a blacklist that was hanging over Anthropic at the time, a sign of how much some agencies wanted access even while the broader standoff played out.
Anthropic’s Rocky Government Relationship
None of this happened in a calm environment. Anthropic has had a turbulent stretch with Washington, rooted in limits it placed on how its technology can be used.
The friction sharpened early in the year. The dispute intensified in February when Anthropic refused to remove safeguards that block its systems from being used for autonomous weapons or domestic surveillance.
The response was severe. The Pentagon imposed a formal supply-chain risk designation on the company, a measure usually reserved for foreign entities suspected of espionage risk. A judge blocked that extraordinary blacklisting in March, and relations eased after the private release of Mythos.
Then came another clash. After Fable launched with its safeguards, the White House abruptly demanded Anthropic ban foreigners from running it, triggering a global shutdown of the model that was lifted only last week. Anthropic has said the suspension stemmed from US export controls, which the Commerce Department later cleared.
What This Signals
Read together, the reporting points to one thing: the US government wants advanced AI for cybersecurity, and it wants it now, even from a company it’s been fighting.
The appeal is straightforward. Scanning sprawling government codebases by hand is slow and incomplete, while a model tuned to find exploitable flaws can cover far more ground far faster. For an agency tasked with defending federal networks, that’s hard to pass up.
The tension is just as clear. The same power that makes Mythos useful to CISA is what made the White House nervous about who else could run it, a balance every government will keep wrestling with as these tools spread.
Plenty stays unknown. The reporting rests on anonymous sources, the agencies aren’t talking, and key details, like the scale of the audits and the nature of the flaws found, remain undisclosed. What’s evident is that AI has moved from experiment to active tool inside US cyber defense.
Digital Trendings is your trusted source for AI news and updates, stay tuned for more.







