CISA Using Anthropic’s Mythos AI to Hunt Flaws in Government Code

CISA is reportedly using Anthropic’s Mythos — one of the most powerful AI models out there — to scan federal government software for security holes. According to Reuters, the agency’s Attack Surface Evaluation team is running Mythos across code repositories to find bugs before foreign intelligence agencies or criminals do.

Sources say the AI-driven operation has already uncovered a “large number” of vulnerabilities. No word on which agencies were affected or how severe the flaws were.

The move is interesting because Anthropic and the US government have been at odds. Earlier this year, Anthropic refused to remove safeguards that stop its models from being used for autonomous weapons or domestic surveillance. The Pentagon responded by labeling the company a “supply-chain risk” — a label usually reserved for foreign firms suspected of espionage.

Then things got weirder. When Anthropic released the public version of this model — called Fable — the White House demanded restricted access over concerns about foreign nationals using it. That kicked off a standoff that led to a temporary global shutdown of Fable. The restrictions were lifted last week.

The NSA is reportedly using Mythos too. A US official recently told the AP that one of Anthropic’s models found vulnerabilities in classified government systems during a test.

So we’ve got the US government scanning its own code with AI from a company it designated a supply-chain risk. That’s the state of play in 2026.

References