US Cyber Agency Uses Anthropic AI Model to Scan Government Code for Security Flaws

Reuters reports that CISA is using Anthropic’s Mythos AI system to identify vulnerabilities in government software repositories, highlighting growing US reliance on advanced AI tools despite tensions between the company and Washington.

1 min read
Dario Amodei of Anthropic

The US Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s artificial intelligence model Mythos to audit government software code for security vulnerabilities, according to three people familiar with the matter who spoke to Reuters.

The initiative involves scanning government code repositories for bugs that could potentially be exploited by foreign intelligence services or cybercriminals, the sources said. The effort represents another example of growing US government interest in using advanced artificial intelligence tools for cybersecurity operations.

According to Reuters, the scanning is being conducted by CISA’s Attack Surface Evaluation team, a unit responsible for digital security assessments and hacking exercises across government networks.

Two sources told Reuters that the audits had already identified a significant number of vulnerabilities, though they did not provide details about the specific flaws discovered, the amount of government code examined or the severity of the security risks involved.

Anthropic did not respond to Reuters’ questions about the initiative. A CISA representative said last month that he would check whether the agency had information to share but did not provide further comments.

The reported use of Mythos comes amid a complicated relationship between Anthropic and the US government. The San Francisco-based artificial intelligence company has faced tensions with Washington over restrictions it placed on how its technology could be used.

The dispute intensified in February when Anthropic refused to remove safeguards preventing its AI systems from being used for autonomous weapons or domestic surveillance. The decision led the Pentagon to impose a formal supply-chain risk designation on the company, a measure typically associated with foreign entities suspected of posing espionage risks.

A judge later blocked the designation in March, and relations between Anthropic and the government improved following the private release of Mythos, an AI model described as highly capable in identifying and exploiting cybersecurity vulnerabilities.

Despite the previous restrictions, the National Security Agency (NSA) has also reportedly used Mythos. Reuters noted that Axios reported the NSA had been using the model as early as April, while The New York Times reported that NSA analysts had tested the technology in classified environments and found its capabilities impressive.

The broader debate over Anthropic’s AI tools intensified after the company released a public version of Mythos called Fable, which included cybersecurity safeguards. The White House subsequently demanded that Anthropic prevent foreign users from accessing the model, prompting the company to temporarily shut down global access before restoring the service last week.

The NSA and the White House did not immediately respond to requests for comment.

The reported use of Mythos by US cybersecurity agencies highlights the growing role of artificial intelligence in identifying digital threats, while also raising questions about how governments balance the adoption of powerful AI systems with security controls and regulatory concerns.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog