CISA Uses Anthropic's Mythos Model to Audit US Government System Code
The US Cybersecurity and Infrastructure Security Agency (CISA) uses Anthropic's closed offensive AI model called Mythos to find vulnerabilities in its own government agency software. Three sources familiar with the situation revealed this—almost no official details have been confirmed.
AI-processed from TNW; edited by Hamidun News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is deploying Anthropic's closed offensive AI model named Mythos to search for vulnerabilities in software used by U.S. government agencies. Three sources familiar with the situation revealed this — while almost nothing about the work itself has been officially confirmed.
What is known about Mythos deployment
The federal agency responsible for protecting U.S. civilian infrastructure is directing a private offensive-class AI model toward auditing its own government software. An "offensive" model in this context means a tool originally developed or adapted for offensive cybersecurity tasks — that is, for finding and exploiting vulnerabilities, not merely passive detection.
- Model name — Mythos, owned by Anthropic
- User — US Cybersecurity and Infrastructure Security Agency (CISA)
- Purpose — finding bugs and vulnerabilities in software used by government agencies
- Information source — three sources familiar with the situation
- Official status — almost nothing about the work is confirmed or publicly documented
Why secrecy around the project matters
The fact that almost nothing about Mythos's work within CISA appears in public is itself significant: the use of advanced AI models for offensive cybersecurity by government agencies is an area where details are intentionally concealed, as publishing the methods and findings of an audit could give potential adversaries clues about vulnerabilities or the tool's capabilities. The deployment of a closed, commercially available model from a private company — rather than exclusively internal agency development — also reflects a broader trend: government entities increasingly rely on frontier lab models like Anthropic's for tasks that until recently required only manual work by in-house cybersecurity specialists.
What this means
The deployment of Anthropic's offensive model for auditing government code is a concrete example of how language models transition from auxiliary chat tools to tasks with direct consequences for national cybersecurity, while simultaneously signaling that boundaries between commercial AI development and government defense operations continue to blur.
Need AI working inside your business — not just in your newsfeed?
I build production AI for companies — custom CRM, internal tools, autonomous agents, workflow automation. Owned by you, shaped to your process, no per-seat tax. Built by Zhemal Khamidun, CPO of AlpinaGPT (AI platform, 6,000+ users).
The AI world, distilled — once a week
Seven stories that actually mattered, hand-picked. No noise, no reposts, no press releases.
Done! Check your inbox for a confirmation.