Particle.news

CISA Uses Anthropic Mythos to Audit US Government Code

Faster automated scans may reveal more bugs, forcing new limits on who can use powerful AI models.

Overview

  • CISA’s Attack Surface Evaluation team is running Anthropic’s Mythos to scan government code repositories, three people familiar with the matter told reporters on Monday.
  • Sources said the audits have already uncovered a large number of vulnerabilities, though CISA and Anthropic have not disclosed how many or how severe the flaws are.
  • CISA gained full access to the Mythos Preview model under Anthropic’s Project Glasswing after the program expanded to roughly 150 partner organizations in early June.
  • The National Security Agency tested Mythos in classified settings earlier this year and reported rapid results, and the deployment follows a recent temporary shutdown and White House demands over foreign access to the model.
  • Officials face tradeoffs: faster, AI-driven bug hunting could harden government systems quickly, but it also raises unresolved questions about supply-chain trust, export controls, foreign partners’ access, and independent oversight.