Source: US Treasury CIO Sam Corcos aims to gain access to Mythos as soon as this week, and directed the Treasury's cybersecurity team to prepare for AI threats
Context & Ripple Effects
Treasury’s push appears as government access to Mythos is uneven: related coverage says CISA initially lacked Mythos Preview while other agencies were using it. The same coverage also records UK regulators preparing to flag security risks associated with the preview.
Subsequent reporting places Mythos in a concrete public-sector security workflow, with CISA using it to audit government code repositories and finding many vulnerabilities. Separately, Mistral’s discussions with European banks point to demand for alternatives where access is constrained.
First-order effects
- Treasury’s cybersecurity organization must prepare to evaluate and operate a frontier model in security-sensitive work, rather than treating AI risk solely as an external threat.
- If access is granted, Treasury gains a potential new capability for cybersecurity analysis while its CIO becomes accountable for the model’s deployment controls and risk posture.
Second-order effects
- Different levels of agency access can make model availability a practical determinant of which public-sector teams can automate code and vulnerability review first.
- Security-focused model suppliers have an opening with regulated organizations and governments that cannot obtain Mythos or are reluctant to rely on it; Mistral’s bank discussions illustrate that demand.
Third-order effects
- Government AI procurement is likely to shift from general experimentation toward controlled access, security evaluation, and mission-specific deployment of frontier models.
- As models are used both to strengthen defenses and create new security concerns, access policy and assurance requirements may become as consequential as model capability for public-sector adoption.
The trend: This is part of the shift toward frontier-model access as strategic cybersecurity infrastructure, with governments seeking capability while building controls around its risks.