Sources: the US NSA is using Mythos Preview; one source says Mythos is also being widely used within the DoD, despite Anthropic's supply chain risk designation
- The department moved in February to cut off Anthropic and force its vendors to follow suit.
Axios
Context & Ripple Effects
Related coverage traces Mythos from preview access at security agencies to testing against vulnerabilities in Microsoft products and other widely used software. Subsequent reporting says the DoD planned to deploy it for government vulnerability discovery and patching while transitioning away from Anthropic.
That sequence makes the reported use notable as an operational-policy conflict: intelligence and defense users appear to value the model’s cyber capabilities even as the department’s supplier-risk action seeks to restrict Anthropic and its vendor ecosystem.
First-order effects
The NSA and, according to one source, broader DoD users gain access to Mythos capabilities while the department is pursuing a cutoff from Anthropic.
The supply-chain-risk designation creates an immediate compliance and continuity problem for DoD components and vendors that may be using, supporting, or planning around Mythos.
Second-order effects
Security teams may need to separate high-value model use for vulnerability work from procurement restrictions, producing uneven access across agencies; related coverage indicates CISA did not have access to Mythos Preview.
A transition away from Anthropic could disrupt or delay cyber workflows built around Mythos, increasing pressure to validate substitute models for vulnerability identification and remediation.
Third-order effects
If this pattern persists, government AI policy will shift from a simple supplier-approval decision toward granular controls over which agencies, tasks, and environments may access frontier models.
The episode highlights concentration risk in government cyber tooling: restricting a model provider can also constrain security capabilities when alternatives are not yet proven for the same work.
The trend: Frontier-model access is becoming a security-governance issue in which procurement restrictions, operational cyber needs, and agency-specific permissions increasingly collide.
No joke here: presumably someone in the NSA had to get sign off from someone very high up to do something so contrary to current Pentagon policy on Anthropic? Does the NSA doing this not risk completely undermining the Department's upcoming case in the Ninth Circuit?
Because it's existential for the NSA to understand and deploy the infinite zero day glitch. Which highlights the stupidity the supply chain risk designation.
Before this inevitably gets out of hand, a gentle reminder that the NSA is the federal agency responsible for the U.S. government's cybersecurity capabilities. [image]
The United States National Security Agency is using Anthropic's Mythos Preview AI tool despite the Pentagon hitting the company with a formal supply-chain risk designation, Axios reported on Sunday. …