Sources: CISA doesn't have access to Mythos Preview, even as some other government agencies use it; Anthropic says it briefed CISA before Mythos' unveiling
The Cybersecurity and Infrastructure Security Agency doesn't have access to Anthropic's powerful new Mythos Preview model …
Context & Ripple Effects
Anthropic had presented Mythos Preview as a tightly controlled capability for a limited set of critical-software maintainers rather than a general release. Related reporting indicated that NSA and parts of the DoD were already using it, making CISA's position a notable gap in the government-access pattern.
Later coverage says CISA's Attack Surface Evaluation team used Mythos to audit government code repositories and found many vulnerabilities, indicating that the initial access boundary was not permanent.
First-order effects
- At the time of the report, CISA could not directly apply Mythos Preview to its cybersecurity work, while other national-security agencies reportedly could.
- Anthropic's pre-launch briefing gave CISA visibility into the model without operational access, separating consultation from deployment.
Second-order effects
- Different access across agencies can shift which organizations identify and remediate software weaknesses first, especially when a model is reserved for selected users.
- CISA's later use of Mythos suggests that high-value government access may be phased, with evaluation and security controls determining when an agency moves from briefing to operational deployment.
Third-order effects
- Frontier-model distribution is becoming an access-governance issue: providers can make agency-by-agency decisions that function as security boundaries, not merely customer onboarding.
- If this pattern persists, government adoption will depend increasingly on whether labs can offer controlled deployments that satisfy both mission needs and risk concerns.
The trend: Advanced AI is being deployed to government through selective, governed access rather than broad availability, turning model distribution into part of security policy.