Sources: the NSA has been testing Anthropic's Mythos model to find vulnerabilities in Microsoft products and widely used software from other companies
The National Security Agency has been testing the capabilities of Anthropic PBC's new artificial intelligence model to find cybersecurity vulnerabilities …
Context & Ripple Effects
Related coverage had already placed Mythos Preview inside the NSA and, according to one source, in wider DoD use despite Anthropic’s supply-chain-risk designation. This report makes the use case concrete: model-assisted vulnerability discovery against broadly deployed software.
Later coverage describes NSA red-teaming of a newer Mythos version, findings involving classified systems, and Anthropic engineers helping deploy the model for offensive cyber operations. Together, the coverage traces a move from evaluation toward operational integration, while leaving model access subject to institutional dispute.
First-order effects
- The NSA gains another tool to test whether a frontier model can accelerate discovery of software weaknesses across Microsoft and other widely used products.
- Anthropic’s relationship with national-security users becomes more operationally significant, while Microsoft and other software vendors face the prospect that AI-assisted testing may surface flaws faster.
Second-order effects
- Security teams and software vendors may need to assume faster vulnerability discovery by both defenders and adversaries, increasing the value of rapid patching, code review, and red-team capacity.
- Anthropic’s government-model access and deployment practices become a strategic constraint: subsequent coverage indicates that losing access can interrupt active NSA testing even after the model has demonstrated utility.
Third-order effects
- If frontier models consistently improve vulnerability research, cyber capability will depend less only on human researcher headcount and more on reliable access to high-performing models, secure deployment environments, and vendor cooperation.
- The pattern strengthens pressure to treat leading AI labs as national-security infrastructure while intensifying disputes over who controls model access, permitted uses, and supply-chain trust.
The trend: This is one data point in the conversion of frontier AI from a general-purpose software product into controlled cyber and national-security capability.