US Cyber Agency CISA Employs Anthropic's AI Model Mythos for Government Code Audits

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic's AI model, Mythos, to scan government software for bugs that could let in foreign spies and hackers, according to Yahoo News. The scanning is run by CISA's Attack Surface Evaluation team, a unit that conducts digital security checks and mock hacking exercises across federal agencies.
The move signals growing government trust in Anthropic's tools — even as the company faces an unresolved dispute with the White House. It also follows news that the National Security Agency began using Mythos in April, according to Mix 92.9.
CISA's Attack Surface Evaluation team is the group running the Mythos scans, according to Hot 96. The team's job is to find weaknesses in government systems before attackers do. Using AI to comb through software code is a faster way to spot vulnerabilities — flaws in code that bad actors could exploit to break into systems.
Government software repositories hold large volumes of code used to run federal systems. Manually auditing all of it is slow and expensive. AI models like Mythos can scan far more code in less time, flagging potential issues for human reviewers to investigate.
CISA is not the first U.S. intelligence or security agency to adopt Mythos. The National Security Agency has been using the model since April, according to 95 KQDS. That makes two major federal security agencies now relying on Anthropic's AI for sensitive work.
The NSA's earlier adoption suggests Mythos passed internal security reviews at one of the most secretive agencies in the U.S. government. CISA's decision to follow suit adds weight to Anthropic's standing as a trusted AI vendor for national security work.
The expanded use of Mythos comes despite an ongoing dispute between Anthropic and the White House, according to 1027 WBOW. The nature of the dispute has not been fully detailed, but the company was previously blacklisted by the White House. That history makes the agencies' continued adoption of its tools a notable show of institutional confidence.
Anthropic's Mythos is now being used for some of the most sensitive code reviews in the federal government. That level of access — even amid political tension — points to a gap between White House politics and the day-to-day decisions of national security agencies.
Federal agencies face constant threats from foreign hackers, including state-sponsored groups linked to China, Russia, Iran, and North Korea. Finding bugs in government code before adversaries do is a core part of cyber defense. AI tools like Mythos offer a way to do that at scale, reviewing millions of lines of code far faster than human analysts.
CISA's use of Mythos is an early example of AI being plugged directly into the government's cyber defense pipeline. If the audits prove effective, the approach could spread to other agencies and set a new standard for how the U.S. government protects its digital infrastructure.
Publishers
5
Articles
5
Reach
5