CISA Reportedly Uses Anthropic AI to Find Software Vulnerabilities in Government Systems

Last updated: July 8, 2026 Reading time: 5 minutes
Disclosure
Share
CISA Reportedly Uses Anthropic AI to Find Software Vulnerabilities in Government Systems
  • CISA has reportedly adopted Anthropic’s Mythos AI model to identify security weaknesses across U.S. government software systems.
  • The agency’s Attack Surface Evaluation team has already discovered numerous vulnerabilities during AI-assisted code reviews, according to Reuters.
  • The reported deployment signals a major shift in Anthropic’s relationship with Washington after months of policy disputes and procurement restrictions.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reportedly begun using Anthropic’s advanced artificial intelligence model, Mythos, to uncover software vulnerabilities across federal government systems. Reuters revealed the initiative, citing three people familiar with the matter.

CISA wants to strengthen the security of government software before attackers discover hidden weaknesses. The AI model scans code repositories for flaws that foreign intelligence agencies, cybercriminals, or other threat actors could exploit.

According to Reuters, CISA assigned the work to its Attack Surface Evaluation team. The group specializes in penetration testing, security assessments, and offensive cybersecurity exercises across federal networks.

People familiar with the project told Reuters that the AI-assisted reviews have already exposed a considerable number of software vulnerabilities. Neither Reuters nor CISA disclosed how many applications underwent review or how severe the discovered flaws were.

CISA declined to publicly discuss the reported project. Reuters said an agency spokesperson previously indicated officials would determine whether details could be shared but never provided additional comments afterward. Anthropic also chose not to address Reuters’ questions regarding the reported deployment.

AI Strengthens Government Cybersecurity Operations

The reported rollout highlights how government agencies increasingly rely on artificial intelligence to improve cyber defense capabilities. Instead of depending solely on manual reviews, analysts can now identify weaknesses much faster.

The need for such tools is underscored by incidents like the hack of Indian embassies, which security negligence reportedly enabled.

Mythos has attracted significant attention because of its ability to inspect source code, detect security vulnerabilities, and highlight possible exploitation paths within a short period. Those capabilities allow security teams to examine far larger software environments than traditional approaches.

Earlier reports suggested that U.S. intelligence agencies had already recognized the model’s cybersecurity potential. According to Axios, the National Security Agency began evaluating Mythos inside classified environments as early as April. Those assessments reportedly continued despite Anthropic receiving a temporary government supply-chain risk designation earlier this year.

The Associated Press later reported that intelligence officials testing the model expressed confidence in its performance. According to the publication, the AI identified vulnerabilities inside classified government systems much faster than expected. Outside government projects, Anthropic has also showcased Mythos during limited cybersecurity evaluations involving industry organizations.

According to reports, participants using the model collectively uncovered thousands of software vulnerabilities during those assessments. The results demonstrated how artificial intelligence can significantly accelerate vulnerability discovery across complex software environments.

If Reuters’ report accurately reflects current operations, CISA’s adoption of Mythos marks another step toward integrating advanced AI into everyday federal cybersecurity work. The technology allows analysts to identify weaknesses before attackers can abuse them.

Months of Disputes did not Stop Government Interest

The reported deployment also reflects a dramatic improvement in Anthropic’s relationship with the U.S. government after several months of disagreements over AI policy. Earlier this year, reports indicated that tensions emerged after Anthropic refused to weaken safeguards designed to prevent its AI models from supporting autonomous weapons or domestic surveillance activities.

That disagreement reportedly prompted the Pentagon to assign Anthropic a formal supply-chain risk designation. The designation effectively prevented parts of the federal government from purchasing or adopting the company’s technology. The restriction did not remain in place for long.

A federal judge later blocked the designation, allowing government agencies to continue reviewing Anthropic’s products for potential use. The situation evolved again after Anthropic privately introduced Mythos, a model specifically designed for advanced cybersecurity operations.

Government organizations reportedly welcomed the technology because of its ability to locate software vulnerabilities efficiently. However, another dispute soon followed after Anthropic publicly released a related model known as Fable.

Reports indicated that the White House requested additional safeguards before allowing broader access to the technology. Those measures reportedly included tighter restrictions on foreign access to the model.

The reported concerns resulted in a temporary global shutdown before officials lifted the restrictions last week. Reuters’ latest report suggests those earlier disagreements have not reduced federal interest in Anthropic’s cybersecurity capabilities.

Security Teams to Face Growing Software Ecosystems

According to people familiar with the project, government agencies continue evaluating the company’s technology because of its ability to improve vulnerability discovery and software security.

The reported deployment also reflects a broader trend across governments worldwide. Public sector organizations increasingly view artificial intelligence as an essential cybersecurity tool rather than an experimental technology.

Security teams face growing software ecosystems and increasingly sophisticated cyber threats every year. AI models such as Mythos help analysts review larger volumes of code while reducing the time required to identify dangerous flaws.

That advantage could become increasingly important as nation-state attackers and cybercriminal groups continue targeting government infrastructure with more advanced techniques.

Although neither CISA nor Anthropic has officially confirmed the Reuters report, the reported initiative demonstrates how artificial intelligence is becoming a central component of modern cybersecurity operations.

If the deployment continues expanding, CISA could identify and remediate software weaknesses much earlier in the development process. That proactive approach would reduce opportunities for attackers while strengthening the security of federal digital infrastructure before vulnerabilities become active threats.

Share this article

About the Author

Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.

More from Farwa Sajjad

Related Posts