Anthropic Mythos AI Uncovers Flaws in Classified US Government Systems
A senior U.S. official confirmed to The Associated Press that Anthropic's Mythos artificial intelligence model identified vulnerabilities in highly sensitive and classified government computer systems during a joint testing exercise with U.S. intelligence agencies. The testing, conducted under Anthropic's Project Glasswing initiative, brought together major technology firms to proactively assess the security risks that advanced AI models like Mythos could pose to public safety, national security, and critical infrastructure. While the model flagged vulnerabilities within hours, the official clarified that this did not necessarily mean those flaws were actively exploited during the exercise.
Senator Mark Warner (D-VA) publicly referenced the testing during a June 11 hearing before the Senate Committee on Banking, Housing, and Urban Affairs, stating, "This tool broke into almost all of our classified systems, not in weeks but in hours." Warner attributed the revelation to General Joshua Rudd, head of the National Security Agency and U.S. Cyber Command. Neither the NSA nor Anthropic commented further on the findings, though the implications are significant for federal defenders working to harden systems against AI-augmented offensive operations. Security teams tasked with defending similar environments can audit their own external attack surfaces using a port scanner to identify exposed services that an AI-driven adversary could rapidly enumerate.
Tensions between Anthropic and the Trump administration have escalated alongside the cooperation. Earlier this month, the administration issued a directive requiring Anthropic to block foreign nationals from using its latest models, Fable 5 and Mythos 5, prompting Anthropic to disable the models for all customers pending compliance. The directive followed an executive order signed by President Donald Trump establishing a voluntary framework for federal vetting of advanced AI systems up to a month before public release. Anthropic stated it did not believe the government's actions were warranted by the flagged security concern, and a coalition of more than 100 cybersecurity executives has urged the administration to reconsider, arguing the restrictions could advantage U.S. adversaries.
The episode highlights a growing paradox in AI policy: the same frontier models capable of accelerating vulnerability discovery are now subject to export-style controls that may fragment the defensive research community. Organizations monitoring their own exposure to credential-based intrusions, which remain a common entry vector for both human and AI-assisted attackers, can verify whether employee accounts have been compromised via an email breach checker and strengthen their overall posture with a privacy checkup as part of routine incident response planning.