Drooid Logo
Back to story perspectives

Full Breakdown

NSA Embeds Anthropic Engineers to Deploy Mythos AI for Offensive Cyber Operations

6/6/2026, 4:48:26 AM

The Deployment of Mythos at the NSA

The National Security Agency has placed roughly six Anthropic engineers on-site to operationalize the company’s frontier cybersecurity model, Mythos, for intelligence-grade applications. Sources say the model could be used to infiltrate networks in China, Iran and other adversaries, though the agency has not confirmed whether the engineers are participating in live attacks.

Background: Supply-Chain Risk Designation and Legal Dispute

In January 2026 the Trump administration demanded that Anthropic allow its Claude models to be used for “all lawful purposes,” including mass surveillance and autonomous weapons. Anthropic refused. Defense Secretary Pete Hegseth issued a supply-chain risk directive on 27 Feb 2026, and the Department of War (DoW) formally designated Anthropic a supply-chain risk under the Federal Acquisition Supply-Chain Security Act on 4-5 Mar 2026. President Trump ordered a purge of Anthropic products. Anthropic sued, securing a preliminary injunction on 26 Mar 2026 that blocked the broader ban, while the specific DoW designation remained in effect.

Key Players

  • Pete Hegseth – Defense Secretary, architect of the supply-chain risk label.
  • Dario Amodei – CEO of Anthropic, vocal opponent of unrestricted government use.
  • Emil Michael – DoW chief technology officer, described the NSA-Mythos carve-out as “a separate national security moment.”
  • National Security Agency (NSA) – Intelligence agency testing and potentially fielding Mythos.
  • Cloud Security Alliance – Independent researchers who benchmarked Mythos.

Timeline of the Conflict

  • Jan 2026 – Trump administration’s “all lawful purposes” demand.
  • 27 Feb 2026 – Hegseth’s supply-chain risk directive.
  • 26 Mar 2026 – Judge Rita Lin grants preliminary injunction.
  • 7 Apr 2026 – Anthropic launches Project Glasswing (defensive access to Mythos).
  • Early Spring 2026 – NSA conducts simulated Mythos tests.
  • 5 Jun 2026 – Financial Times reports six Anthropic engineers embedded at NSA.

Data & Capabilities

  • Engineers embedded: ~6 (half-a-dozen).
  • Mythos exploits: 181 working exploits in a Firefox benchmark (Cloud Security Alliance).
  • Glasswing rollout: 150 organizations in 15 countries (later ~200 across >15 countries).
  • Vulnerabilities discovered: >10 000 high- or critical-severity bugs since launch.

Why It Matters

Mythos represents a leap from narrow vulnerability scanners to an agentic system that can autonomously discover, test and exploit zero-day flaws. Its deployment by the NSA, despite a federal ban on Anthropic products, raises questions about the enforceability of AI procurement restrictions, the balance between offensive advantage and safety commitments, and the need for congressional oversight of AI in intelligence work.

Official Statements & Responses

  • Hegseth reaffirmed Anthropic’s classification as a national-security risk, citing loss of trust in Claude’s safeguards.
  • An NSA spokesperson declined to confirm or deny the report.
  • Anthropic declined comment on the NSA arrangement.
  • Judge Lin’s injunction blocked the broader procurement ban but left the DoW designation intact.
  • Emil Michael publicly called the NSA carve-out “a separate national security moment.”

Criticism & Opposition

The Electronic Frontier Foundation warned that privacy protections should not hinge on a few powerful actors. Congresswoman Valerie Foushee labeled the administration’s pressure on Anthropic “deeply troubling.” AI safety researcher Roman Yampolskiy warned that any leakage of Mythos-class capabilities could be inevitable.

Conflicting Reports & Gaps

Sources differ on whether Mythos is actively used in offensive missions; some describe the engineers as merely customizing the model, while others suggest operational use. The legal status of the NSA carve-out remains ambiguous, with the ban technically in place but reportedly exempted for this specific deployment.

Verbatim Quotes

  • “The argument that Hegseth and his underlings were trying to make, that Anthropic was a unique threat to national security, never made any sense.” — Gizmodo analysis
  • “in a narrow set of cases, [Anthropic believes] AI can undermine, rather than defend, democratic values.” — Dario Amodei, CEO, Anthropic
  • “the best way to build a good defence is to build a good attack” — Anthropic insider
  • “a separate national security moment.” — Emil Michael, DoW chief technology officer

What’s Next

Senator Mark Warner’s AI Accountability in Defense Act, which would require disclosure and audits of AI-driven offensive tools, is moving through committee markup. The D.C. Circuit’s pending ruling on Anthropic’s lawsuits will clarify the scope of the supply-chain risk designation. Meanwhile, Anthropic plans to expand Mythos access to additional vetted partners, potentially prompting further clashes between AI safety policy and intelligence priorities.