Full Breakdown
NSA Deploys Anthropic’s Mythos AI for Cyber Operations
6/8/2026, 1:20:51 PM
Core Deployment: Engineers Embedded and Model Activation
In June 2026 the U.S. National Security Agency began preparing Anthropic’s restricted AI model Mythos for cyber work. Financial Times and TechCrunch reports say roughly six Anthropic engineers have been “forward-deployed” inside the agency to customize the model for potential offensive tasks such as infiltrating networks in China or Iran.
Background & Capability Overview
Anthropic, creator of the Claude conversational series, introduced Mythos as a frontier cybersecurity system designed to scan code, locate zero-day flaws and generate exploit paths. The company previously resisted Pentagon requests to embed its models in mass-surveillance and autonomous-weapon programs, prompting the Trump administration to label it a “supply-chain risk” and to ban Claude from DoD systems. The NSA arrangement exists under a specific carve-out from that ban.
Scale, Testing Results, and Expansion
Project Glasswing initially limited Mythos Preview to about 50 vetted organizations; by early June it covered roughly 150 entities across more than 15 countries, including Okta, Samsung, NATO and the EU agency ENISA. Internal scans of 1,000 open-source projects flagged 23,019 potential vulnerabilities, 6,202 of them high or critical, and partners have reported over 10,000 high-severity flaws. Independent testing showed Mythos could complete a 32-step simulated corporate-network attack and produce a full exploit pipeline against a complex Linux target in under a day for less than $2,000.
Global Implications for Cybersecurity
The deployment illustrates how a state-level AI tool can accelerate offensive cyber work beyond human speed, raising concerns that criminal groups will emulate the approach. In Africa, where banks, telecoms and public services already face persistent cyber pressure, the gap between well-funded attackers and under-resourced defenders could widen dramatically.
Official Statements & Government Responses
- The NSA declined to confirm or deny the Financial Times report.
- Anthropic maintains that Mythos is “too dangerous to release broadly” and stresses that “the best way to build a good defence is to build a good attack.”
- The White House announced accelerated AI development for national security while calling for responsible use and updated autonomous-weapon policy.
- The Department of Defense continues to label Anthropic a supply-chain risk, a designation upheld by a federal appeals court despite mixed evidence of malicious intent.
Criticism, Legal Dispute, and Opposition
Legal scholars and cybersecurity advocates argue the lack of public disclosure, congressional oversight and audit mechanisms makes the model’s offensive use opaque. Critics warn that deploying a system capable of exploiting “every major operating system and every major web browser” without transparent safeguards could destabilize international cyber norms. A federal appeals court has been asked to review the Pentagon’s “supply-chain risk” label, while Anthropic contends the designation hampers legitimate defensive research.
Conflicting Reports & Information Gaps
Sources differ on whether Anthropic engineers are involved in live intrusion campaigns or solely in model customization. Descriptions of “cyber operations” vary between defensive vulnerability hunting and offensive network disruption, leaving the precise scope of NSA activity unclear.
Verbatim Quotes
- “The best way to build a good defence is to build a good attack.” — Financial Times (citing Anthropic defenders)
- “In an April 7 post, Anthropic’s red team said Mythos Preview could find and exploit zero-day vulnerabilities in “every major operating system and every major web browser” when a user directed it to.” — Anthropic red team, April 7 post
- “The National Security Agency is using Anthropic’s most powerful model yet, Mythos Preview, despite top officials at the Department of Defense — which oversees the NSA — insisting the company is a “supply chain risk,” two sources tell Axios.” — Axios report
Outlook: Policy and Operational Next Steps
Anthropic plans to broaden Project Glasswing further, while U.S. lawmakers are expected to hold hearings on AI-enabled cyber capabilities. NATO, ENISA and other international bodies may draft guidelines for AI-assisted offensive tools, and South African regulators are monitoring potential spill-over effects on regional cyber resilience.
