# Anthropic's Mythos AI Found Vulnerabilities in Classified US Systems—Sparking Debate Over AI Security Tools
Landmark government-industry partnership reveals AI's capability to rapidly identify flaws in critical infrastructure, but sparks contentious policy response
A classified testing exercise has confirmed what cybersecurity researchers have long theorized: advanced AI models like Anthropic's Mythos can identify vulnerabilities in government computer systems with remarkable speed. According to a U.S. official speaking to The Associated Press, Mythos located weaknesses in highly secure Department of Defense systems within hours during controlled testing—reigniting an urgent policy debate about whether restricting such tools helps or harms national security.
The revelation, combined with the Trump administration's swift regulatory response, has fractured consensus among security experts and exposed fundamental disagreements about how to govern AI capabilities that are both defensive and potentially offensive.
## The Incident: Project Glasswing's Startling Results
Under an initiative called Project Glasswing, Anthropic partnered with U.S. intelligence agencies and the NSA to test Mythos against classified government infrastructure. The results were sobering: the model identified multiple vulnerabilities in hours.
During a June 11 Senate Banking Committee hearing, Democratic Senator Mark Warner of Virginia disclosed the scale of the findings, citing briefings from General Joshua Rudd, the head of both the National Security Agency and U.S. Cyber Command. "This tool broke into almost all of our classified systems, not in weeks but in hours," Warner stated, according to the AP account.
However, officials stressed an important distinction: identifying vulnerabilities and exploiting them are different capabilities. A U.S. official clarified to the AP that while Mythos found these flaws within hours, "that does not mean the model was able to exploit them within that time." The distinction matters for understanding the actual threat—and whether the government's response was proportionate.
## Background: Project Glasswing and Mythos's Rising Profile
Project Glasswing represents a rare collaboration between Silicon Valley and U.S. defense agencies to identify potential catastrophic risks from advanced AI systems before they become widespread. The initiative aims to secure critical software infrastructure against what the government views as "severe" fallout risks that frontier models could pose to national security and the economy.
Anthropic's Mythos model, the company's most advanced offering to date, was purpose-built with security in mind. The company has tightly restricted access to Mythos precisely because of concerns about dual-use risks—the model's ability to both detect and potentially weaponize security exploits. In contrast, Anthropic released a limited version called Fable 5 more broadly to the public earlier this month.
The classified testing appears to have been designed to answer a critical question before wider deployment: *How effective is this AI at finding vulnerabilities in systems designed to be resistant to intrusion?* The answer—extremely effective, and faster than human security researchers—forced the government's hand.
## The Government's Swift Response: Restrictions and Backlash
Within days of Senator Warner's disclosure, the Trump administration issued a directive prohibiting Anthropic from allowing foreign nationals to access Mythos 5 and Fable 5. The order was part of a broader executive framework requiring AI developers to submit their most advanced models for voluntary national security vetting before public release—a 30-day review period meant to identify potential risks.
Anthropic complied immediately, disabling both models for all customers globally to comply with the foreign national restriction. However, the company pushed back strategically, releasing a statement saying it "did not believe the steps taken by the government were warranted by the concern it flagged about a potential security issue."
The administration's move represented a stunning reversal in the relationship between Anthropic and the federal government. Just months earlier, the two had partnered on Project Glasswing. The tension escalated as Anthropic raised concerns about military applications of its AI, while the administration grew more skeptical of the company's independence.
## Technical Details: How Mythos Finds Flaws
While specific technical details remain classified, the capabilities demonstrated align with published research on Mythos's design. The model excels at:
This speed and accuracy derive from Mythos's training on large corpora of security research, documented vulnerabilities, and code repositories. The model can reason about software architecture and potential attack vectors in ways that amplify human security researchers' capabilities.
Importantly, the model's ability to *identify* vulnerabilities does not automatically confer the ability to exploit them reliably. Exploitation often requires knowledge of specific system configurations, runtime environments, and defensive measures in place—context that even advanced AI may struggle to infer.
## The Industry Strikes Back: Security Experts Oppose the Restriction
The administration's move provoked an unusual alliance: over 100 cybersecurity executives and researchers from companies including Adobe, Nvidia, Mandiant, and others signed a letter opposing the foreign national directive.
Their argument was blunt: the restriction could help U.S. adversaries more than it helps America's defense.
The signatories contended that:
The letter's strongest rhetorical point: Why disable your best cyber-defense capability "without a good reason" when adversaries like China and Russia are rapidly advancing their own AI security tools?
This framing recast the debate from "dangerous AI" to "unilateral disarmament in AI-powered defense."
## Policy Tensions: National Security vs. Defensive Capabilities
The incident exposes a fundamental fault line in AI governance:
| Perspective | Position | Concern |
|---|---|---|
| Government | AI models pose unquantified risk to classified systems | Rapid deployment of frontier models without vetting is reckless |
| Industry | Mythos is a valuable defense tool that shouldn't be restricted unilaterally | Restrictions harm U.S. defenders without equivalent global enforcement |
| Security Community | Risk must be weighed against capability benefits | A tool that finds vulnerabilities is also a tool that *prevents* breaches |
The 30-day vetting window in Trump's executive order suggests a middle ground: allowing government review before public release. But the foreign national restriction—a blanket ban—suggests the administration views even civilian, international use of Mythos as a national security concern.
## Implications: A Watershed Moment for AI Oversight
The Mythos incident will likely define AI governance for years:
1. Precedent for pre-release review: If voluntary vetting becomes the norm, expect other AI labs to submit frontier models for government scrutiny.
2. Tension between offense and defense: Tools that help secure systems are inseparable from tools that might help attack them. Governance frameworks must account for this duality.
3. Global competition: Restricting Mythos while adversaries develop equivalent capabilities creates long-term disadvantages for U.S. cyber defense.
4. Trust erosion: Anthropic's willingness to comply also signals that policy pressure, not technical capability, determines access.
## Recommendations for Organizations and Policymakers
For security teams:
For policymakers:
For AI developers:
---
## HackWire Analysis
The Mythos incident reveals a critical inflection point in how governments and industry approach dual-use AI. The testing was, in retrospect, exactly what responsible oversight should look like: controlled, collaborative, and designed to answer hard questions before widespread deployment.
But the government's response—a blanket foreign national ban—suggests officials conflated two separate problems: (1) whether Mythos poses a national security risk, and (2) whether it poses a risk greater than the cost of losing a powerful defensive capability. The evidence presented doesn't clearly support both conclusions simultaneously.
Senator Warner's description of the system breaking into "almost all" classified systems in hours is striking. But here's what's missing from the public narrative: *compared to what?* Could human red teams do the same in hours? Days? Could rival nations' AI models do it faster? We don't know, because the comparison never made it into the Congressional record.
The cybersecurity experts' letter highlights a sharper concern: the U.S. is restricting its own best tool while competitors build equivalent (or better) ones. China's AI security research is advancing rapidly. Russia has demonstrated interest in AI-powered cyber operations. A unilateral restriction on Mythos doesn't reduce the global pool of advanced vulnerability-finding AI—it just shifts advantage toward adversaries who've already trained their own models.
There's also a darker subtext here about Anthropic's relationship with the U.S. government. The company has been vocal about refusing military contracts and restricting government use of its models. The Trump administration's response—swift, punitive, and designed to limit the company's revenue from international customers—reads less like policy and more like leverage. Whether intentionally or not, the directive punishes Anthropic for not being compliant enough.
The real test of whether this policy framework works will be whether it includes equivalent restrictions on Chinese or Russian AI security tools—and given the classified nature of foreign AI capabilities, the public will likely never know.
— HackWire Editorial
---
## Related Coverage