Anthropic’s AI Model Finds Vulnerabilities in U.S. Government Systems

Anthropic’s AI Model Finds Vulnerabilities in U.S. Government Systems

On Tuesday, a senior United States government official confirmed to The Associated Press that an artificial intelligence model built by AI developer Anthropic detected unaddressed security gaps in highly classified, hardened U.S. government computer systems during a recent collaborative testing exercise.

Speaking on condition of anonymity to discuss the confidential matter freely, the official shared that Anthropic partnered with U.S. intelligence agencies to run the trial using the company’s Mythos AI model. While the model flagged multiple existing vulnerabilities within just a few hours, the official clarified that the system did not demonstrate the ability to actually exploit those security gaps during the testing window.

According to the official, the testing was conducted as part of Anthropic’s Project Glasswing, an industry initiative that brings together major tech giants and private sector stakeholders to harden global critical software against potentially catastrophic harm that advanced AI models like Mythos could pose to public safety, national security, and economic stability.

The exercise was first referenced publicly by Democratic Senator Mark Warner of Virginia during a June 11 hearing of the Senate Committee on Banking, Housing, and Urban Affairs. Warner told attendees, “This tool broke into almost all of our classified systems, not in weeks but in hours,” noting he received the update from General Joshua Rudd, the head of both the National Security Agency (NSA) and U.S. Cyber Command.

When reached for comment via email, the NSA declined to share any details on the test or Warner’s claims. A spokesperson for Anthropic also declined to comment on the record.

Despite Anthropic’s recent collaboration with U.S. agencies to root out system vulnerabilities, tensions between the California-based AI firm and the Trump administration have escalated in recent weeks. Anthropic has raised repeated concerns over potential U.S. military use of its AI technology, while the administration has imposed new restrictions on access to some of the company’s most advanced models.

Earlier this month, the administration issued a directive requiring Anthropic to block foreign nationals from accessing its two newest flagship AI models, designated Fable 5 and Mythos 5. Anthropic released a wide public version of Fable earlier the same month; the model is a limited, less powerful iteration of the far more advanced Mythos, which Anthropic already tightly restricted access to due to pre-existing cybersecurity concerns.

The directive was issued 10 days after President Donald Trump signed an executive order establishing a new voluntary framework that allows the federal government to review national security risks of the most advanced AI systems for up to one month before their public release. The order confirms that participation in the vetting process is not mandatory for AI developers.

To comply with the administration’s directive, Anthropic announced it disabled access to the restricted models for all of its customers. The company added that it does not believe the government’s actions are justified by the potential security concerns the administration cited.

A coalition of top cybersecurity industry executives has also called on the Trump administration to reverse the directive, arguing the restriction ultimately benefits U.S. adversaries more than it limits their capabilities. More than 100 cybersecurity experts and company leaders, including representatives from Adobe and Nvidia, laid out their case in an open letter to the administration.

They acknowledged that Anthropic’s Mythos models are “quite good” at identifying software flaws and weaponizing exploits, but noted that “they are not uniquely good at these tasks.” Many signatories shared that they regularly use other open-source and foundational AI models to conduct security audits and cyber defense training. The letter concluded that removing the most capable cyber defense tools from U.S. teams “without a good reason” is reckless, as U.S. adversaries continue to rapidly advance their own AI-powered cyber capabilities.