In a striking illustration of how artificial intelligence is reshaping national security, Anthropic's frontier model Mythos reportedly uncovered vulnerabilities in classified United States government systems during testing — within hours. Yet the same export-control dispute that has roiled the AI industry in recent weeks has now cut parts of the National Security Agency off from the very model that found those flaws.

The reports, published on June 24, 2026, paint a picture of an AI system powerful enough to expose cracks in some of the government's most guarded systems, at precisely the moment the government's own policy has restricted access to it. "The AI model that broke into NSA systems is now the one the NSA cannot use," as one headline summarized the paradox. For more context on this story, see our ongoing more AI stories.

A Model That Found Vulnerabilities in Hours

According to Reuters, reporting on an Associated Press account, Anthropic's Mythos model found vulnerabilities in classified US government systems. CNBC similarly reported that the model found flaws in classified US systems, citing an official. Euronews, Cybernews, and TechRadar all corroborated the finding, with multiple reports emphasizing that the vulnerabilities were uncovered within hours of testing.

The detail is significant. Traditional security auditing of classified systems is a slow, labor-intensive process, often requiring teams of cleared specialists and weeks or months of effort. An AI model capable of surfacing real vulnerabilities in a matter of hours suggests a dramatic acceleration in offensive security capability — and raises urgent questions about how such power should be governed.

Mythos has been promoted by Anthropic as a cybersecurity force, and the company has previously framed its frontier models as a potential "reckoning" for the security status quo. The latest findings appear to bear that framing out, demonstrating concrete, high-impact results against hardened government targets.

The Export-Control Dispute

The discovery, however, is overshadowed by the policy fight surrounding Anthropic's most powerful models. The New York Times reported that the NSA "lost access to a powerful AI model amid [an] Anthropic dispute," and the federal technology outlet Nextgov/FCW reported that parts of the NSA lost Mythos 5 access amid an Anthropic supply-chain dispute. MSN reported that the NSA lost access to Anthropic's AI after export controls took effect.

This dispute traces back to an earlier directive. As previously reported, the US government issued an export-control order that forced Anthropic to disable its top-tier models — including the Fable and Mythos lines — for foreign nationals. That order, intended to keep frontier AI out of the hands of foreign adversaries, has produced an unintended consequence: it has also disrupted access for the US government's own intelligence agencies.

The result is a deep irony. The same national-security logic that motivated the export controls is now depriving agencies like the NSA of a tool that was demonstrably effective at finding vulnerabilities in American systems.

The Governance Dilemma

The episode crystallizes one of the central dilemmas of AI governance: how to capture the enormous defensive and offensive potential of frontier models without creating unacceptable risks. A model that can find classified vulnerabilities in hours is a powerful asset for defenders who want to patch those flaws before adversaries exploit them. But that same capability, if it leaked to malicious actors, could be catastrophic.

Export controls are one tool policymakers have reached for, but the Mythos case shows their limitations. A blunt restriction that cuts off foreign access can also hamstring domestic agencies, disrupt commercial operations, and push capability into less accountable corners. The fact that the restriction caught the NSA itself in its net suggests the policy was drafted with too little attention to how these models are actually used inside the government.

Competing Pressures

Anthropic, for its part, has emphasized its commitment to safety and responsible deployment, and has cooperated with government evaluations of its models. But the company is also navigating intense commercial and geopolitical pressure. Pulling its most capable models off the market — even temporarily, and even for foreign users — carries real costs, both in revenue and in the strategic advantage those models confer.

Meanwhile, the findings about Mythos are likely to intensify the debate over AI in cybersecurity. If frontier models can routinely uncover zero-day-style vulnerabilities in hardened systems, the entire calculus of digital defense changes. Defenders will need faster ways to absorb and act on AI-generated findings, and policymakers will need frameworks that distinguish between using AI to secure systems and using it to attack them.

What Comes Next

The immediate question is whether the access dispute between the NSA and Anthropic will be resolved. Allowing intelligence agencies to retain access to a model that proved effective at finding vulnerabilities seems an obvious priority, but it sits in tension with a broader policy designed to restrict the model's reach. Reconciling the two will likely require a more granular approach to export controls — one that distinguishes between trusted domestic users and the foreign access the controls were meant to block.

The Mythos episode is, in many ways, a preview of the challenges ahead. Frontier AI models are becoming powerful enough to reshape fields as sensitive as national cybersecurity, and the policies meant to govern them are struggling to keep pace. That an AI model could expose flaws in classified systems within hours, only for the government to lose access to it days later, is a perfect distillation of the tension between capability and control that will define the AI era.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →