Anthropic's Mythos/Claude Security and US Government Tensions
TECH

Anthropic's Mythos/Claude Security and US Government Tensions

64+
Signals

Strategic Overview

  • 01.
    Anthropic launched Claude Security in public beta on April 30, 2026, available to Claude Enterprise customers, using Claude Opus 4.7 to scan codebases, trace data flows, and propose fixes with confidence ratings.
  • 02.
    The Trump White House is blocking Anthropic's plan to expand Mythos access from roughly 50 organizations to 120, citing fears the cyber-capable model could fall into adversarial hands.
  • 03.
    On May 1, 2026, the Pentagon announced classified-network AI deals with OpenAI, Google, Microsoft, AWS, Nvidia, xAI, and Reflection — explicitly excluding Anthropic, which Pentagon CTO Emil Michael said remains a supply chain risk.
  • 04.
    Despite the broader Anthropic ban, the NSA is reportedly already using Mythos and the Treasury Department has requested access — a contradiction that has prompted the White House to draft guidance carving out Mythos from the supply-chain-risk designation.

Banned and Indispensable: The U.S. Government's Bifurcated Anthropic Posture

On May 1, 2026, the Pentagon awarded classified-network AI work to seven firms — OpenAI, Google, Microsoft, AWS, Nvidia, xAI, and Reflection — and pointedly left Anthropic off the list. Pentagon CTO Emil Michael told reporters that Anthropic remains a supply chain risk, the same harsh designation typically applied to firms with foreign-adversary ties. By any normal procurement logic, that should be the end of Anthropic's federal story for the foreseeable future.

It isn't. The same reporting reveals the National Security Agency is already using Mythos despite the ban, and the Treasury Department has requested access. Pentagon CTO Michael himself separates Mythos from the rest of Anthropic's posture, calling it a 'separate national security moment.' The White House, having earlier blocked Anthropic's plan to expand Mythos access from roughly 50 to 120 organizations, is now drafting guidance to let agencies onboard Mythos around the supply-chain-risk designation. Treasury Secretary Scott Bessent and Fed Chair Jerome Powell have met with bank CEOs about Mythos's financial-system implications. The U.S. government's working stance is therefore that Anthropic is too dangerous to use, and Mythos is too dangerous not to.

That contradiction is the structural insight: federal procurement and national-security workflows are running on different operating systems, and Mythos is the wedge that exposes the gap. The seven-firm classified deal locks in Anthropic competitors for the foreseeable future even if the supply-chain-risk label gets struck. But the Mythos carve-out, if it lands, creates a precedent that capability-tier strategic models can route around standard procurement bans. That is a structural shift in how the federal government will buy frontier AI.

The Safety Clause That Triggered a Blacklist

The standard reading of the Anthropic-Pentagon fight is that it's about export risk and trustworthiness. The timeline tells a different story. Pentagon GenAI.mil negotiations stalled in September 2025 because Anthropic refused to permit Claude's use for fully autonomous weapons or domestic mass surveillance. Defense Secretary Pete Hegseth issued an ultimatum on February 24, 2026 demanding unrestricted DoD use of Claude for 'all lawful purposes.' Anthropic refused on February 26. President Trump posted his 'immediately cease' directive on February 27. The supply-chain-risk label landed March 6.

The sequence is unambiguous: Anthropic's usage policy — not its supply chain, not its security posture, not foreign exposure — triggered a designation historically reserved for firms with adversary ties. Judge Rita F. Lin's March 26 preliminary injunction explicitly found the government acted retaliatorily. The D.C. Circuit on April 8 nonetheless refused Anthropic's stay request, citing reluctance to force DoD to keep an unwanted vendor. So the legal record now contains both a federal court finding of retaliation and an appeals decision treating the dispute as a normal vendor matter.

For every other AI lab watching, the lesson is operational: published usage policies are now procurement risk. The terms in your acceptable-use document are not just a values statement — they're a procurement filter that the federal government can reverse-engineer into a blacklist. Anthropic is the first lab to discover where that line sits, and it cost them a $200 million Pentagon contract before the Glasswing partners and Mythos credits arguably bought back the leverage.

The Six-Month Defender Window

Mythos's measured capability is not subtle. UK AISI evaluations put it at 73% on expert-level cyber tasks, up from zero before April 2025. In Firefox exploit testing, Mythos produced 181 working exploits and achieved register control on 29 more, against just two for Opus 4.6 across several hundred attempts. It crashed 595 OSS-Fuzz tier 1-2 targets and achieved full control-flow hijack on ten fully patched programs. Expert reviewers agreed with its severity scoring on 89% of 198 manually reviewed reports. Kemba Walden cites an 83% first-attempt exploit-creation rate.

This is what Alex Stamos is racing against when he tells Platformer that defenders have 'something like six months before the open-weight models catch up to the foundation models in bug finding.' Project Glasswing's coalition — AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, Palo Alto Networks — is structured around that window: get critical-infrastructure software hardened before commodity models reach equivalent capability. Anthropic's $100M Mythos credit pool plus $4M in donations to OpenSSF, Alpha-Omega, and the Apache Software Foundation underwrite that timeline.

The skeptics push back hard. Reddit's r/Anthropic top thread argues Mythos is 'mostly hype' — pointing out that the thousands-of-zero-day claim rests on 198 manually reviewed cases, and that bugs identified included reproductions of issues open-weight models had already found. Tom's Hardware called it 'a sales pitch.' Both can be true: the capability number can be real and the marketing framing can be inflated. What matters operationally is the proliferation curve. If Stamos's six-month estimate is right, the policy fight over Mythos access will look quaint by November 2026 because adversaries will have rough equivalents on hardware they already control.

By the Numbers

By the Numbers
Mythos vs Opus 4.6: working Firefox exploits produced across hundreds of attempts

The scale of the Anthropic-government collision is best read in the figures themselves. On capability: Mythos scores 73% on expert cyber tasks per UK AISI — a domain where no model could complete tasks before April 2025. It produced 181 working Firefox exploits versus Opus 4.6's two. Severity-scoring agreement with expert reviewers ran 89% across 198 reports, and 98% within one severity level. Kemba Walden's 83% first-attempt exploit success rate sits on top of all that.

On money and access: Anthropic committed up to $100M in Mythos usage credits to Glasswing partners, plus $4M in open-source security donations ($2.5M to Alpha-Omega/OpenSSF via the Linux Foundation, $1.5M to the Apache Software Foundation). Mythos access today reaches roughly 50 organizations; Anthropic asked the White House to expand to 120 and was blocked. The Pentagon contract Anthropic lost was worth $200M (signed July 2025). The May 1, 2026 classified-network deals went to seven competitors.

On market impact: Black Duck has cut headcount 8% since end-2024, Snyk 9%, Veracode 19% — compression that Claude Security's bundled pricing inside Claude Code on the Web is expected to accelerate. The pattern across all three rows is the same: capability and market disruption are scaling faster than the procurement and policy systems built to govern them.

Historical Context

2025-07-01
Anthropic signed a $200 million contract with the Pentagon for AI services.
2025-09-01
Talks stalled after Anthropic refused to permit Claude's use for fully autonomous weapons or domestic mass surveillance.
2026-02-24
Issued ultimatum demanding Anthropic allow unrestricted DoD use of Claude for 'all lawful purposes'; Anthropic refused two days later.
2026-02-27
Posted directive ordering federal agencies to 'immediately cease' using Anthropic technology.
2026-03-06
Pentagon labeled Anthropic a 'supply chain risk' — a designation historically reserved for foreign-adversary-linked firms.
2026-03-09
Filed two lawsuits against the federal government in N.D. Cal. seeking to enjoin the supply-chain-risk designation.
2026-03-26
Granted preliminary injunction blocking enforcement of the Pentagon ban, finding the government acted retaliatorily.
2026-04-08
Denied Anthropic's stay request in a related appeal, citing concern about forcing DoD to keep an unwanted vendor.
2026-04-09
Unveiled Mythos Preview and Project Glasswing coalition for gated cybersecurity research deployment.
2026-04-17
Anthropic CEO met White House Chief of Staff in a 'productive and constructive' meeting on Mythos and AI policy.
2026-04-30
Launched Claude Security in public beta for Claude Enterprise customers, built on Opus 4.7.
2026-05-01
Announced classified-network AI deals with OpenAI, Google, Microsoft, AWS, Nvidia, xAI, and Reflection — excluding Anthropic.

Power Map

Key Players
Subject

Anthropic's Mythos/Claude Security and US Government Tensions

AN

Anthropic

AI lab launching Claude Security beta and Mythos research preview while suing the federal government to block the Pentagon's supply-chain-risk designation; CEO Dario Amodei met with White House Chief of Staff Susie Wiles on April 17, 2026 in a 'productive and constructive' meeting.

WH

White House / Trump Administration

Blocked Anthropic's expansion of Mythos access from ~50 to 120 firms, previously directed agencies to 'immediately cease' using Anthropic products, and is now drafting guidance to bring Anthropic back via a Mythos-specific carve-out.

PE

Pentagon / Department of Defense

Labeled Anthropic a 'supply chain risk' in March 2026 — a designation typically reserved for foreign-adversary-linked firms — and awarded classified-network AI work to seven competitors. CTO Emil Michael distinguishes Mythos as a 'separate national security moment'.

OP

OpenAI, Google, Microsoft, AWS, Nvidia, xAI, Reflection

The seven firms cleared to deploy AI in DoD classified networks under May 1, 2026 deals — direct beneficiaries of Anthropic's exclusion from the Pentagon procurement portfolio.

PR

Project Glasswing partners

Coalition of critical-infrastructure firms — AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks — receiving gated Mythos Preview access and absorbing Anthropic's $100M usage-credit commitment.

JU

Judge Rita F. Lin (N.D. Cal.)

Granted preliminary injunction on March 26, 2026 blocking enforcement of the Pentagon's supply-chain-risk designation against Anthropic, finding the government acted retaliatorily.

Source Articles

Top 5

THE SIGNAL.

Analysts

"'Mythos, Anthropic's most advanced model, should be a clarion call to address weaknesses in our cyber ecosystem.' Walden frames Mythos as a defender's wake-up call rather than a marketing event."

Kemba Walden
Former U.S. National Cyber Director

"'We only have something like six months before the open-weight models catch up to the foundation models in bug finding' — making the Project Glasswing coalition a race against capability proliferation."

Alex Stamos
Chief Product Officer, Corridor (former Facebook and Yahoo security lead)

"'AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back.'"

Anthony Grieco
Chief Security and Trust Officer, Cisco

"'This is not only a game changer for finding previously hidden vulnerabilities, but it also signals a dangerous shift' — capturing Mythos's dual role as defender breakthrough and offensive weapon."

Lee Klarich
Chief Product Officer, Palo Alto Networks

"'What we need to do is look at this as a wake-up call to say, the storm isn't coming — the storm is here.' Knight argues the AI-cyber risk landscape is no longer prospective."

Alissa Valentina Knight
CEO, Assail

"'Together we're helping our clients close the critical gap between threat and remediation' — framing Claude Security as compressing the time between vulnerability discovery and fix."

Adnan Amjad
Partner & US Cyber Leader, Deloitte
The Crowd

"NEWS: Anthropic's new model, Claude Mythos, is so powerful that it is not releasing it to the public. Instead, it is starting a 40-company coalition, Project Glasswing, to allow cybersecurity defenders a head start in locking down critical software."

@@kevinroose0

"We're putting @Anthropic's Claude Opus 4.7 to work across the Falcon platform and Project QuiltWorks, accelerating vulnerability discovery and remediation for customers. This comes on the heels of the launch of Claude Security, built on Opus 4.7, in public beta for Claude Enterprise customers."

@@CrowdStrike0

"Anthropic sues Pentagon over "supply-chain-risk" Anthropic filed two lawsuits against the Pentagon after being labeled a rare "supply chain risk," a designation usually reserved for foreign adversaries. The company argues the move violates its First Amendment rights."

@@kimmonismus0

"Mythos is Mostly Hype... (also the bugs it found were mostly unexploitable and exaggerated...)"

@u/InterestProof15261200
Broadcast
Claude Mythos is too dangerous for public consumption...

Claude Mythos is too dangerous for public consumption...

Why Anthropic's Mythos Is Sparking Alarm

Why Anthropic's Mythos Is Sparking Alarm

Anthropic's Mythos: What It Is and What It Is Capable of

Anthropic's Mythos: What It Is and What It Is Capable of