Federal Cyber Agency Reportedly Turning to AI to Hunt for Weaknesses in Government Software
CISA's specialist team is said to be using Anthropic's Mythos tool to scan federal systems for security flaws, in what could become a significant shift in how the U.S. government checks its own digital defenses.

Key points
- CISA, the U.S. Cybersecurity and Infrastructure Security Agency, is reportedly using an AI tool called Mythos, built by Anthropic, to scan government software for security flaws.
- The scans are being led by CISA's Attack Surface Evaluation team, a unit whose job is to find weaknesses in federal systems before criminals do.
- The reporting, first surfaced by SecurityWeek, is based on unnamed sources and hasn't been officially confirmed by CISA or Anthropic.
- No breach of government systems has been reported in connection with this program.
The federal agency responsible for protecting U.S. Government computer systems is reportedly bringing in AI to find the cracks in those systems first.
CISA is said to be using Mythos, developed by Anthropic, to run automated security scans across government software. A security scan here means the tool combs through code or running systems looking for vulnerabilities: weaknesses that criminals could exploit to break in or steal data.
Who is actually doing the scanning?
The work sits with CISA's Attack Surface Evaluation team, which runs simulated hacking exercises where security professionals legally attempt to break into systems before real attackers find a way in. Adding AI to that process would let the team cover more ground than human reviewers working alone.
The reports come from unnamed sources. Neither CISA nor Anthropic has confirmed the arrangement publicly. No procurement notice or formal disclosure has been published, so the regulatory picture is incomplete.
That gap matters. When federal agencies adopt new tools for security assessment, questions of oversight and procurement rules follow. CISA operates under the Federal Information Security Modernization Act, which governs how agencies manage and report on their security programs. Whether AI-assisted scanning of this kind requires new policy guidance isn't clear from available information. Our earlier story on CISA's updated TIC 3.0 guidance shows the agency has been pushing hard on federal network modernisation since at least July; Mythos would be the most operationally direct step yet.
We reported in June that Anthropic's Mythos specifically changes attacker economics, and that most organisations are still failing older controls long before AI enters the picture. Deploying the same model on the defence side is the more interesting test.
Should you worry?
For most people the stakes are indirect but concrete. Government software handles tax records and benefit payments. A weakness found and quietly patched by CISA's team is one a criminal never gets to use. If Mythos accelerates that discovery process, anyone whose personal data sits in a federal database benefits.
No vulnerability has been publicly disclosed and no data exposure has been reported. Members of the public don't need to take any action.
What to watch: whether CISA or Anthropic issues any formal statement, and whether Congress asks procurement questions. That's where this story goes next.



