Anthropic’s Mythos model found vulnerabilities in classified US government systems, official says
WASHINGTON (AP) — A U.S. official told The Associated Press on Tuesday that one of Anthropic’s artificial intelligence models had identified vulnerabilities in highly sensitive and secure U.S. government computer systems during a testing exercise.
The official, who spoke on the condition of anonymity to discuss the matter, said Anthropic had teamed up with U.S. intelligence agencies to conduct tests using the company’s Mythos model. It had identified certain vulnerabilities within hours, but that does not mean the model was able to exploit them within that time, the official said.
The official said the testing was done through an Anthropic initiative called Project Glasswing, which brought together tech giants and other companies in hopes of securing the world’s critical software from “severe” fallout that the Mythos model could pose to public safety, national security and the economy.
Democratic Sen. Mark Warner of Virginia had briefly mentioned the testing during a June 11 hearing before the Senate Committee on Banking, Housing, and Urban Affairs. Warner had said, “This tool broke into almost all of our classified systems, not in weeks but in hours.” He attributed the information to the head of the National Security Agency and U.S. Cyber Command, who is Gen. Joshua Rudd.
Despite the recent cooperation between Anthropic and U.S. agencies to test for vulnerabilities, tensions between the California company and the administration have been growing. Anthropic has raised concerns over how the administration would use its AI, while the administration has restricted the use of some of Anthropic’s models.
The administration issued a directive earlier this month requiring Anthropic to prevent foreign nationals from using its latest artificial intelligence models, known as Fable 5 and Mythos 5. Anthropic released Fable widely earlier this month. That model is a limited version of the more advanced Mythos, to which the company has tightly limited access due to cybersecurity fears.
Anthropic said it disabled the models for all of its customers to comply with the administration’s directive, but added it did not believe the steps taken by the government were warranted by the concern it flagged about a potential security issue.
The episode lands inside a tangle the U.S. government has not resolved. The NSA has been authorised to keep using Mythos on classified networks, and parts of the intelligence community and the Cybersecurity and Infrastructure Security Agency have been testing it. At the same time, the administration forced Anthropic to disable Mythos and its public counterpart Fable on June 12, after a separate dispute in court.
Anthropic has not disclosed what the test found, and the agencies involved have said little on the record. The company has finished training a successor to Mythos, a sign the capability is advancing regardless of how the politics settle.
Through Project Glasswing, Anthropic and approximately 50 partners have used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities across systemically important software. Progress on software security used to be limited by how quickly vulnerabilities could be found; now it is limited by how quickly they can be verified, disclosed, and patched.