# CISA Deploys Anthropic AI for Cybersecurity Audits

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has operationally deployed Anthropic's advanced AI model, Mythos, to audit federal government software code repositories for vulnerabilities. This initiative represents a significant federal adoption of AI-driven cybersecurity tools aimed at automating large-scale code analysis to enhance vulnerability detection and cyber defense capabilities. Despite Anthropic's designation as a supply-chain risk by the Pentagon and ongoing regulatory challenges, CISA and other agencies such as the National Security Agency (NSA) continue to integrate Mythos into their cybersecurity operations under controlled conditions. This deployment signals expanding opportunities for AI technology providers in federal cybersecurity modernization and highlights evolving government policies balancing AI innovation with supply chain risk management.

- **Why this matters:** Procurement professionals should note the growing federal demand for AI-powered cybersecurity solutions that automate vulnerability discovery and code auditing.
- Agencies are increasingly prioritizing AI integration despite regulatory and supply chain risk concerns, indicating potential procurement complexities and the need for compliance with evolving federal AI guardrails.
- Vendors specializing in AI cybersecurity tools may find expanding opportunities within federal agencies, especially CISA and NSA, as these agencies seek advanced capabilities to accelerate vulnerability detection and remediation.
- Organizations should evaluate how AI-driven cybersecurity tools like Mythos impact contract requirements, risk assessments, and supply chain security considerations in upcoming federal procurements.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity, Artificial Intelligence
**Published:** July 13, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- National Security Agency (NSA)
- Pentagon
- Department of Defense (DoD)
- Office of Management and Budget (OMB)

### Vendors
- Anthropic (AI technology provider)
- OpenAI (AI product provider)

### Key Quotes
> The broader implication is that the vulnerability discovery race is accelerating. The same AI capabilities helping defenders identify weaknesses are also becoming available to sophisticated threat actors. Governments and enterprises should assume both sides are using increasingly capable AI systems and adjust their remediation timelines accordingly. Finding vulnerabilities faster only improves security if organizations can also fix them faster.
> — Ensar Seker, CISO at SOCRadar

> The Office of Management and Budget is working with Anthropic, industry partners and the intelligence community on guardrails before a modified Mythos is cleared for wider agency use.
> — Gregory Barbaccia, Federal Chief Information Officer

> The federal government can’t seem to decide what it thinks about AI in general, or Mythos, in particular. One week Anthropic is a supply-chain risk, the next week CISA is handing Mythos the keys to scan federal code for vulnerabilities. That inconsistency would be bad enough to start with, but because it’s not clear what Mythos is actually scanning, it’s much, much worse. Is this government-written code, or software built by third-party contractors and vendors? In-house bugs are one problem. Vendor bugs running across federal systems are a supply chain problem, and the public has a right to know which one this is.
> — Bronwen Aker, AI Research & Strategy Analyst at Black Hills Information Security

### Sources
- [US Cyber Agency Uses Anthropic Mythos to Audit Government Code for Bugs](https://gbhackers.com/us-cyber-agency-uses-anthropic-mythos) - gbhackers.com
- [U.S. Cyber Defense Agency Reportedly Using Anthropic's Mythos to Audit Government Code Repositories](https://cybersecuritynews.com/u-s-cyber-defense-agency-using-anthropics-mythos) - CyberSecurityNews
- [US cyber agency deploys Anthropic’s Mythos to detect software flaws: Report – Firstpost](https://www.firstpost.com/tech/us-cyber-agency-deploys-anthropics-mythos-to-detect-software-flaws-report-14029408.html/amp) - Firstpost