# NHS England Restricts Software Access

NHS England has mandated that all internally developed software repositories be made private by default by May 11, 2026, reversing its prior open-source policy due to concerns that advanced AI tools, such as Anthropic's Mythos, could exploit publicly accessible code to identify cybersecurity vulnerabilities. This temporary measure aims to mitigate AI-driven hacking risks while NHS England evaluates the broader implications of AI on software security.

- Procurement professionals should anticipate increased demand for secure software development practices and tools that support private code management.
- Contractors providing software solutions to NHS England may need to adjust to stricter access controls and enhanced cybersecurity requirements.
- This shift signals a growing emphasis on AI-related cybersecurity risk management in public sector IT procurement.
- Organizations involved in healthcare IT should consider the impact of AI vulnerabilities on open-source policies and prepare for potential changes in contract terms related to software security.

**Jurisdictions:** sled
**Industries:** Healthcare, Information Technology
**Topics:** Cybersecurity, Artificial Intelligence
**Published:** May 05, 2026

### Government Entities
- NHS England
- AI Security Institute

### Vendors
- Anthropic (developer of Mythos AI model)

### Key Quotes
> I am convinced that closing all their excellent open-source work is the wrong move for the NHS.
> — Terence Eden, Public Sector Transparency Advocate

### Sources
- [NHS England withdraws public software over AI hacking fears](https://www.computing.co.uk/news/2026/security/nhs-england-withdraws-public-software-over-hacking-fears) - Computing UK