NSA Deploys Anthropic Mythos for Cyber Work While Its Own Parent Department Calls Anthropic a Supply Chain Risk
The National Security Agency is actively running Anthropic’s Claude Mythos Preview, according to two sources who spoke to Axios. The disclosure puts the NSA in direct contradiction with its own chain of command: the Department of Defense, which oversees the NSA, has told procurement officials that Anthropic constitutes a “supply chain risk” — a designation that typically triggers vendor exclusion reviews across the entire department.
The gap between those two positions is not a bureaucratic lag. Both stances are current.
The Contradiction in Detail
The DoD supply chain risk designation for Anthropic surfaced earlier this month as part of a broader review of AI vendor relationships tied to national security. The classification was driven by concerns about foreign influence risk and the opacity of large foundation model training pipelines — arguments that have circulated inside the Pentagon since at least late 2025.
The NSA, however, is using Mythos. Per the Axios report, the model is being applied to cyber threat analysis and security research, which is precisely the domain where Mythos’s capabilities are most advanced. Anthropic’s own safety disclosure, published alongside the Mythos Preview release, identified the model as having unusually strong offensive and defensive cyber ability — one of the clearest dual-use evaluations an AI lab has ever published about its own model.
That same capability profile is presumably why the NSA wants access to it.
Access Is Restricted to 40 Organisations
Mythos Preview is not publicly available. Anthropic has limited distribution to roughly 40 organisations, primarily government agencies, defence contractors, and major financial institutions running security evaluations. The restricted rollout was explicitly designed to slow the spread of Mythos’s more dangerous capability profile while Anthropic and its partners assess the risk envelope.
That list now demonstrably includes an intelligence agency operating under a department that has formally questioned whether Anthropic should be a government vendor at all.
Anthropic CEO Met White House Officials April 18
Dario Amodei met with White House officials on Friday, April 18, the day before the Axios report appeared. The meeting’s agenda was not disclosed publicly, though it follows a pattern of Anthropic engaging federal agencies directly as the regulatory and procurement picture becomes more complicated.
The White House has separately signalled it wants Mythos access extended to major federal agencies — a posture that is now awkwardly aligned with the DoD’s supply chain risk designation.
Why It Matters
The NSA deployment makes it harder for the Pentagon to maintain a coherent position on Anthropic. A supply chain risk designation that coexists with active use by the department’s own signals intelligence arm is not a sustainable policy outcome. The likely resolution is one of two things: the DoD walks back the designation under pressure from the intelligence community, or the NSA use becomes a political problem that forces a formal inter-agency review.
What it is not is an accident. Someone inside the US government decided Mythos’s capabilities were worth more than procedural consistency with a vendor flag their own department issued.
That is the most accurate summary of where American AI security policy stands right now.