← Anthropic Pentagon Watch

Anthropic’s Mythos Hits CISA as AI Controls Splinter (July 14, 2026)

July 14, 2026 · 8m 4s · Listen

Three weeks ago Washington called this model a supply-chain risk. Today it's reading Washington's own code for holes. If you're just joining, Anthropic's been fighting the Pentagon over whether Claude can do classified military work while the company sticks to its own limits on autonomous weapons and mass surveillance. The courts have sent conflicting signals on whether the supply-chain-risk designation is even enforceable — leaving agencies and contractors to decide how much risk they'd tolerate on their own. This is Anthropic Pentagon Watch. Today — CISA leans in, India slams the brakes, and Washington quietly panics about cheap Chinese models. Let's start inside the cyber agency. From Raphael Satter at Reuters:

The U.S. cyber defense agency CISA is using Anthropic’s AI model Mythos to audit government software, three people familiar with the matter said on Monday, another sign of government enthusiasm for adopting the AI startup’s tools even as the company navigates an ongoing standoff with the White House.

Update on that Anthropic-White House supply-chain fight: per Reuters, CISA is now running Mythos to audit government code. So the model Washington branded a supply-chain risk five weeks ago is now reading Washington's own software for holes. It's CISA's Attack Surface Evaluation team — the hacking-exercise crew — pointing Mythos at other agencies' repositories. That's the single most sensitive read access you can hand a vendor, and it's a vendor that was under a global ban 33 days ago. And the sources say the audits have already turned up a large number of bugs. FedRAMP High covers a chat surface — ingesting whole federal codebases is a different attack surface entirely. I keep coming back to this: what's the audit trail on the auditor? Right — three people familiar, no published criteria, and CISA's spokesman said he'd check, then went quiet. Great. The agency defending federal networks won't say what standard it cleared the model against. Lawfare argued a few weeks back that core governance running on one vendor's model is a risk all by itself. Well — here's what that looks like. A federal cyber agency now depends on Mythos to find its bugs, while the administration is still in a classified-use standoff with that same company. That's the whole trajectory in one line. Designated a threat in June, embedded in the cyber-defense stack in July. Nothing on paper changed — the criteria still don't exist. Only the deployment did. Here's Just Security:

In a June 2026 filing for a lawsuit against Elon Musk’s xAI, the Pentagon’s Chief Digital and Artificial Intelligence Officer submitted a sworn declaration stating that the government-oriented version of xAI’s chatbot Grok had contributed to workflows in Palantir’s Maven Smart System – the DoD’s flagship AI-enabled software platform– to deploy “over 2,000 munitions to 2,000 distinct targets within 96 hours” during the Iran war.

Just Security is walking through the Congressional proposals for civilian protection when military AI does the targeting — and they pin it to the record from this year. In February, the Wall Street Journal reported Claude was used in the Maduro raid. Same month, Anthropic objected to the Pentagon stripping its proposed safeguards, and got branded a supply-chain risk for the trouble. So read that sequence back. The safeguards Anthropic wanted in the contract? Those were about targeting. The Pentagon said no, went to OpenAI instead, and now CENTCOM's admiral is on record saying warfighters are leveraging this stuff after the Iran strikes. And the legal frame Just Security lands on is IHL — international humanitarian law, the lawful-targeting rules. That's the closest anyone's come to defining what constraints actually bind a model in the kill chain, versus a vendor's press release about being the careful one. Right, and Congress writing safeguards into statute is different from a lab writing them into a contract clause the customer can just delete. If it's in statute, the Pentagon can't brand you a supply-chain risk just for asking for it. Vrinda Tulsian, writing in ThePrint:

New Delhi: A department under the Ministry of Electronics and Information Technology (MeitY) has asked ministries not to deploy OpenAI and Anthropic’s models for cybersecurity and related functions for now, ThePrint has learnt, days after the two companies approached several ministries with their proposals.

Same week CISA is running Mythos inside the federal cyber stack — which we just hit — India's MeitY tells its ministries to hold off on the exact same class of models. Two allied governments, opposite directions, same week. And it's not a leak or a rumor — ThePrint says there's an office memorandum circulated telling ministries not to deploy prematurely. That's a paper trail. A hold order with a document number. What I like here? A foreign regulator treated the category evenly. MeitY named OpenAI and Anthropic. Both. Commerce spent June singling out one lab; Delhi looked at the whole category and said, not yet. The detail that matters: reps from both companies were physically meeting ministries to press for deployment, per ThePrint. So the hold order landed right in the middle of an active sales push. And the number of ministries approached, the level of the meetings — couldn't be confirmed. So we know they pitched hard, we just don't know how deep it went. This one's from Firstpost:

The United States is reassessing how it governs advanced open-source artificial intelligence as Chinese AI development accelerates, prompting fresh discussions between the Trump administration and leading technology companies over how America’s most capable models should be released.

The Washington Post reporting says the whole framework is capability-based — you benchmark U.S. open-source models against China's best open-source systems before you release. Safety is taking a back seat to market-share pressure. And it lands the same morning we confirmed CISA is running Mythos on federal code. So the administration is standing up a national-security release regime around the exact vendor it branded a supply-chain risk in June. Right — businesses are grabbing cheap Chinese models and Chinese hardware, per Firstpost, and suddenly every export-control 'threat assessment' from a month ago reads like it was really about who's losing customers. Though credit where it's due — for two years the U.S. strategy was chip export controls and nothing on how you actually govern releasing an open model. This is the first admission that restricting silicon didn't slow the race. Gate the release, sure. Just don't dress a competitiveness panic up in threat language. If you're benchmarking against Chinese models, say the quiet part: this is about the scoreboard. If you follow Anthropic’s Pentagon work, you might also like AI Daily Briefing — top AI news for engineers, founders, and investors every weekday, with real capabilities versus demo hype explained fast. Find it wherever you listen to podcasts.

What we’re watching next: whether Chinese developers make Mythos-class open-source systems freely downloadable over the next six to 12 months. We’ll keep checking that.

You’ll find links to every story from today’s briefing in the show notes, so if one of them stuck with you, that’s the place to dig in. That’s Anthropic Pentagon Watch for today. This is a Lantern Podcast.