White House told agencies to expect Mythos access. The memo said safeguards are being developed.
What the memo said
An internal message from Gregory Barbaccia, federal chief information officer at the White House Office of Management and Budget, asked senior technology and cybersecurity officials across major departments to prepare for possible access to Anthropic's Mythos model. The note didn't promise a delivery date or a firm timetable. Instead, it flagged that a modified version of the model could be made available once the Office of Management and Budget finishes designing guardrails.
The agencies copied on the memo included representatives from Defence, the Treasury, Commerce, Homeland Security, Justice and State. That list suggests Washington is treating the potential rollout as broadly relevant to federal cyber-defence workflows and to departments that handle critical infrastructure, financial stability and national security.
The instruction came as part of a stepped-up engagement between Anthropic and US officials over research access to its most capable frontier models. Anthropic has been running a gated preview of what it calls Claude Mythos as part of Project Glasswing. The company describes Mythos as far more capable in tasks such as coding and automated agent work, and especially powerful at identifying software vulnerabilities—an ability that has made some government and financial leaders wary.
Why Mythos is tightly controlled
Anthropic launched Mythos through a restricted research channel and has limited its use to select partners. The company says Mythos Preview has already found thousands of zero‑day vulnerabilities across critical systems in partner trials, which is precisely why the model hasn't been opened up commercially.
Anthropic frames Project Glasswing as a way to let trusted institutions test and harden core infrastructure while keeping potentially dangerous capabilities under strict supervision.
That promise of strong vulnerability detection is a double‑edged sword. The same pattern‑recognition that helps spot flaws could, in the wrong hands, be directed to find and exploit weaknesses. Treasury Secretary Scott Bessent raised those kinds of concerns when he warned bank executives about the risks linked to models with Mythos‑level capability. Jerome Powell, chair of the Federal Reserve, also discussed the potential dangers with banking leaders, signalling that financial regulators are watching closely.
Federal interest in Mythos is partly practical. Officials in the Treasury’s cybersecurity units have sought early access to models that can automate and accelerate the discovery of software defects. Faster detection is useful in patching vulnerable services and preventing cascades of failure in systems that underpin payments, trading, and public services. But the benefits only materialise if the government can control how the model is used, who can run sensitive queries, and where the underlying code executes.
How access could be limited
The OMB memo suggests that any federal access would be to a modified, more tightly constrained variant of Mythos rather than the version Anthropic described in its initial preview. That approach mirrors how governments often get early access to advanced tools: through bespoke deployments with additional monitoring, usage limits, and technical interfaces that reduce the chance of misuse.
Possible measures under consideration include run‑time monitoring of prompts and outputs, whitelists of allowed tasks, human‑in‑the‑loop review for sensitive queries, and network isolation so the model can't be used to execute arbitrary code outside approved testing environments. Agencies are also expected to weigh legal and procurement issues: who bears liability if the model suggests harmful actions, and how to acquire and host the service under federal security standards.
Those practical questions aren't new. Large departments already operate high assurance environments for classified systems and for threat hunting. But integrating a frontier AI model raises fresh operational challenges because its outputs are probabilistic and can steer human operators in unexpected directions. That puts a premium on careful, ongoing oversight.
What agencies might use Mythos for
Officials are most interested in applying Mythos to software‑security triage, vulnerability scanning, and automated code review at scale. The Treasury's interest has included using the model to help find flaws in widely used financial software and in third‑party supply chains. Homeland Security and Justice may see value in enhanced forensic tools and in automating certain defensive cyber functions.
Anthropic has positioned Project Glasswing partners to test the model on precisely those tasks—helping institutions discover flaws before adversaries do. For agencies, the attraction is clear: human analysts are swamped by alerts and by thousands of lines of code; a model that reliably highlights the most critical faults would save time and reduce risk.
But the agencies will have to accept trade‑offs. Greater automation can speed detection, but it can also generate false positives or suggest remediation steps that require careful vetting. Training staff to interpret model outputs, and to avoid treating them as definitive, will be part of any deployment plan.
Industry and market ripple effects
Government use of a frontier model like Mythos could also shape public perception of Anthropic’s technology. Adoption by federal agencies tends to be seen as a trust vote: it implies a vendor can meet high security and procurement standards. That perception could influence how private firms and international bodies view Anthropic’s place among rivals offering advanced AI services.
Some market observers are already pricing in the effect. Traders and analysts have noted that government deployment may feed into public benchmarks, and that real‑world agency feedback could alter how the model performs in standard evaluations. For Anthropic, the upside is a potential reputational boost and a stream of operational data; the downside is the political scrutiny that comes with federal use of novel capabilities.
Next steps and timeline
The OMB memo told agency officials to expect more detail in the weeks ahead. It didn’t set a deadline or lay out how long pilots might run. What's clear is that the rollout, if it happens, will be gradual, gated and closely supervised. Agencies will likely begin with small, controlled tests in secure environments before expanding any use to production systems.
Legal, procurement and compliance teams across departments will need to agree a framework that covers data handling, record‑keeping, and incident response. And because the model’s strength in cyber tasks invites both defensive uses and potential offensive misuse, policymakers will keep a close eye on governance arrangements and on how Anthropic implements the promised safeguards.
For now, the most concrete item on the table is the memo from Gregory Barbaccia, which starts the formal process of preparing agencies for a possible, constrained deployment of Mythos. Agencies and Anthropic will decide the shape of any partnership through the coming weeks as technical reviews and policy debates proceed.
Related Articles
- OpenAI upgrades Codex with desktop agent powers
- InsightFinder raises $15M to track where AI agents fail
The instruction came in a memo from Gregory Barbaccia, federal chief information officer at the Office of Management and Budget.
This article was created with AI assistance.