NSA red-team test: Anthropic Mythos penetrated classified systems in hours, triggering first AI model export ban
On June 11, Anthropic's Mythos AI model participated in an authorized NSA internal red-team exercise and reportedly gained access to nearly all targeted classified systems within hours, prompting NSA Director General Joshua Rudd to brief lawmakers on the results. On June 12, the Trump administration directed Anthropic to restrict access to Fable 5 and Mythos 5 exclusively to U.S. citizens. Since nationality verification in real time is impractical, Anthropic disabled access to those models for all customers.
This marks the first time the United States has applied export controls directly to an AI model rather than to the hardware or chips powering it, a landmark regulatory precedent in AI national security governance. Allied governments within the Five Eyes alliance (Australia, Britain, Canada, New Zealand) were caught off guard, with permissions revoked without warning. Britain's AI Security Institute, the world's leading body for testing frontier AI models, was also locked out.
Anthropic disputed the directive, saying the government cited national security concerns but did not provide specific details, though it believed the government had become aware of a jailbreak method that could bypass Fable 5's safety guardrails. Anthropic characterized the jailbreak as narrow and claimed the same vulnerability exists in other publicly available models like OpenAI's GPT-5.5 that face no such controls. The incident highlights the government's growing view of frontier AI capabilities—especially cybersecurity prowess—as dual-use national security assets requiring direct control.
Sources
- Primary source
- Tom's Hardware: Mythos breach during NSA red-team test
“NSA Director Joshua Rudd told Senator Mark Warner that Mythos broke into almost all classified systems within hours during controlled red-team test. June 12 ban marked first export controls on AI model, not hardware.”
- CNN: Anthropic suspends Mythos and Fable after export control directive
“US government ordered Anthropic to suspend all access by foreign nationals to Mythos 5 and Fable 5. Anthropic disputes directive, says jailbreak is narrow and found in other models.”
- Cyber Security News: NSA classified systems breach
“Mythos infiltrated nearly all NSA classified systems during authorized red-team evaluation. Five Eyes partners caught off guard; Britain's AI Security Institute locked out.”