Industry Impact3 min read

Anthropic Plants Engineers Inside NSA for Cyberattacks

June 10, 2026Synthesized from 1 source: TLDR AI

Anthropic has placed about six of its own engineers inside the U.S. National Security Agency to help deploy Mythos, a cyber AI model it refuses to release publicly, for offensive operations against foreign networks, even as it sues the Pentagon and files for a near-trillion-dollar IPO.

The story Anthropic tells about itself is one of a company with limits. It walked away from a $200 million Pentagon contract rather than let its AI be used for mass domestic surveillance or fully autonomous weapons. When the Defense Department retaliated in March by labeling it a national security threat, putting it in the same category as Huawei, Anthropic sued. That positioning has been central to how it presents itself to customers, investors, and regulators.

What was not in the public positioning: about six Anthropic engineers, placed inside the National Security Agency, helping deploy Mythos for offensive cyber operations. The Financial Times reported this arrangement this week, citing people familiar with it. Those engineers are customizing the model for specific uses. One person familiar with the work told the FT it would be useful for infiltrating networks in countries like China and Iran.

The NSA sits inside the Department of Defense, the same department Anthropic is currently suing. That detail is not a technicality. It means Anthropic is simultaneously fighting the Pentagon in court and sending its engineers to work inside a Pentagon-run agency. The legal fight was about domestic surveillance and autonomous weapons. The NSA arrangement is aimed outward. Anthropic drew the line at uses it found legally and reputationally risky at home. The offensive foreign intelligence work did not cross that line.

Mythos is the model Anthropic says is too dangerous to release publicly. The company's own red team showed it can find and exploit serious software flaws in every major operating system and web browser, with working attacks built overnight for under $2,000. Britain's AI Security Institute tested it independently and found it solved 73% of expert-level security tasks that no AI had completed before April 2025. It also became the first AI to complete a simulated 32-step corporate network attack from start to finish.

For the 150 or so organizations now in Anthropic's Project Glasswing program, including NATO, ENISA, Samsung, and financial market operators, the stated purpose is defensive: find the flaws in your own systems before an attacker does. Those partners have surfaced over 10,000 high or critical-severity flaws since April. Cloudflare alone found 2,000 bugs in its own systems. That is a real and useful outcome.

But the NSA deployment is different. Anthropic is not just giving the agency a tool to scan its own systems. It has engineers inside the agency customizing the model for offensive use: the kind of work that, in the intelligence world, means finding weaknesses in someone else's systems to exploit them. The company's public defense of this, relayed through a person close to it, is that the best way to build a good defense is to build a good attack, and that adversaries will build their own tools regardless.

That argument is not wrong. China and other state actors are almost certainly building equivalent capabilities. The question it does not answer is why this particular arrangement is consistent with a company that built its brand on saying no to certain government uses of its AI.

The timing of all this matters for anyone watching Anthropic from the outside. It confidentially filed for a U.S. IPO on June 1, with a valuation near $965 billion. Its revenue has gone from $9 billion at the end of 2025 to a $47 billion annual run rate by May 2026. The IPO will force Anthropic to disclose its finances publicly for the first time. Analysts have flagged that gross margin, the share of revenue left after paying to run the AI systems, is the number that will determine whether the valuation holds up. No one outside the company has seen it yet.

For businesses that use Anthropic's products or are considering doing so, the immediate operational picture is unchanged. Claude for enterprise use is unaffected by the NSA arrangement. But the legal situation is still unsettled. A three-judge appeals panel heard arguments in May and appeared divided. A lower court in California already blocked the Pentagon's blacklist as likely unconstitutional. The Pentagon has an August deadline to remove Claude from its systems. Two courts have now issued conflicting signals about whether that ban is enforceable.

What this week showed is that Anthropic's safety boundaries are real but specific. They apply to domestic surveillance and autonomous weapons pointed at Americans. They do not apply to offensive foreign intelligence work when a powerful enough buyer asks. That is a meaningful distinction to understand, whether you are a customer, a regulator, or an investor waiting to see the S-1.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable