A senior FBI official has identified Anthropic’s Mythos AI as a potential challenge for law enforcement, pointing to the model’s reported ability to discover and exploit vulnerabilities in widely used software.
FBI Deputy Assistant Director Todd Hemmen discussed the system on July 28 at the Digital Government Institute’s 930gov conference in Washington. Hemmen, who leads the bureau’s Cyber Capabilities Branch, said the agency has not yet observed widespread operational use of such tools by adversaries but expects the threat to grow.
“It presents future challenges for law enforcement,” Hemmen said.
Tech Times reported that Mythos Preview uncovered previously unknown flaws in software including OpenBSD and FFmpeg, as well as vulnerability chains affecting the Linux kernel. The reported OpenBSD flaw involved the implementation of TCP Selective Acknowledgment and could allow a remote attacker to crash a vulnerable machine. The FFmpeg issue had also remained undetected for years despite extensive automated testing.
Anthropic reportedly tested Mythos across nearly 1,000 open-source repositories, generating thousands of possible high- or critical-severity findings. Human specialists reviewed 198 cases and agreed with the model’s severity rating in 89% of them. Those results suggest that increasingly capable coding agents could help defenders review large codebases, while also reducing the expertise, time and expense required to identify exploitable weaknesses.
The model’s reported performance extended beyond locating bugs. In testing involving previously patched Firefox vulnerabilities, Mythos produced working exploits far more often than Anthropic’s earlier Claude Opus 4.6 model. That distinction matters for law enforcement because automated exploitation could let attackers move more quickly from public disclosures or code changes to functioning attacks.
Hemmen’s warning was not limited to one proprietary system. He acknowledged that less capable models can perform similar vulnerability discovery and exploitation tasks. Separate research cited by Tech Times found that a relatively small open-source model running on consumer hardware could identify real software flaws, while another experiment used free models to build a prototype worm for a simulated enterprise network.
The availability of such systems complicates attempts to manage cyber risk through access restrictions on frontier models. Open-source models can be downloaded, modified and operated locally, leaving providers with little ability to monitor prompts or suspend accounts. Their performance may lag behind the most advanced commercial systems, but attackers may not require frontier-level reliability if they can run many inexpensive attempts.
The FBI’s concern also comes as federal agencies expand their own use of AI. Hemmen said the bureau has about 50 active AI applications, including systems used to triage criminal allegations, assist research and support court-authorized offensive operations. He said human reviewers remain involved in the allegation-triage process.
Tech Times reported that the FBI had not completed federal risk-management requirements for any of its high-impact AI applications despite an April 3 deadline set by the Office of Management and Budget. That leaves the bureau managing two related governance problems: preparing for criminal use of increasingly autonomous cyber tools while establishing safeguards for its own deployments.
Mythos has already been at the center of a federal access-control dispute. The Commerce Department temporarily directed Anthropic to block foreign nationals from using Mythos 5 and Fable 5, prompting a global interruption because the company could not verify nationality at consumer scale. The restrictions were lifted on July 1 after Anthropic agreed to cooperate with the government on safety standards, address security risks and report malicious activity, Tech Times reported.
Mythos 5 remains limited to vetted participants in Project Glasswing, while Fable 5 is available to paying subscribers with safety controls. However, the diffusion of vulnerability-finding capabilities into smaller and openly available systems means restrictions on a single model are unlikely to address the full challenge described by the FBI.
Sources: AI safety policy