The agency that investigates most computer intrusions in the United States now treats autonomous vulnerability discovery as a coming enforcement problem. Todd Hemmen, deputy assistant director of the FBI Cyber Division’s Cyber Capabilities Branch, told the Digital Government Institute’s 930gov conference in Washington on July 28, 2026 that the software flaws surfaced by Anthropic’s Mythos model sit inside the code almost everything else depends on: operating systems, security tooling, web infrastructure and encryption. “It presents future challenges for law enforcement,” he said.

That framing matters because the FBI is the lead federal agency for cyber intrusion cases, so its caseload is where a capability shift eventually shows up as charged conduct. Hemmen said the bureau has not seen the capability used against victims at industrial scale, and does not expect that to hold. “Though we haven’t seen this operationalized at scale, the expectation is that there is a future date where that is coming,” he said.

His practical concern is attribution. When flaw-finding stops requiring rare expertise, the pool of plausible suspects widens and investigations get harder to narrow. Mythos 5 is available only to a set of US organizations cleared by the government, but it shares its underlying model with the widely sold Claude Fable 5, and Anthropic’s own testing found that weaker, broadly available models could locate the same flaws that triggered a federal intervention in June 2026.

What Mythos found in critical code

Anthropic’s Frontier Red Team published its assessment of the model’s cybersecurity capabilities on April 7, 2026. It reported that the model identified and exploited previously unknown flaws in every major operating system and web browser when directed to, including a 27-year-old bug in OpenBSD that let an attacker crash any machine answering network traffic, and a 16-year-old flaw in the FFmpeg video library that had survived years of automated testing. In one case the model found a remote flaw in FreeBSD’s network file server and wrote a working root exploit for it without human help.

Two details set the scale for regulators. Anthropic said fewer than 1% of the flaws it had found were fully patched at the time of publication, so the published examples represent a floor rather than a total. And the economics are unremarkable: the OpenBSD finding came out of roughly $20,000 of model runs across a thousand attempts, with the successful run costing under $50.

The company has said it will not release the model generally. Instead it seeded Project Glasswing, a defensive program whose partners include Amazon (AMZN ) Web Services, Apple (AAPL ), Cisco, CrowdStrike (CRWD ), JPMorganChase, the Linux Foundation and Palo Alto Networks (PANW ), backed by $100 million in usage credits. Rivals are building toward the same tier: Microsoft (MSFT ) benchmarked its own security model against Mythos when it put its first cyber model inside Project Perception in July 2026.

How Washington has handled the model

The federal response so far has run through export law rather than any AI statute. On June 12, 2026, Commerce applied export controls to Fable 5 and Mythos 5 that barred use by foreign nationals inside or outside the country, after officials reviewed an Amazon report describing a way around Fable 5’s safeguards. With no way to verify nationality in real time, Anthropic switched both models off for everyone. The controls were lifted on June 30, 2026 once the company trained a new classifier targeting the reported technique and Commerce’s Center for AI Standards and Innovation tested the result. The fix carries a cost for defenders: more benign coding and debugging requests get blocked.

A more durable structure arrived weeks earlier. A June 2, 2026 executive order on advanced AI and security set three pieces of machinery in motion:

  • A government-industry clearinghouse, led by Treasury with the National Cyber Director, the National Security Agency and the US cybersecurity agency, to deconflict vulnerability scanning, validate what turns up and prioritize patch distribution.
  • A classified benchmarking process, with the threshold decision resting on the NSA director, to determine which models count as “covered frontier models,” plus a voluntary route for developers to give the government up to 30 days of pre-release access. The order expressly rules out any licensing or preclearance requirement, a line labs have pushed for as OpenAI presses the White House to speed frontier model reviews.
  • An instruction to the Attorney General to prioritize prosecutions under existing computer-fraud, identity-fraud and wire-fraud laws when AI, including AI agents, is used to break into systems.

That last item is the FBI’s assignment. The bureau supplies the investigations that the policy converts into cases, and it works the same enforcement perimeter Washington has been testing on model access, from export controls on Anthropic’s models to the threat to blacklist China’s Moonshot over distillation.

Inside the bureau’s own AI use

Hemmen also described the FBI as an AI buyer, citing facial recognition as an enterprise capability and saying staff use the technology to triage public reports of criminal allegations, support court-authorized offensive operations and conduct research, with human review of the output.

The Justice Department’s 2025 AI use case inventory lists 315 entries across the department, a 30.7% increase over the prior year. The FBI accounts for roughly 50 of them, more than double its 2024 count, with about 27 categorized as law enforcement and several new projects generating investigative leads from suggested facial matches. Under a 2025 White House budget-office memo, agencies had until April 3, 2026 to document minimum risk-management practices for high-impact AI already in service or stop using it. The inventory shows the FBI has completed those steps for none of its high-impact deployments, all of which are law enforcement uses.

The clearinghouse is standing up, the classified threshold work that decides which models draw federal oversight sits with the NSA, and the prosecution priority is already assigned. That is the machinery the FBI’s next generation of intrusion cases will run through.