AIResearchAIResearch
Machine Learning

Anthropic Embeds Engineers at NSA While Urging AI Pause

Anthropic's engineers are inside the NSA customizing Mythos for cyber ops, while the company's research arm publishes a paper calling for a coordinated global AI development pause.

3 min read
Anthropic Embeds Engineers at NSA While Urging AI Pause

TL;DR

Anthropic's engineers are inside the NSA customizing Mythos for cyber ops, while the company's research arm publishes a paper calling for a coordinated global AI development pause.

Six Anthropic engineers are now working inside the National Security Agency, adapting the company's most capable model for offensive cyber operations. The model, Mythos, has never been publicly released. Anthropic withheld it from general availability over misuse concerns, limiting access to a vetted consortium called Project Glasswing that includes Microsoft, Apple, and Amazon.

That tension surfaced Thursday in a single news cycle, alongside an Anthropic research paper calling for international coordination to slow or pause frontier artificial intelligence development. For researchers tracking the field, it raises an immediate question: how much daylight actually exists between safety messaging and real-world deployment decisions?

Reporting by Yahoo News, citing the Financial Times, places Anthropic's forward-deployed staff inside the NSA, customizing Mythos for applications that could include infiltrating networks in China and Iran. Whether those engineers participate in active operations remains unconfirmed. What is documented: Mythos is the same model Anthropic has refused to release on the open market.

Anthropic's relationship with the U.S. government is further complicated by a concurrent legal dispute. In late February, Defense Secretary Pete Hegseth designated Anthropic a supply-chain risk after a $200 million Pentagon contract collapsed; the breakdown came after Anthropic refused to allow Claude to be used for fully autonomous weapons or domestic mass surveillance. The NSA contract carried no such restriction and continued operating throughout the dispute. A California judge blocked the designation as apparent First Amendment retaliation, but a D.C. appeals court declined to pause it while litigation proceeds.

The self-improvement paper

Published on the same day, "When AI Builds Itself" comes from the Anthropic Institute and details how far Claude has progressed at automating its own development. According to The Next Web, as of May 2026 Claude authored more than 80% of the code merged into Anthropic's production codebase, up from low single digits when Claude Code shipped in February 2025. Engineers are now merging roughly eight times as much code per day as in 2024. An internal survey of 130 research staff estimated a median productivity multiplier of approximately four times with Mythos Preview versus working without AI assistance.

Capability gains on difficult tasks have also accelerated sharply. Claude's success rate on complex, open-ended engineering problems reached 76% in May 2026, a 50-percentage-point increase over six months. One concrete example from the paper: when a routine upgrade began crashing tens of thousands of training jobs simultaneously, Claude isolated an obscure debugging flag, reproduced the crash, and confirmed a fix in roughly two hours, a problem that would normally require two to three days.

USA Today covered the paper's central policy argument: Anthropic wants a coordinated, verifiable mechanism allowing multiple frontier labs to simultaneously slow or halt development if recursive self-improvement accelerates beyond society's capacity to manage. The company drew an explicit analogy to Cold War nuclear arms control treaties. A unilateral slowdown, Anthropic acknowledged, would mainly shift competitive position rather than reduce global risk. Meaningful action requires agreement among several well-resourced labs, clear trigger conditions, and independent oversight.

Where it lands

Defense contractors have long navigated the gap between stated ethics and national security obligations. What distinguishes Anthropic's situation is the speed at which that gap has opened: a company built around AI safety now deploys its most restricted model inside an intelligence agency while simultaneously proposing a formal artificial intelligence review mechanism with treaty-like authority over the entire industry.

Any coordinated pause faces structural obstacles. LLM Stats tracks multiple frontier model releases per month from Anthropic, Google, Microsoft, xAI, and others. With the NSA actively using AI against Chinese networks and Chinese labs continuing to advance, verification remains the hardest unsolved problem. Anthropic's paper acknowledges this directly: willingness to coordinate may be the easier half of the equation.

Harder still is the question this news cycle leaves open: whether a company can credibly lead a global slowdown effort while simultaneously supplying the technology it wants slowed down to one of the most powerful intelligence agencies on earth.

FAQ

What is Anthropic's Mythos model?
Mythos is Anthropic's most capable AI system as of mid-2026. The company has not released it publicly, restricting access to vetted partners through Project Glasswing. The NSA gained access under a separate government agreement.

What is Project Glasswing?
Project Glasswing is Anthropic's restricted access program for its most advanced models. Partners reportedly include Microsoft, Apple, and Amazon, alongside intelligence agency access under separate terms.

What does recursive self-improvement mean for AI safety?
It refers to a scenario in which an AI system can meaningfully accelerate development of its own successor without human engineers driving each incremental gain. Anthropic's paper argues this threshold may be closer than most institutions are prepared for, given that Claude already contributes more than 80% of the company's own production code.

Why is Anthropic in a legal dispute with the Pentagon?
After a $200 million contract collapsed in late February 2026, Defense Secretary Pete Hegseth designated Anthropic a supply-chain risk. The company had refused to allow Claude to be used for autonomous weapons or domestic mass surveillance. Litigation continues, though a California judge has temporarily blocked the designation.

About the Author

Guilherme A.

Guilherme A.

Former dentist (MD) from Brazil, 41 years old, husband, and AI enthusiast. In 2020, he transitioned from a decade-long career in dentistry to pursue his passion for technology, entrepreneurship, and helping others grow.

Connect on LinkedIn