The executive order said one thing. The intelligence community did another. Eight weeks after President Trump ordered federal agencies to stop working with Anthropic, the National Security Agency began using the company’s newest model, Mythos Preview, according to Axios. Now the NSA is preparing to bring Mythos into its network warfare operations, according to a TechCrunch report this week citing people familiar with the matter.
The story of how the most sensitive agency in the U.S. government came to rely on a company it is formally barred from working with runs through a winter of confrontation. In February, the White House issued a blanket order for agencies to cease using Anthropic’s services, after the company refused to remove certain safeguards during negotiations over military contracts. Anthropic’s chief executive, Dario Amodei, walked out of a White House meeting around the same time, and the Pentagon later formalized the break by designating Anthropic a supply chain risk, a label reserved for companies deemed an unacceptable risk to national security.
The ban did not stop the deployment. Mythos Preview, announced in early April, was described by Anthropic as its most capable model yet for coding and agentic tasks, and by the company and outside experts as strikingly capable at computer security work. The NSA is one of roughly 40 organizations worldwide granted access to the preview, according to intelligence reports cited at the time, and the model was being used more widely across the Defense Department than the agency itself, sources told Axios.
The capabilities that make Mythos attractive to an intelligence agency are the same ones that made it controversial. The model can rapidly detect vulnerabilities across software and infrastructure, generate functional exploit paths for offensive operations, automate code auditing and threat hunting at scale, and produce accelerated patching recommendations for critical systems. For the NSA, which runs both defensive and offensive cyber missions, that combination has few equivalents anywhere, a point the agency’s leadership has made in internal discussions, according to people familiar with the matter.
Anthropic has fought the designation in court. In March, the company sued the Defense Department in two federal courts challenging the supply chain risk label. One court granted a preliminary injunction temporarily blocking the designation; in the other, judges denied the company’s motion to lift it. The company remains, at once, formally designated a risk and embedded in one of the government’s most secretive agencies, and it is litigating against the very departments now using its technology.
The political track and the operational track have run on parallel lines. Days before the NSA began using Mythos, Amodei met with White House chief of staff Susie Wiles and other officials to discuss the model, a meeting the White House characterized as productive and constructive. Asked about it by reporters, Trump said he had no idea the meeting had taken place. The administration had earlier framed its dispute with Anthropic in part around fears that the company’s most advanced models could supercharge cyberattacks.
The contradiction has not gone unnoticed inside the government. Officials publicly describe the company as a supply chain risk while operational agencies privately race to deploy its core technology, a pattern that analysts who track federal AI procurement say reflects a structural gap: policy is written in public, while missions are executed in secret. Stanford researchers have documented the underlying dependence, noting that less than 2 percent of AI doctorates work in government, leaving agencies reliant on a handful of private labs for frontier capability.
The NSA’s move raises a practical question for the rest of the federal establishment. If the agency that runs America’s signals intelligence can use Anthropic’s models under a formal ban, other agencies may follow under cover of pilot programs and research initiatives, and the February order becomes less a prohibition than a negotiating posture. Anthropic has said it wants a controlled framework for selective government use of powerful models, and talks between its leadership and U.S. officials have continued even as the lawsuits proceed.
The NSA and Anthropic declined to comment on the TechCrunch report, and the agency does not publicly discuss its operational tools. Former officials familiar with intelligence procurement said the episode fits a longer pattern: agencies that are barred from contracting with a vendor find other routes to its technology when the capability is essential. The practical result, they said, is that the supply chain risk label has come to mean less than it appears to, and that other agencies are likely watching the NSA’s path closely.
What the episode reveals is a Washington that wants it both ways: limiting AI companies in public, while depending on them in private. For Anthropic, the NSA’s interest is a validation of its technology and a validation it cannot advertise. For the government, the deployment is a bet that the most capable models, the same ones it has called too dangerous to trust, are exactly the tools its operators most want.


