跳到主要內容

CISA用Mythos AI稽核政府軟體:五角大廈才封殺Anthropic | CISA Uses Anthropic's Mythos to Audit Government Code

By Kit 小克 | AI Tool Observer | 2026-07-26

🇹🇼 CISA用Mythos AI稽核政府軟體:五角大廈才封殺Anthropic

CISA(美國網路安全暨基礎設施安全局)被爆出正在使用 Anthropic 的 Mythos AI 模型,大規模稽核聯邦政府機關的原始碼,找出可能被敵對國家或駭客利用的安全漏洞。這件事本身不算意外——AI 抓漏早就是資安圈的日常——但真正讓人玩味的是時間點:五角大廈幾個月前才把 Anthropic 正式列為「供應鏈風險」,禁止旗下承包商使用其 AI 模型,CISA 卻在同一個政府體系裡持續仰賴同一家公司的技術。

什麼是CISA的Mythos AI稽核計畫?

簡單說,CISA 旗下的 Attack Surface Evaluation 小組,把 Mythos 當成自動化程式碼審查員,掃描各聯邦機關的程式碼庫,抓出可能被利用的安全漏洞並優先修補。

根據路透社等多家媒體引述的消息來源,這項計畫已經找出「大量」漏洞,但官方沒有公開具體數量、嚴重程度或受影響的機關名單。值得注意的是,NSA(國家安全局)據信也在自家業務中使用 Mythos,顯示這類 AI 稽核工具已經深入美國情報與資安體系,不只是實驗性質。

五角大廈才剛封殺Anthropic,CISA為何還在用?

這場矛盾源自今年稍早的一場拉鋸戰:五角大廈要求 Anthropic 開放 Claude 系列模型用於「任何合法用途」,Anthropic 則堅持保留兩條紅線——不得用於大規模監控美國公民,也不得用於全自動致命武器系統。談判破裂後,五角大廈祭出史上首次對美國企業的「國安供應鏈風險」認定,要求所有承包商切結不得使用 Anthropic 模型;Anthropic 執行長 Dario Amodei 則公開表態要提告。

但這個禁令主要卡在國防採購體系,並未直接約束 CISA 這類民事資安機關。換句話說,同一個聯邦政府,一邊在法庭上互相對峙,一邊還是離不開對方的技術——這正凸顯出目前 AI 稽核政府軟體已經走得比政策協調更快。

對開發者與資安團隊的意義

  • AI 抓漏正在規模化:連最保守、最龐大的美國聯邦程式碼庫都在導入 AI 稽核,代表這已不是新創公司的專利工具。
  • 模型選擇正變成政治問題:企業與機關未來挑選 AI 供應商,可能要考慮的不只是技術能力,還有地緣政治與合約條款風險。
  • 人工複核仍不可少:官方沒公布漏洞細節,正說明 AI 找出的問題仍需要人類專家確認與排序,不是掃完就自動安全了。

好不好用,試了才知道。


🇺🇸 CISA Uses Anthropic's Mythos to Audit Government Code

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic's Mythos AI model to audit source code across federal government agencies, hunting for vulnerabilities before foreign adversaries or criminals can exploit them. AI-assisted code auditing isn't new, but the timing here is the real story: the Pentagon formally labeled Anthropic a "supply-chain risk" just months ago and barred contractors from using its models — yet another arm of the same federal government keeps relying on that exact technology.

What is CISA's Mythos audit program?

CISA's Attack Surface Evaluation team is using Mythos as an automated code reviewer, scanning repositories across federal agencies to surface exploitable flaws so they can be patched proactively.

According to Reuters and multiple outlets citing sources familiar with the effort, the program has already uncovered a "large number" of vulnerabilities, though officials haven't disclosed severity, volume, or which agencies were affected. The NSA is also believed to be using Mythos internally — a sign this kind of AI code audit tooling has moved well past the pilot stage inside US security agencies.

Why is CISA still using Anthropic after the Pentagon's ban?

The contradiction traces back to a standoff earlier this year: the Pentagon wanted Claude models cleared for "any lawful use," while Anthropic insisted on two carve-outs — no mass domestic surveillance and no fully autonomous lethal weapons. When talks broke down, the Pentagon issued the first-ever "national security supply-chain risk" designation against a US company, requiring contractors to certify they don't use Anthropic models. CEO Dario Amodei said Anthropic would sue.

That designation mainly binds defense procurement, not civilian security agencies like CISA. So the same federal government is fighting Anthropic in one lane while depending on it in another — proof that AI-driven government code auditing is outrunning the policy fights around it.

What this means for developers and security teams

  • AI vulnerability scanning is going mainstream — even the most risk-averse, sprawling codebase in the country (the US federal government) is leaning on it.
  • Choosing an AI vendor is becoming a geopolitical decision, not just a technical one, as contract terms and government relationships enter the calculus.
  • Human review still matters — the lack of public detail on findings is a reminder that AI-flagged issues still need expert triage, not blind trust.

好不好用,試了才知道 — the only way to know if it works is to try it yourself.

Sources / 資料來源

常見問題 FAQ

CISA是什麼機關?

CISA(Cybersecurity and Infrastructure Security Agency)是美國國土安全部旗下的網路安全暨基礎設施安全局,負責防護聯邦政府與關鍵基礎設施的資安。

Mythos AI是什麼?

Mythos是Anthropic開發的AI模型,被CISA的Attack Surface Evaluation小組用來自動掃描並稽核聯邦政府機關的原始碼,找出安全漏洞。

五角大廈為什麼封殺Anthropic?

因為Anthropic拒絕讓Claude模型被用於大規模監控美國公民或全自動致命武器系統,雙方談判破裂後,五角大廈將Anthropic列為國安供應鏈風險,禁止國防承包商使用其模型。

CISA用Mythos合法嗎?

五角大廈的供應鏈風險認定主要約束國防採購與承包商,並未直接禁止CISA等民事資安機關使用Anthropic的模型,因此CISA目前仍可持續採用。

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Stanford 研究登上《Science》:11 個 AI 模型有 47% 機率說你對,即使你錯了 | Stanford Study in Science: AI Models Validate Harmful Behavior 47% of the Time — Sycophancy Is a Real Problem