A dark data center aisle between two rows of server racks with green status lights, the kind of physical infrastructure that anchors both the NSA's classified cyber operations and Anthropic's Mythos training and inference capacity
Photo via Unsplash

TL;DR: On June 23, 2026, The New York Times reported that the NSA lost access to Anthropic's Mythos cyber-defense model amid the Fable 5 / Mythos 5 export-control dispute.[1] The classified contract that would have formalized the NSA's use of Mythos for intelligence analysis and vulnerability detection has not been finalized, and some Pentagon officials now want the agency to find a way to work with other models.[1] The reversal is sharp: in April, Axios reported the NSA was using Mythos despite a Pentagon supply-chain-risk blacklist.[2] Two months later, the agency that wanted the model cannot use it. The trigger is the administration's June 12 directive restricting non-American access to frontier U.S. AI models, the same directive driving the Fable 5 fight.[1]

What the Times Reported

The New York Times reported on June 23, 2026 that the NSA lost access to Anthropic's Mythos cyber-defense model amid the export-control dispute over Anthropic's frontier systems.[1] The classified contract that would have formalized the relationship, an arrangement that would have let the spy agency use the company's technology for intelligence analysis and for detecting new computer vulnerabilities, has not been finalized.[1]

According to the Times, some Pentagon officials want the NSA to find a way to work with other models rather than wait out the standoff.[1] That is a meaningful tell. It means the loss of Mythos is not being treated inside the building as a temporary glitch to ride out, but as a problem serious enough to justify rebuilding cyber-defense tooling on a different foundation.

The story drew significant discussion online, and the reception split between two readings: that the access loss is a genuine operational setback for U.S. cyber defense, and that the framing flatters Anthropic by casting Mythos as a model so capable the NSA cannot do without it. Both readings can be true at once, which is part of why the story landed the way it did.

How a Non-American Directive Became a Total Access Loss

The mechanism is the strange part. The administration's June 12 directive did not order Anthropic to cut off the NSA. It restricted access for non-American users. But Anthropic does not reliably verify the identity of users at the access-control layer, so it could not cleanly separate American users from everyone else. Faced with a directive it could not enforce selectively, the company pulled access broadly, and U.S. persons, including the NSA, were swept up in the result.

The company's footprint makes the gap concrete. Anthropic operates offices across the U.S., Europe, and Asia-Pacific, with only a minority of them on U.S. soil. A directive aimed at non-American access, applied to a company that cannot distinguish its users one from another, becomes operationally close to a directive that cuts everyone off. The irony is that the same global structure that made the directive enforceable in principle is what made the enforcement overbroad in practice.

This is also why the identity-verification question matters going forward. Anthropic has been building out identity checks for its consumer surface through a partnership with Persona, a move that drew its own scrutiny.[3] Whether the company extends a comparable verification layer to a classified-contract use case will determine whether the NSA's lost access is a permanent structural fact or a temporary one that ends when the plumbing catches up.

From "Using Despite the Ban" to "Lost Access Amid the Dispute"

Two months ago the story ran the other way. On April 19, 2026, Axios reported that the NSA was using Anthropic's Mythos model despite the Defense Department's supply-chain-risk designation, a designation that, on paper, marked Anthropic as too risky to do business with.[2] The contradiction was the headline: the same government that had blacklisted the company was quietly evaluating its most advanced model for one of its most sensitive agencies.

The June report flips that picture. The supply-chain-risk designation is still in effect, but it is no longer the operative fact. What changed is the June 12 export-control directive, a separate action layered on top of the older designation. The April paradox was about a government using a model it had formally disowned. The June reality is about an agency that needs the model and cannot reach it, because the access layer cannot tell an NSA analyst apart from a foreign user.

For our prior coverage of the April situation, see The Pentagon Banned Anthropic. The NSA Kept Using Its Model. That piece is the anchor for the "using despite the ban" framing this story reverses.

The Fable 5 Export-Control Backdrop

The dispute that cost the NSA its access did not start with the NSA. It is the same export-control fight over Anthropic's Fable 5 and Mythos 5 frontier models that has been building for weeks. The administration issued its directive on June 12, distinct from the earlier Pentagon supply-chain-risk designation, which remains in force. The supply-chain designation came first; the export directive added the non-American-access obligation that, through Anthropic's verification gap, produced the access loss.

The shape of the dispute is contradictory on both sides, and that contradiction is doing real work. The government has labeled the model a supply-chain risk while also signaling it could compel access under the Defense Production Act if Anthropic refuses to cooperate. Anthropic, for its part, has positioned Mythos as powerful enough to carry serious national-security weight while arguing its broader systems are safe for general release. Each side is claiming the same model is at once too dangerous to hand over and too valuable to give up. Disputes built on that kind of doubled framing tend to resolve only when one side concedes, or when a court, Congress, or a rival lab forces the question.

For the export-control thread itself, see Anthropic Fable 5 / Mythos 5: U.S. Export Control Suspended and our coverage of the underlying capability claims in Anthropic Mythos and Project Glasswing.

What to Watch

A first-party NSA statement. The agency has not publicly confirmed or denied the report. A statement from the NSA, or from the Office of the Director of National Intelligence, would clarify whether the classified-contract track is alive, modified, or abandoned.

A first-party Anthropic statement. Anthropic has not publicly addressed the report. The company's response would settle whether the cutoff was driven by the directive itself or by its own inability to verify users, and whether it intends to build a verification layer that could restore access for confirmed U.S. persons.

The text of the June 12 directive. The directive has not been made public. Its actual wording would show whether it targeted non-American access specifically or whether the broad cutoff was a downstream consequence of some other obligation.

The classified NSA-Anthropic contract. The Times reports the contract has not been finalized.[1] Whether it is signed, narrowed to sidestep the access question, or dropped will define the operational future of the relationship.

The Fable 5 appeal. Any move by Anthropic to challenge the export directive, and any preliminary relief from a court, would set the timeline for whether and when access could be restored.

Sources

  1. The New York Times: “NSA Lost Access to Anthropic Tool” (June 23, 2026): nytimes.com/2026/06/23/us/politics/nsa-lost-access-anthropic-tool.html
  2. Axios: “NSA using Anthropic's Mythos despite blacklist” (April 19, 2026): axios.com/2026/04/19/nsa-anthropic-mythos-pentagon
  3. State of Surveillance: “Anthropic ID Verification, Persona, and BIPA” (2026): stateofsurveillance.org/news/anthropic-id-verification-500-points-persona-bipa-2026