Anthropic が NSA にエンジニアを派遣し、攻撃用サイバー作戦向け「Mythos」を展開(3 分読了)
本文の状態
日本語全文を表示中
詳細モードで約13分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
TLDR AI
AI 企業 Anthropic は約 6 名のエンジニアを米国国家安全保障局(NSA)に配置し、中国やイランなどのネットワークへの侵入を目的とした攻撃用モデル「Mythos」のカスタマイズ支援を行っている。Anthropic は現在、軍での自社モデル使用に関するペンタゴンとの訴訟中である。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
米国家安全保障局(NSA)にエンジニアを派遣し、攻撃用サイバー戦のために「Mythos」を展開するアンソロピック
アンソロピックは、リリースすると危険すぎるため公開を拒否しているサイバーモデル「Mythos」の攻撃作戦への展開のため、約 6 名のエンジニアを米国家安全保障局(NSA)に配置したと、FT が報じた。一方で同社は、自社のモデルが戦争でどのように使用されるかについてペンタゴンに対して訴訟を起こしている。その拒否は実際には選択的であることが判明した。
アンソロピックは、最も能力の高いサイバーモデル「Mythos」の攻撃作戦への展開を支援するため、エンジニア約 6 名を米国家安全保障局(NSA)に配置したと、木曜日にこの取り決めに関係する二人の情報源を引用し、Financial Times が報じた。これらのエンジニアは「前方展開」スタッフとして勤務し、誤用の観点からアンソロピックが一般公開を拒否しているモデルのカスタマイズを行っている。ある関係者は FT に対し、このモデルは中国やイランなどの国のネットワークへの侵入に有用であると語った。彼らが実際の作戦支援を行っているかどうかはまだ不明である。この作業は、NSA を監督するペンタゴンに対して、自社のモデルが戦争でどのように使用されるかについて訴訟を起こしている最中に行われている。
Anthropic は、自らが拒否する用途に基づいて公的なアイデンティティを構築してきました。同社は、Claude の米国人に対する大量監視や自律型兵器への利用を制限しようと試み、ペンタゴンはそれを抵抗勢力にとっての「サプライチェーンリスク」として認定しました。これは米国企業に対して行われた初のSuchな指定です。NSA での業務は、これらの拒否がどこで終わるのかを示しています。Anthropic は国内で評判や法的コストを伴う用途には躊躇しましたが、外向きの用途については人員を配置し、米国の情報機関が攻撃的なサイバー戦用に構築されたモデルを展開するのを支援しました。
キーポイント
- 金融タイムズ紙によると、Anthropic は約6名の「前方展開」エンジニアを NSA に派遣し、攻撃的運用用の Mythos サイバーモデルの展開を行いました。
- この取り決めは、Claude の軍事利用制限を理由に Anthropic を「サプライチェーンリスク」としてブラックリスト化したペンタゴンに対する Anthropic の訴訟と並行して進められています。
- Anthropic は Mythos が公的に公開されるには危険すぎると主張していますが、6 月 2 日には約150の組織を対象に、15 カ国以上でアクセスを拡大しました。
- この発表は、Anthropic が時価総額約 1 兆ドルで非公開 IPO を申請してから数日後に行われました。
AI 生成による要約。編集者のレビュー済み。当社の AI ガイドラインの詳細はこちら。
Anthropic のレッドチームが 4 月に明らかにしたこと
Anthropic のレッドチームは 4 月 7 日の投稿 で、Mythos Preview はユーザーの指示により「主要なオペレーティングシステムおよび主要な Web ブラウザ」すべてにおいてゼロデイ脆弱性を発見し、悪用できると述べています。同チームが見つけた最も古い欠陥は、セキュリティを中核に設計されたオペレーティングシステムである OpenBSD 内の 27 年前のバグでした。投稿によると、複雑な Linux ターゲットに対する完全なエクスプロイト・パイプラインは 1 日以内に実行可能で、コストは 2,000 ドル未満でした。また、OpenBSD の脆弱性に関する約 1,000 回の検索の総コストも 20,000 ドル未満でした。セキュリティ訓練を受けたことのないエンジニアが、モデルに一夜にしてリモートコード実行バグを問い合わせたところ、朝には動作するエクスプロイトが得られました。
イギリスの AI セキュリティ研究所は 同モデルを独立してテスト した結果、2025 年 4 月以前にはどのモデルも完了できなかった専門家レベルのタスクの 73% を解決し、10 回の試行のうち 3 回で 32 ステップからなるシミュレーションされた企業ネットワーク攻撃を完了する最初のモデルとなったことを発見しました。Anthropic は、Mythos を「Project Glasswing」と呼ぶプログラムの下、主に米国パートナー約 50 社に制限し、深刻な悪用を防ぐための必要なセーフガードが欠けていると説明しています。
Implicator.ai をあなたのメールボックスへ
サンフランシスコからの戦略的 AI ニュース。過剰な期待や「AI がすべてを変える」といった前置きはなし。何が変わり、誰が勝ち、なぜそれが重要なのかだけを伝えます。毎日太平洋標準時午前 6 時に配信。
メールアドレス
ご自身の受信トレイを確認し、リンクをクリックして確認してください。
スパムはございません。いつでも購読解除が可能です。
ヘグセットのサプライチェーンリスクラベル
NSAとの提携は、同省との Anthropic の他のモデルをめぐる未解決の対立の中で位置づけられています。3 月初旬、国防長官ピート・ヘグセットは、国内監視や自律型兵器における Claude の利用制限を Anthropic が求めた交渉が決裂したため、同社をサプライチェーンリスク(supply-chain risk)と指定しました。Anthropic は第一修正条項の違反を理由に提訴し、今週、同省は連邦控訴裁判所に対し、ヘグセットが再考を求める Anthropic の要請を拒否したと伝えました。ドナルド・トランプ大統領は、8 月までに Pentagon(ペンタゴン)のシステムから Claude を排除するよう命じています。
この事件は、特定の方向への疑問だけでなく、鋭い質疑応答を引き起こしています。「私の人生において、悪意のある証拠を一つも見つけることはできません」と、カレン・ヘンダーソン判事は 5 月の口頭弁論で述べました。これは、Anthropic が「悪意ある意図(mal-intent)」を持っていると非難したペンタゴンのメモ書を指しています。しかし、3 人の裁判官からなる陪席の過半数は、指定を維持する方向に傾いているように見えました。同じ週、戦闘への Claude の導入阻止のために戦ってきた同社のエンジニアが、同省が運営する NSA(国家安全保障局)内に配置され、同省が構築した最も強力なサイバーモデルの開発に取り組んでいます。
50 のパートナーから 150 へ
6 月 2 日、Anthropic は Mythos へのアクセスを約 150 の組織に拡大しました。対象は 15 カ国以上にまたがり、4 月に承認された主に米国企業の約 50 のパートナーから増えています。FT(Financial Times)の報道によると、新しい参加者には Okta、Samsung、NATO(北大西洋条約機構)、EU のサイバーセキュリティ機関である ENISA が含まれています。これらのパートナーは 10,000 件以上の高または致命的な深刻度の欠陥を報告しており、Anthropic 内部が実施した 1,000 のオープンソースプロジェクトのスキャンでは 23,019 の潜在的な脆弱性が検出されました。そのうち 6,202 件が高または致命的な深刻度と推定されています。
Anthropic はこの制限付きリリースを安全対策として提示しています。しかし、脆弱性探索用の AI はもともと不足していたわけではありませんでした。「数ヶ月、あるいは数年にわたり、AI を使って対処しきれないほどのバグを発見してきました」と、初期の Mythos アクセス権を持つある研究者は Reuters に語りました。Reuters は 5 月にも、このモデルに関する懸念が過大評価されていると報じています。管理されたロールアウトは、その能力を希少なものに保ったというよりも、誰がそれを保有するかを決めたものです。現在その保有者には、NSA(アメリカ国家安全保障局)自身に加え、セキュリティ機関、半導体メーカー、通信事業者などが含まれており、これらは 150 の組織からなる「Project Glasswing」に参加しています。これは Anthropic が資金調達ラウンドで約 1 兆ドルと評価され、非公開で IPO(株式公開)届出を行った数日後のことです。同社の年間換算収益は、2025 年末の 90 億ドルから、6 月末までに 500 億ドルに達する見込みです。
Anthropic の擁護派は、NSA での業務を不可避なものと呼んでいる。同社に近い人物は FT に対し、「優れた防御を構築する最良の方法は、優れた攻撃を構築することである」と語り、敵対勢力が自らの攻撃エージェントを構築するのは避けられないと主張した。ワシントンにある三人の判事からなるパネルは、ヘグセット氏の指名が有効かどうかを検討中であり、ペンタゴンが Claude をそのシステムから撤去する期限は 8 月となっている。Anthropic の非公開 IPO 提出書類は、最終的に同社の財務状況を公衆の目にさらすことになる。
よくある質問
Claude Mythos とは何ですか?
Mythos は Anthropic が持つ最も能力の高いサイバーモデルであり、ゼロデイソフトウェア脆弱性の発見と悪用が可能である。Anthropic のレッドチームは、主要なオペレーティングシステムおよびブラウザのすべての欠陥を突破し、27 年前の OpenBSD のバグを含むものも含まれ、かつ 2,000 ドル未満で動作するエクスプロイト(脆弱性悪用の仕組み)を構築したと報告している。同社は誤用リスクを理由に、これを公衆に公開することを拒否している。
Anthropic は NSA で何をしているのですか?
Financial Times の報道によると、Anthropic は約 6 名の「前方展開」エンジニアを国家安全保障局(NSA)内に配置し、Mythos を攻撃的サイバー作戦のために展開し、特定の用途に合わせてカスタマイズするのを支援している。これらのエンジニアが実際の作戦の支援を行っているかどうかは依然として不明である。
なぜアンソロピックはペンタゴンを訴えているのか?
3 月初旬、国防長官のピーター・ヘグセットは、同社が Claude の国内監視や自律型兵器への利用を制限しようとしたことを理由に、アンソロピックを「サプライチェーンリスク」と指定しました。これに対しアンソロピックが訴訟を起こし、米国の企業に対する此类の指定としては初めてとなりました。ペンタゴンは再考を求める要請を拒否しており、3 人の判事からなるパネルがこの事件を検討中です。
Mythos を利用可能な組織はどれくらいあるのか?
アンソロピックは 6 月 2 日、同社が「Project Glasswing」と呼ぶプログラムのもと、利用可能組織を約 50 社(主に米国パートナー)から約 150 社に拡大し、対象国も 15 カ国以上に広げました。参加組織には Okta、Samsung、NATO、および EU のサイバーセキュリティ機関である ENISA が含まれています。
Mythos は懸念されるほど危険なのか?
見解は分かれます。アンソロピックが利用を制限した理由は、Mythos が自律的に脆弱性を悪用できる点にあり、英国 AI セキュリティ研究所は同システムが専門家レベルのタスクの 73% を解決できたと報告しています。しかし、ロイター通信は 5 月に懸念が過大評価されたと報じ、ある研究者は「脆弱性探索用の AI は数ヶ月、あるいは数年にわたり利用可能だった」と述べています。
AI 生成の要約を編集者がレビューしました。当社の AI ガイドラインの詳細はこちら。
アンソロピックはペンタゴン契約を失った。しかし議論に勝利し、その後「明かりを維持する」提案を行った。
木曜日の午後、国防省は正式にアンソロピックに対し、同社およびその製品が「即時効力をもってサプライチェーンリスクとみなされる」と通知した。このラベルは歴史的に『The Implicator』[https://www.implicator.ai/anthropic-lost-the-pentagon-contract-it-won-the-argument/]として知られている。
ペンタゴンが自らの内側で対立する。ベルリンがブリュッセルと対立する。レクンがアモダイと対立する。
サンフランシスコ | 2026年4月20日(月)
ペンタゴンは2月にアンソロピックをサプライチェーンリスクと認定した。しかし、Axiosは現在、諜報機関であるNSA(National Security Agency:国家安全保障局)がそれでも同社のMythos[注:AIモデル名]を利用していると報じている。戦争を戦う諜報機関『The Implicator』[https://www.implicator.ai/the-pentagon-fights-itself-berlin-fights-brussels-lecun-fights-amodei/]
ペンタゴンがアンソロピックを狙う。インドが資金を提供する。
サンフランシスコ | 2026年2月17日(火)
ペンタゴンはまもなくアンソロピックをサプライチェーンリスクと認定しようとしている。ペーター・ヘグセット国防長官は、Claude[注:AIモデル名]が「すべての合法的な目的」で使用可能であることを望んでいる。アンソロピック『The Implicator』[https://www.implicator.ai/pentagon-targets-anthropic-india-writes-the-checks/]
## マーカス・シューラー
サンフランシスコ
インプリケーター.ai(Implicator.ai)の編集長兼創設者。元ARD(ドイツ公共放送連盟)特派員で、10年以上にわたりテクノロジー分野を取材してきたシニア放送ジャーナリスト。政策および市場動向に関する日次ブリーフィングを執筆。サンフランシスコ在住。
E-mail: editor@implicator.ai
朝のブリーフィング
インプットボックスに朝のブリーフィングを受け取る。
無料の毎日朝ニュースレターと会員限定記事に登録してください。有料で提供されるのは、週刊の特別プロブリーフィングのみで、月額8ドルです。
原文を表示
Anthropic Embeds Engineers in the NSA to Deploy Mythos for Offensive Cyber
Anthropic put about six engineers inside the NSA to deploy Mythos, the cyber model it calls too dangerous to release, for offensive operations, the FT reported, even as it sues the Pentagon over how its models get used in war. The refusals, it turns out, are selective.
Anthropic has placed about half a dozen of its engineers inside the U.S. National Security Agency to help deploy Mythos, its most capable cyber model, for offensive operations, the Financial Times reported Thursday, citing two people familiar with the arrangement. The engineers work as "forward-deployed" staff, customizing a model Anthropic has declined to release publicly on misuse grounds; one person told the FT it would be useful for infiltrating networks in nations such as China or Iran. It remains unclear whether they are assisting active operations. The work proceeds while Anthropic sues the Pentagon, which oversees the NSA, over how its models are used in war.
Anthropic has built its public identity on the uses it refuses. It sought to restrict Claude's use for mass surveillance of Americans and autonomous weapons, and the Pentagon branded it a "supply-chain risk" for the resistance, the first such designation against an American company. The NSA work shows where those refusals stop. Anthropic balked at the uses that carry reputational and legal cost at home, and it staffed the one aimed outward, helping a U.S. intelligence agency deploy a model built for offensive cyber.
Key Takeaways
- Anthropic embedded about six "forward-deployed" engineers inside the NSA to deploy its Mythos cyber model for offensive operations, the Financial Times reported.
- The arrangement runs alongside Anthropic's lawsuit against the Pentagon, which blacklisted it as a "supply-chain risk" over limits on Claude's military use.
- Anthropic calls Mythos too dangerous to release publicly, yet expanded access to about 150 organizations across 15-plus countries on June 2.
- The disclosure lands days after Anthropic filed confidentially for an IPO at a valuation near $1 trillion.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
What Anthropic's red team disclosed in April
In an April 7 post, Anthropic's red team said Mythos Preview could find and exploit zero-day vulnerabilities in "every major operating system and every major web browser" when a user directed it to. The oldest flaw it found was a 27-year-old bug in OpenBSD, an operating system built around security. A complete exploit pipeline against a complex Linux target ran under a day at a cost below $2,000, the post said, and roughly a thousand OpenBSD vulnerability searches cost under $20,000 in total. Engineers with no security training asked the model for remote-code-execution bugs overnight and woke to working exploits.
Britain's AI Security Institute, testing the model independently, found it solved 73% of expert-level tasks that no model could complete before April 2025, and became the first to finish a 32-step simulated corporate-network attack, in 3 of 10 attempts. Anthropic restricted Mythos to about 50 mostly U.S. partners under a program it calls Project Glasswing, saying it lacks the safeguards needed to prevent serious misuse.
Get Implicator.ai in your inbox
Strategic AI news from San Francisco. No hype, no "AI will change everything" throat clearing. Just what moved, who won, and why it matters. Daily at 6am PST.
Email address
Check your inbox. Click the link to confirm.
No spam. Unsubscribe anytime.
Hegseth's supply-chain-risk label
The NSA arrangement sits against an unresolved fight with the same department over Anthropic's other models. In early March, Defense Secretary Pete Hegseth designated the company a supply-chain risk after talks collapsed over Anthropic's request to limit Claude in domestic surveillance and autonomous weapons. Anthropic sued, citing the First Amendment, and this week the department told a federal appeals court that Hegseth had denied its request to reconsider. President Trump has ordered the Pentagon to remove Claude from its systems by August.
The case has drawn sharp questioning, though not in one direction. "For the life of me, I do not see any evidence of maliciousness," Judge Karen Henderson said at May oral arguments, referring to a Pentagon memo that accused Anthropic of "mal-intent." A majority of the three-judge panel, even so, appeared disposed to let the designation stand. In the same weeks, a company that fought to keep Claude out of warfighting has had its own engineers inside the NSA, which the department runs, working on the most powerful cyber model it has built.
From 50 partners to 150
On June 2, Anthropic widened access to Mythos to about 150 organizations across more than 15 countries, up from the roughly 50 mostly U.S. partners admitted in April. The new cohort, the FT reported, includes Okta, Samsung, NATO, and the EU's cybersecurity agency, ENISA. Partners have surfaced more than 10,000 high- or critical-severity flaws, and an internal Anthropic scan of 1,000 open-source projects flagged 23,019 potential vulnerabilities, 6,202 of them estimated high or critical.
Anthropic presents the restricted release as a safety measure. But vulnerability-hunting AI was not scarce to begin with. "We've been able to use AI to find more bugs than we know what to do with for months if not years," one researcher with early Mythos access told Reuters, which reported in May that fears about the model were overstated. The controlled rollout has not kept the capability rare so much as decided who holds it. Those holders now include the NSA itself, alongside the security agencies, chipmakers, and telecom operators among the 150 organizations admitted to Project Glasswing, days after a funding round valued Anthropic near $1 trillion and it filed confidentially for an IPO. Its annualized revenue is on track to reach $50 billion by the end of June, up from $9 billion at the end of 2025.
Anthropic's defenders call the NSA work unavoidable. "The best way to build a good defence is to build a good attack," a person close to the company told the FT, arguing that adversaries will build their own attack agents regardless. The three-judge panel in Washington is still weighing whether Hegseth's designation stands, and the Pentagon's deadline to drop Claude from its systems falls in August. Anthropic's confidential IPO filing will eventually move its finances into public view.
Frequently Asked Questions
What is Claude Mythos?
Mythos is Anthropic's most capable cyber model, able to find and exploit zero-day software vulnerabilities. Anthropic's red team said it cracked flaws in every major operating system and browser, including a 27-year-old OpenBSD bug, and built working exploits for under $2,000. The company has declined to release it publicly, citing misuse risk.
What is Anthropic doing at the NSA?
The Financial Times reported Anthropic placed about half a dozen "forward-deployed" engineers inside the National Security Agency to help deploy Mythos for offensive cyber operations and customize it for specific uses. It remains unclear whether the engineers are assisting active operations.
Why is Anthropic suing the Pentagon?
In early March, Defense Secretary Pete Hegseth designated Anthropic a "supply-chain risk" after the company sought to limit Claude's use in domestic surveillance and autonomous weapons. Anthropic sued, the first such designation against a U.S. company. The Pentagon has denied its request to reconsider, and a three-judge panel is weighing the case.
How many organizations can use Mythos?
Anthropic expanded access on June 2 to about 150 organizations across more than 15 countries, up from roughly 50 mostly U.S. partners in April, under a program it calls Project Glasswing. Named members include Okta, Samsung, NATO, and the EU cybersecurity agency ENISA.
Is Mythos as dangerous as feared?
Views differ. Anthropic restricted release because Mythos can autonomously exploit vulnerabilities, and the UK AI Security Institute found it solved 73% of expert-level tasks. But Reuters reported in May that fears were overstated, quoting a researcher who said vulnerability-hunting AI has been available "for months if not years."
AI-generated summary, reviewed by an editor. More on our AI guidelines.
[The Pentagon Fights Itself. Berlin Fights Brussels. LeCun Fights Amodei.San Francisco | Monday, April 20, 2026
The Pentagon labeled Anthropic a supply-chain risk in February. Axios now reports the NSA is running Anthropic's Mythos anyway. The spy agency that fights wars The Implicator](https://www.implicator.ai/the-pentagon-fights-itself-berlin-fights-brussels-lecun-fights-amodei/)
[Pentagon Targets Anthropic. India Writes the Checks.San Francisco | Tuesday, February 17, 2026
The Pentagon is close to labeling Anthropic a supply chain risk. Defense Secretary Pete Hegseth wants Claude available for "all lawful purposes." Anthropic The Implicator](https://www.implicator.ai/pentagon-targets-anthropic-india-writes-the-checks/)
Marcus Schuler
San Francisco
Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco.
E-mail: editor@implicator.ai
The Morning Briefing
Get the Morning Briefing in your inbox.
Sign up to our free daily morning newsletter and free member articles. Only our special weekly Pro Briefing is available for $8/month.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み