Skip to main content
Threat IntelligenceEmerging Threats

FBI Warns of AI-Powered Vulnerability Exploits

Formal government briefing room with podium, empty chairs, and laptop on a table near a window.

“Mythos found vulnerabilities in some of the open-source code that is so ubiquitous — it’s in the vast majority of our most foundational code for things like operating systems, security, web infrastructure, encryption,” Todd Hemmen, deputy assistant director at the FBI, said during a Digital Government Institute event.

Todd Hemmen on Mythos and systemic vulnerabilities

At a public forum, Todd Hemmen framed Anthropic’s Mythos as a new class of challenge for law enforcement. He described findings from the model that touched “open-source code that is so ubiquitous” and listed areas — operating systems, security, web infrastructure, encryption — where the vendor said Mythos could identify and exploit previously unknown bugs. Hemmen characterized those discoveries as presenting “future challenges for law enforcement,” and warned that while the FBI has not yet observed those capabilities used “operationalized at scale,” the agency expects a future date when that changes.

Export controls on Mythos 5 and the guardrail review

The Trump administration imposed export controls on the Mythos 5 model in June shortly after its release, citing national security implications. Anthropic had stated in a blog preview that Mythos 5 could identify and exploit bugs “in every major operating system.” Over recent weeks, those prohibitions were lifted after Anthropic “worked with the government and other partners to review guardrails,” according to the reporting. The company also found that “less capable” models could identify vulnerabilities similarly, and that an Anthropic-built model with the same underlying technology is available globally even though Mythos 5 itself is limited to a select U.S. government-approved group.

FBI’s investigative posture and how access changes the suspect list

Hemmen reminded listeners that the FBI is the lead federal agency for investigating cyberattacks and intrusions — a role that places the bureau at the front line as capabilities evolve. He noted a simple operational fact: when tools with wide-ranging security implications become accessible, “the suspect list grows longer and investigations become more complex.” That is linked to the government’s concern that the potential to expose vulnerabilities at scale could enable new exploitations by adversaries, even if the bureau has not yet seen widespread operational use of such model-led exploitation.

FBI internal AI use and the agency’s inventory

The FBI is also expanding the ways it uses AI internally. Hemmen said the bureau is “leveraging AI for facial recognition technology.” In its latest AI use case inventory, published earlier this year, the FBI identified a handful of new projects aimed at generating investigative leads using facial matches and other data. Those projects are classed as high-impact — meaning they could serve as a principal basis for decisions or actions with legal, material, binding or significant effects on rights or safety.

Despite an April 3 deadline from the Office of Management and Budget, the FBI has not completed its risk management requirements for any of its high-impact use cases, according to the inventory. The reporting states that “the DOJ division has around 50 AI use cases.” FBI staff are applying AI to triage public reports of criminal allegations, to enhance court-authorized offensive operations, and for general research. Hemmen emphasized process controls in that work: “We’re using AI to help triage those things and with a human in the loop to review everything that’s being done.”

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Hemmen’s comments put a premium on auditing the open-source components Hemmen named — operating systems, web infrastructure and encryption libraries — because Anthropic’s preview claims those areas were within Mythos’s reach. The vendor’s finding that “less capable” models can also identify vulnerabilities means defenders must watch a widening range of tools, not only flagship models.
  • Policymakers and regulators: The June export controls and their subsequent lifting after a guardrail review illustrate two levers available to government — temporary restriction and collaborative mitigation. The unresolved administrative detail in the report is the completion of required risk management for high-impact FBI AI projects, despite an OMB deadline.
  • Affected enterprises and procurement leaders: The existence of Anthropic-built models with similar underlying technology available globally — contrasted with Mythos 5’s limited access — underscores a procurement dilemma: product-specific controls may not contain broader architectural capabilities once variants circulate.

The picture that emerges from Hemmen’s remarks and the recent Anthropic developments is a working tension: law enforcement is both adapting to AI internally and bracing for new forms of external exploitation tied to model capabilities, even as procedural safeguards and risk-management steps remain incomplete. The immediate, concrete questions left on the table are practical: will investigations detect and stem any operationalized exploitation when it appears, and will the FBI finish the risk management work on its high-impact use cases by the deadlines that govern them?

Original story