OpenAI Scolded Anthropic for Restricting Mythos—Then Quietly Did the Same Thing

Days after calling out Anthropic for limiting Mythos, OpenAI restricted its Cyber agent—sources say the tool was being used to probe rival AI systems for vulnerabilities.

Security researcher at dual monitors showing AI vulnerability scan results and competitor system architecture, representing dual-use cybersecurity tools
  • OpenAI restricted its Cyber reasoning agent days after publicly criticizing Anthropic for limiting Mythos.
  • Sources say Cyber was being used to probe vulnerabilities in rival AI systems.
  • The reversal shows the gap between OpenAI’s “cybersecurity tool” pitch and what the technology actually does.

OpenAI clamped down on access to its Cyber reasoning agent this week—just days after the company publicly called out Anthropic for restricting its own Mythos security model. The timing could hardly be less subtle. reported TechCrunch, citing sources who say Cyber was being used to probe for vulnerabilities in competitor AI systems.

The dust-up started when Anthropic quietly limited access to Mythos, the model that autonomously found critical flaws across major browsers and operating systems—including a 27-year-old OpenBSD vulnerability that evaded 5 million fuzzer attempts. OpenAI’s policy team called it out publicly. Then came the quiet reversal. reported Axios that both companies met behind closed doors with the House Homeland Security Committee last week to discuss the national security implications of AI vulnerability research.

The irony writes itself. “We aren’t even allowed to say the name Anthropic right now,” said a current CISA employee to Forbes, explaining that federal cyber defenders lack access to either company’s advanced security models. Meanwhile, foreign hacking groups and nation-state actors almost certainly do not have the same ethical constraints. The U.S. government’s leading cyber agency is playing defense without the best tools, while the companies that built those tools are fighting over who gets to hold them.

AI Cyber Tools Have Two Edges—And Everyone Pretends Only One Is Real

OpenAI marketed Cyber as a defensive tool: find bugs, fix vulnerabilities, protect infrastructure. It launched a “Trusted Access for Cyber” program in April and hosted a Washington workshop to court federal agencies. But the same model that finds vulnerabilities in your code can find vulnerabilities in a competitor’s AI system. That is not a hypothetical—it is reportedly what happened, which is why the access restrictions landed. The offensive use case is real, documented by the fact that both companies hit the same wall at almost the same time.

Anthropic’s response to that realization was blunt: lock Mythos down entirely. OpenAI’s response was initially to position itself as the responsible alternative—the company that would not restrict access. That argument lasted about as long as it takes a Senate staffer to read the briefing memo. Within days, OpenAI had quietly limited Cyber too. reported CNN that the company is actively courting government customers for its cybersecurity program while America’s own cyber agency still has no access to any of the advanced models from either lab.

The pattern is becoming familiar: AI companies discover their research tools are double-edged swords, quietly restrict them, and then claim the moral high ground. We covered Bessent and Powell’s bank CEO summit last week as the government response to exactly this problem. The Treasury Secretary and Fed Chair called in the heads of major banks after Mythos demonstrated how thoroughly AI can find vulnerabilities that human researchers miss for decades. Banks now face the same tool that found those flaws—capable of being used by attackers as easily as defenders. The government response is legislation draft, not a solution.

Neither OpenAI nor Anthropic has publicly discussed the specific nature of the probe activities that triggered their respective restrictions. Both companies declined to comment for this article. The restrictions appear to remain in place. CISA continues to have no access to either model, according to Forbes—which is probably for the best, given the agency’s recent workforce cuts and the likelihood that any access would have been used to analyze attacks on critical infrastructure rather than to prevent them.

Leave your vote