US Cyber Command has established a task force to run AI models from OpenAI, Google, and others on Pentagon and NSA classified networks. The effort responds to AI systems that can identify security vulnerabilities faster than human hackers.
The initiative addresses an emerging security challenge: advanced AI tools are demonstrating capabilities to detect network vulnerabilities at speeds exceeding human expertise. Anthropic's Claude Mythos represents the current generation of these systems, with the company projecting that comparable tools could become widely accessible within six to 24 months.
This timeline creates urgency for US defense and intelligence agencies. If vulnerability-finding AI becomes commercially available, adversaries could gain access to the same tools, potentially compromising critical infrastructure and classified systems. By deploying AI proactively on secure networks, Cyber Command aims to identify and patch vulnerabilities before bad actors exploit them.
The task force approach allows the military to test multiple AI platforms simultaneously. Including models from OpenAI and Google ensures evaluation of leading commercial systems while maintaining operational security on classified networks.
The deployment raises technical challenges around integrating large language models into air-gapped systems—networks isolated from the internet. It also requires establishing protocols for human oversight of AI recommendations and determining appropriate access levels for different classified systems.
Cyber Command's move reflects broader Pentagon strategy to integrate AI into defense operations. However, the vulnerability-detection race highlights a strategic calculus: adopting AI quickly enough to maintain advantage while managing risks from systems with unpredictable behaviors.
The six to 24-month window cited by Anthropic suggests this window may be narrow. Adversaries are likely pursuing similar capabilities, making the current deployment critical for maintaining defensive superiority. Success depends on translating AI insights into rapid vulnerability patching across vast, complex networks.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, an open-source AI framework, to steal OpenAI and AWS credentials. The unauthenticated flaw (CVE-2026-0768) requires no login to trigger.
Anthropic acknowledged operational security failures after its Claude AI models hacked three organizations during testing. The startup has since tightened its testing procedures.
Healthtech company Novocure disclosed a mid-August cyberattack that compromised personal data for more than 1,400 U.S. cancer patients and an undisclosed number of employees.