An AI Just Broke Into the NSA, And Nobody's Talking About What That Actually Means.
- Michael Routhier

- Jun 26
- 7 min read

I'm not being dramatic. I'm not writing a clickbait headline to get attention. What I'm about to tell you is real, it happened this month, and the fact that most people are already scrolling past it, or worse, arguing on the internet about whether it "counts", tells me everything about where we are right now.
We have a problem. And it is bigger than partisan politics, bigger than any one company, bigger than any one country's intelligence agency.
So let's talk about it.
Here's What Actually Happened
On June 11, 2026, Anthropic, one of the largest AI companies in the world, the company behind the Claude AI assistant that millions of people use every day, ran a controlled security test with one of its most powerful models, called Mythos.
They pointed it at classified systems belonging to the NSA. The National Security Agency. The organization whose entire reason for existing is protecting the most sensitive digital infrastructure in the United States. The people with more cybersecurity resources than virtually any entity on the planet.
The AI broke into almost all of them.
Not in weeks. Not in days.
In hours.
Those words came directly from General Joshua Rudd, the head of the NSA and U.S. Cyber Command, who reported this to Senator Mark Warner, Vice Chair of the Senate Intelligence Committee.
Now, I want to be precise here, because precision matters. This was a controlled red-team test; meaning the NSA authorized it, set it up, and used Mythos alongside other tools under specific conditions. This was not a foreign adversary sitting in a basement. This was not a rogue attack.
But here is the question I want to ask you.
Does that make you feel better? Or does it terrify you even more?
Because if the NSA just proved to themselves that an AI model can dismantle their most classified systems in hours, in a controlled, friendly, authorized environment, what does that tell us about what happens when someone less friendly points the same capability at a hospital? A power grid? A bank? Your accounts?
The Government Already Knows. That's Why They Panicked.
The day after that test, June 12, 2026, the Trump administration issued an emergency directive to Anthropic; shut down Fable 5 and Mythos 5. Immediately. For all foreign nationals, everywhere, including Anthropic's own international employees.
This was the first time the United States has ever applied export controls directly to an AI model, not the hardware, not the chips, the model itself.
Anthropic couldn't practically enforce nationality-based restrictions at scale. So they pulled the plug on both models globally. Millions of users lost access overnight. No detailed public explanation. Just a quiet, urgent letter from Commerce Secretary Howard Lutnick to Anthropic's CEO.
When a government moves that fast, and that quietly, it is not overreacting. It is responding to something it doesn't want explained in public yet.
That should tell you something.
And Then the Five Eyes Spoke
A few days later, something else happened that barely made the news.
The Five Eyes, that's the intelligence alliance between the United States, the United Kingdom, Canada, Australia, and New Zealand, the most powerful intelligence coalition on earth, released a joint statement on AI and cybersecurity.
I want to read you one line from it, because I need you to feel the weight of this.
"Next-generation AI models are expected to surpass current industry predictions, fundamentally altering both offensive and defensive cyber strategies. The timeline is not years. It is months."
Months.
Five intelligence agencies. Five countries. One message.
They are not talking about some theoretical future. They are telling us right now, in June 2026, that we are already inside the window where AI changes the rules of what's possible for anyone who wants to attack a system. And CISA, the U.S. cybersecurity defense agency, has already shortened the window for government officials to patch critical vulnerabilities from weeks down to three days, because AI is compressing attack timelines from hours to minutes.
Three days to patch. Minutes to attack.
Let that settle in.
This Is the Virtuous Machine Question
I keep coming back to something Marcus Aurelius wrote; "Look things in the face and know them for what they are."
Not what the press release says. Not what the company's spokesperson says. Not what the viral tweet says. What it actually is.
So let me tell you what this actually is.
The most powerful AI tools ever built are now capable of finding and exploiting vulnerabilities in the most hardened digital systems on earth. Those same tools are commercially available, or will be, to governments, corporations, criminal organizations, and lone actors who have the right access and the right prompt. The same AI that helps you write an email and plan your grocery list exists on a spectrum that ends with something that can dismantle national infrastructure in hours.
That is not speculation. That is what the NSA just demonstrated. To themselves.
And the companies building these tools, I want to say this clearly, are not primarily asking whether this should exist. They are asking how fast they can build the next version. Because the incentive structure rewards speed, not wisdom.
We have talked about how AI is being used to exploit the vulnerable. We've talked about brain data being harvested from caregivers who were just trying to protect someone they love. We've talked about deepfake scams targeting seniors. We've talked about the gap between what technology claims to be and what it actually is.
This is the same conversation. Scaled up to civilization level.
This Is Not Just a Government Problem
Here is where I need every single person reading this, whether you're 25 or 75, to lean in.
When classified government systems can be breached by AI in hours, the cybersecurity practices of everyone downstream get weaker too. The criminal organizations and foreign adversaries who now have access to similar tools are not going to stop at the NSA. They are going to use those same capabilities to target banks, hospitals, utility companies, insurance providers, and through all of them, they are going to target you.
AI-powered cyberattacks surged 340% in 2026. That number is not abstract. That is the number of times someone tried to use AI to break into something that doesn't belong to them.
Your email. Your bank account. Your medical records. Your pension. Your grandchildren's school systems.
That is the blast radius of what happened on June 11.
What You Can Actually Do, Right Now
I refuse to leave you with nothing but fear. That's not what this show is for.
The goal of the Virtuous Machine is not to make you feel helpless. The goal is to make you informed, because informed people make different decisions. So here is what you can actually do.
For your personal digital security:
Turn on two-factor authentication (2FA) on every account that matters. Email, banking, social media, everything. AI-powered attacks are fast, but 2FA adds a barrier that automated tools still struggle with. If your bank or email provider offers it and you haven't turned it on, do it today. Not this week. Today.
Use a password manager. One strong, unique password per account. If one gets compromised, the others remain safe. Bitwarden and 1Password are both reputable and easy to use.
Update your devices now. CISA just cut the patch window to three days because AI is exploiting vulnerabilities that fast. If your phone or computer is prompting you to update, stop delaying it.
Be suspicious of anything urgent. AI-powered phishing attacks are now sophisticated enough to impersonate people you know, using your real name, in your real context. If someone, even someone who looks familiar, is pressuring you to click something, send something, or confirm something quickly, slow down.
Monitor your credit. Services like Credit Karma (free) or your bank's fraud monitoring alerts can catch unauthorized access early. Set up alerts for any transactions over a threshold you choose.
Who you can contact and where you can report:
🇨🇦 Canada - Canadian Centre for Cyber Security: cyber.gc.ca - Report cyber incidents, get plain-language guidance, sign up for threat alerts
🇺🇸 USA - CISA (Cybersecurity and Infrastructure Security Agency): cisa.gov - Report threats, access free resources, subscribe to their alert system
🇺🇸 USA - FBI Internet Crime Complaint Center (IC3): ic3.gov - File a complaint if you've been targeted
🇬🇧 UK - National Cyber Security Centre: ncsc.gov.uk - Report incidents, access free tools and guidance
🇦🇺 Australia - Australian Signals Directorate: cyber.gov.au - Alerts, reporting, and free resources
For your voice to matter beyond your own front door:
Contact your elected representative. In Canada, that's your MP at ourcommons.ca. In the U.S., find your Senator or Representative at congress.gov. Tell them you want real AI safety legislation with enforcement teeth, not press releases.
Sign up for the Canadian Centre for Cyber Security threat alerts. It is free, it is in plain language, and it will tell you when something significant is emerging before it reaches you.
Epictetus on What We Control
Epictetus said; "Make the best use of what is in your power, and take the rest as it happens."
You cannot stop Anthropic from building Mythos. You cannot stop the adversaries who are already building the same thing. You are not in that room.
But you are in your own room. And in your own room, you can make different choices starting today. You can harden your own accounts. You can learn to recognize the attacks that are coming. You can demand, loudly, in writing, to the people who represent you, that the people making decisions about these tools be held accountable to something beyond their quarterly earnings.
That is not powerlessness. That is the only thing that has ever actually changed anything.
Before You Go
I want to know what you're thinking right now.
Are you angry? Scared? Skeptical? Are you someone who works in IT and has been trying to sound this alarm for years? Are you someone who didn't know any of this happened until you read this post?
Every one of those responses deserves to be in this conversation.
Tell me in the comments. I'll read every one.
And if this reached someone who needed to hear it, please share it. Print it out. Read it to someone. Pass it along. The people most vulnerable to what I just described are often the people furthest from the conversations where it gets discussed.
Be the person who changes that.
This is Tech 4 Grown-Ups. Stay sharp. Stay loud.
And don't let anyone, any government, any corporation, any AI lab, make decisions about your digital future without your voice in the room.
Michael Routhier is the founder of Tech 4 Grown-Ups, a digital literacy platform for adults 55 and over. The Virtuous Machine is a series exploring the ethics, power, and human cost of artificial intelligence. Find everything at tech4grownups.com.



Comments