BotBeat
...
← Back

> ▌

AnthropicAnthropic
POLICY & REGULATIONAnthropic2026-05-18

NHS Orders Hundreds of GitHub Repositories to Go Private Over AI Security Concerns

Key Takeaways

  • ▸The NHS mandated all public GitHub repositories be made private by May 11, citing risks from AI models like Anthropic's Mythos that can rapidly discover vulnerabilities at scale
  • ▸This reverses the NHS's explicit policy favoring open source for publicly-funded code, marking a major policy reversal driven by AI safety concerns
  • ▸Most affected repositories contain low-risk content (documentation, architecture, internal tools), suggesting the threat level may be overstated
Source:
Hacker Newshttps://www.theregister.com/software/2026/05/05/nhs-to-close-source-github-repos-over-ai-security-concerns/5224392↗

Summary

The UK's National Health Service (NHS) has mandated that all publicly accessible GitHub repositories be made private by May 11, 2026, citing security risks posed by advanced AI models, particularly Anthropic's Mythos. Internal NHS guidance reveals that the organization views public code repositories as material security risks, stating they "increase the risk of unintended disclosure of source code, architectural decisions, configuration detail, and contextual information" that frontier AI models capable of large-scale code analysis could exploit.

The decision represents a significant reversal of the NHS's established open source policy, which previously mandated that all new publicly-funded code be made open and shareable unless there was an explicit need for secrecy. This policy reflected the principle that taxpayer-funded technology should be reusable across the public sector. The temporary shift marks a watershed moment where organizational leadership has prioritized cybersecurity concerns over open development principles in response to rapid AI advancement.

However, NHS sources suggest the actual risk is likely overstated. Most of the hundreds of affected repositories contain low-sensitivity materials such as documentation, architecture diagrams, and internal tools for managing clinical schedules. While frontier AI models like Mythos could theoretically identify latent code vulnerabilities, there is minimal direct threat to active healthcare services. The NHS characterizes this as a temporary measure while assessing the cybersecurity implications of advanced AI models, though no timeline has been provided for reopening repositories.

  • The move reflects broader organizational anxieties about frontier AI models' code analysis and reasoning capabilities
  • No timeline was provided for when repositories will be reopened, though the closure is described as 'temporary'
HealthcareCybersecurityRegulation & PolicyAI Safety & AlignmentPrivacy & Data

More from Anthropic

AnthropicAnthropic
POLICY & REGULATION

Advanced AI Models Bring Government to 'Reflection Point,' CIA Official Says

2026-05-20
AnthropicAnthropic
RESEARCH

Anthropic Claude Code Sandbox Bypass: Second Vulnerability Exposes Critical Data Exfiltration Risk

2026-05-20
AnthropicAnthropic
RESEARCH

AI Safety Catastrophically Underfunded: Economic Model Reveals Incentive Gap

2026-05-20

Comments

Suggested

Helmholtz MunichHelmholtz Munich
RESEARCH

MouseMapper: AI Foundation Model Maps Systemic Damage from Obesity at Whole-Body Scale

2026-05-20
AnthropicAnthropic
POLICY & REGULATION

Advanced AI Models Bring Government to 'Reflection Point,' CIA Official Says

2026-05-20
OpenAIOpenAI
FUNDING & BUSINESS

OpenAI Prepares for IPO After Musk Lawsuit Threat Clears

2026-05-20
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us