NHS to hide open-source code by May 11 AI hack risk

Get the Health newsletter
Daily health & science — research, biotech, public health, the studies worth knowing. Free.
- NHS England will pull open-source code from public view by 11 May due to AI hacking risk from Anthropic’s Mythos.
- Open letter signed by 682 people, including Cory Doctorow and Matt Hancock, urges reversal, calling the policy a “huge mistake”.
- Vlad‑Stefan Harbuz used Mythos to scan NHS code, finding several severe vulnerabilities, which were disclosed before the pullback.
- AI Security Institute concluded Mythos can only target small, weakly defended enterprise systems, not highly secure networks.
- Terence Eden argues the move harms transparency and public trust, urging NHS to keep code open source.
- NHS service standard requires staff to make software open-source, and experts say the pullback will not improve security.
Why it matters: The pullback blocks developers and security researchers from accessing NHS code, limiting peer review and bug‑fix contributions, while the NHS claims a temporary security gain; experts argue the move does not enhance security and undermines the transparency mandated by the NHS service standard.



