
Judge for yourself: at the bottom are links to the lawmakers' questions, the agreement itself and the state's list of the AI tools it uses.
This summer, a group of state developers began testing tools from the AI company Anthropic to find security holes in Vermont’s computer code before hackers could. The trial was free. It ends in December.
At a legislative hearing Wednesday, Secretary of Digital Services Denise Reilly-Hughes described it as limited and supervised. Members of the Joint Information Technology Oversight Committee said they would like the paperwork to confirm that.
What the state did
Anthropic offered state and local governments $100,000 worth of free use of its tools for six months to look for weak spots in their own software. Vermont signed on in June. Reilly-Hughes said about half the states have joined.
Here is how she described the work:
Test code only. Developers gave the AI pieces of test and development code, not the live systems that hold Vermonters’ records.
Pieces, not whole systems. None of the state’s large systems was reviewed in full. She said a few short programs at the Agency of Natural Resources got a more complete review.
People review the results. The AI sent back reports on possible weak spots, and state staff reviewed them.
Code is the written instructions a computer program runs on. It doesn’t contain your DMV record or benefits file. But it can show how the systems that hold those records are built and protected, and sometimes has passwords written into it. That’s why lawmakers care where it went.
The pieces of code did leave state computers for Anthropic’s. Reilly-Hughes said the state keeps control of its account there. “We are still the administrators and we still have the control in the environment,” she said.
Why it became a dispute
The two sides disagree about process, not about whether the state should use these tools.
The lawmakers’ side: Rep. Laura Sibilia, I-Dover, says she learned of the trial by chance on Aug. 4, at a state technology conference. She says the state’s then-security chief told the audience Vermont was “fortunate” it didn’t have to go through the Legislature. Sibilia met with Reilly-Hughes Aug. 28. On Sept. 24, she, Rep. Monique Priestley, D-Bradford, and committee chair Sen. Rob Plunkett, D-Bennington, sent the agency 10 written questions.
The agency’s side: The Agency of Digital Services didn’t consider the free evaluation a procurement, so it didn’t run it through the state’s full contract review. That review is the set of checks agencies use before signing with a vendor, including bidding and legal sign-off. Reilly-Hughes said statements the former security chief made didn’t reflect her agency’s position.
“I am not opposed to Vermont using artificial intelligence,” Sibilia said in written testimony. “I come into it wanting answers.”
“The more powerful the technology, the more important it is that we understand who authorized its use,” she wrote.
What happened in the room
The hearing was tense.
The secretary objected to the memo. Reilly-Hughes said the lawmakers’ questions “were asked in a way that indicated wrongdoing,” adding she was sure that wasn’t the intent.
A senator saw politics in the timing. Sen. David Weeks, R-Rutland, said the process had “the appearance of a bit of sensationalism with four weeks remaining in the election.”
The chair apologized for the tone. Plunkett apologized for what he called the perceived tone of the memo. The questions in it still stand, and Reilly-Hughes agreed to answer them in writing.
Readers can read the memo and decide for themselves by clicking on it here.
Depending on where you sit, the hearing offered material for either reading: an agency that didn’t think it needed to tell anyone, or lawmakers grandstanding a month before an election. The record doesn’t settle either one. Here’s what it does show.
What the hearing settled
Future trials get full review. Reilly-Hughes said that after consulting Secretary of Administration Sarah Clark, trials like this one will go through the state’s full contract review. She called it a precaution and said she still doesn’t consider this trial a purchase that required that review.
It will be on the public list. She said the trial will be added to the state’s annual public inventory of AI tools, which a 2022 law requires.
Written answers are coming. Answers and documents are due to the committee by Wednesday, Oct. 7.
What it didn’t settle
What the signed agreement says. The only version made public is an unsigned copy of Anthropic’s standard form for government trials, attached to the lawmakers’ memo. It gives the tools “as is,” with no guarantee, and caps either side’s liability at $1,000, or 1 percent of the trial’s value. The cap also protects Vermont: it limits what the state would owe Anthropic. “We were comfortable with the terms of the agreement,” Reilly-Hughes said.
Which AI did the work. Reilly-Hughes said it was not Mythos, Anthropic’s most powerful model for finding security holes. On Aug. 21, in the middle of Vermont’s trial, Anthropic switched its scanning tool to Mythos. Anthropic’s coding assistant runs on the customer’s regular models, not Mythos, so both accounts can be true. The open question is whether Vermont used the scanner after Aug. 21.
Whether any state code was kept. Anthropic keeps whatever is sent to Mythos for 30 days, even for customers promised that nothing is kept. Whether that applies to Vermont turns on the previous question.
What the trial found. Reilly-Hughes said she didn’t have an exact count of the systems reviewed and hadn’t been fully briefed, because the trial isn’t finished.
Three claims that didn’t hold up
The timing. Vermont Public's headline said the Scott administration "begins using AI" to probe state systems. Its own story says the state signed the agreement June 15. The trial had been running for more than three months, and it ends in December.
Hugging Face. The same article included in the committee’s hearing materials said Anthropic’s models broke out of testing and attacked another company, in what it called the Hugging Face incident. That breach was OpenAI’s. Anthropic disclosed separate incidents in which its models reached real systems during hacking tests where internet access had mistakenly been left open.
Sept. 20. A witness said an OpenAI agent got “into U.S. government systems” that day. OpenAI says the agent reached an outside chatbot, not government systems, though its automatic shutdown failed for about two and a half hours.
Travis Hall of the Center for Democracy and Technology called using AI for state cybersecurity “a cautious yes.” He said the limits on these tools should be set before the state buys anything.
“I would be more concerned if we were not doing this type of work,” Reilly-Hughes said.
See It for Yourself
These are the documents this story is built on. Read them and reach your own conclusions.
The lawmakers’ questions and the agreement: the memo includes the unsigned agreement at the end.
The hearing itself: the Legislature’s video of the meeting.
The state’s list of AI tools it uses: the Agency of Digital Services AI page. Reilly-Hughes said this trial will be added to that list.


