AI

Anthropic takes Project Glasswing to critical infrastructure operators in 15 countries

04 June 2026
3 minutes
Anthropic has extended its Project Glasswing cybersecurity initiative to around 150 new organisations, bringing communications operators and other critical infrastructure sectors into the model.

Project Glasswing gives selected partners access to Claude Mythos Preview, a general-purpose frontier model that remains unreleased to the public, for use in defensive cybersecurity work. Each organisation is required to meet security requirements before gaining access.

The programme launched in early April with an initial cohort of roughly 50 partners, including Amazon Web Services, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks. That first wave focused primarily on large technology companies and security firms.

The expanded group covers several industries that were not well represented in the initial cohort, including power, water, healthcare, communications and hardware, and many of the new partners are vendors that maintain codebases relied upon by governments and other organisations around the world.

The communications sector’s inclusion is significant. Anthropic has stated that a major attack on most partner codebases could affect more than 100 million people.

The scale of what Mythos Preview has already identified makes the stakes clear. Since the programme launched, partners have surfaced more than 10,000 high- or critical-severity software vulnerabilities.

Anthropic also used Mythos to scan more than 1,000 open-source projects, flagging 23,019 potential vulnerabilities, of which 6,202 were estimated as high or critical. Of 1,752 high- or critical-rated findings independently reviewed, over 90 per cent were confirmed as valid.

Several partners reported that their rates of bug discovery with Mythos had increased more than tenfold. The model’s capability, however, is also the source of concern.

Anthropic describes Mythos Preview as having reached a level of coding capability where it can surpass all but the most skilled humans at finding and exploiting software vulnerabilities and warns that it will not be long before such capabilities proliferate to actors who may not deploy them safely.

Anthropic has acknowledged that the bottleneck is no longer discovery but the human capacity to triage, report, design and deploy patches before attackers can take advantage of what has been found. The company has said its longer-term goal is to shift the support it provides from finding vulnerabilities to disclosing, fixing and deploying patched software.

Alongside the expansion, Anthropic plans to make vulnerability discovery tools developed for Project Glasswing available to trusted security teams upon request and has said it is working to release Mythos-level capabilities to general customers once additional cyber safeguards are in place. Anthropic has committed up to $100 million in usage credits to support the programme.

RELATED STORIES

Anthropic secures full capacity of SpaceX’s Colossus 1 data centre in Memphis compute deal

Why Amazon is investing $25bn into Anthropic in a major AI deal

Metro Connect Fall 2026

01 September 2026