Safety

AI-generated text

Anthropic expands Project Glasswing to about 150 more critical organizations

Anthropic announced on June 2, 2026 that it is widening Project Glasswing by inviting roughly 150 additional organizations to access Claude Mythos Preview after security vetting.

Anthropic expands Project Glasswing to about 150 more critical organizations

On June 2, 2026, Anthropic announced an expansion of Project Glasswing: after an initial cohort of about 50 partners, the program will invite roughly 150 more organizations to participate, subject to meeting Anthropic’s security requirements. The project uses Claude Mythos Preview to help identify vulnerabilities in important software systems.

Background and early results

In early April Anthropic disclosed that the initial ~50 partners had access to Claude Mythos Preview and had begun scanning their codebases. According to Anthropic, those partners have so far discovered more than 10,000 high- or critical-severity security flaws.

Details of the expansion

  • The newly invited group comprises about 150 organizations located across more than 15 countries. Most provide critical infrastructure or services that affect many more countries and users.
  • The expansion intentionally brings in sectors that were underrepresented in the first cohort, including power, water, healthcare, communications and hardware.
  • Many of the new partners are vendors or nonprofit maintainers whose codebases are relied on by numerous other organizations worldwide, including governments.
  • Anthropic states that a successful attack on these partners’ code could be catastrophic; for most partners the company estimates a major incident could affect more than 100 million people and carry significant global and national security implications.

Project Glasswing’s goals

Anthropic frames Project Glasswing as pursuing two main objectives: (1) help the software industry adapt by providing safer, wider access to more capable models, tools and shared infrastructure; and (2) shift support progressively from finding vulnerabilities toward coordinating disclosure, fixing, and deploying patches.

The company warns that within six to twelve months many other AI companies are likely to have Mythos-class models, some of which could be released without adequate safeguards. That environment could make cyberattacks more frequent and less predictable, increasing the urgency for defenders to adapt.

Supporting cyberdefenders

Early Project Glasswing participants rapidly adopted Mythos Preview at scale, shared findings and best practices, and worked with third parties to triage results. To support defenders, Anthropic recently released Claude Security, a product that uses its latest public frontier models such as Claude Opus 4.8 to scan codebases and suggest patches.

Anthropic is also making available—on request to trusted security teams—the internal tools it developed to help Project Glasswing partners discover vulnerabilities more quickly.

Accelerating disclosure and patching

Anthropic has previously identified the main bottleneck as verifying, disclosing and patching the large number of vulnerabilities that Mythos-class models can reveal. Partners are already using Mythos Preview to write patches and perform pre-release checks to prevent new vulnerabilities. The company notes the model can also be used for penetration testing, automating threat detection and response, and helping migrate legacy code to memory-safe languages.

Anthropic says it is in discussions with third parties to scale up review and patching of vulnerabilities in open-source software, and is working to share ideas and best practices for reporting vulnerabilities to maintainers to make triage and remediation easier.

Next steps and broader outlook

Addressing the upcoming scale of this challenge will likely require hundreds of thousands of organizations, researchers and maintainers to have access to advanced cyber capabilities and tools. Anthropic is working to make Mythos-level capabilities available more broadly and safely, but notes strong and precise safeguards are still needed—safeguards that, to its knowledge, have not yet been developed by them or other AI developers.

In the near term, Anthropic plans further expansions of Project Glasswing, prioritizing additional essential infrastructure providers, maintainers of critical open-source projects, and safety testers. The company also intends to scale up its Cyber Verification Program to grant Mythos-class capabilities to more organizations for specific cyberdefense tasks.

Anthropic concludes that future frontier model releases will be higher-stakes as capabilities improve across domains like cybersecurity, which can empower attackers and defenders alike. Project Glasswing, the company says, has already provided lessons on how to respond when models cross important capability thresholds, and if successful the initiative could help give defenders a lasting advantage.