Apr 07, 2026 · View original article

Anthropic gates Claude Mythos Preview behind Project Glasswing over cyber capabilities

On 7 April 2026 Anthropic unveiled Claude Mythos Preview, a model it says has found thousands of zero-day vulnerabilities, and restricted access to a defensive-security coalition backed by $100 million in credits.

On 7 April 2026 Anthropic announced Claude Mythos Preview, which it describes as its most capable model to date, together with Project Glasswing, an initiative to route the model's offensive-grade security abilities toward defenders before adversaries obtain equivalent capabilities. Rather than a general release, Mythos Preview is a gated research preview: access goes to organisations that maintain critical software and infrastructure, and Anthropic commits to sharing findings across the industry.

The company says the model's strength in cybersecurity stems from its ability to understand and modify large, complex codebases, and claims it has already identified thousands of previously unknown vulnerabilities across widely used software. Twelve launch partners were named: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks, alongside Anthropic itself. More than 40 further organisations were given access. Anthropic is backing the programme with $100 million in usage credits and $4 million in donations to open-source security organisations. For approved participants the model is available through the Claude API, Amazon Bedrock, Google Cloud Vertex AI and Microsoft Foundry at $25 per million input tokens and $125 per million output tokens, several times the price of Anthropic's public models.

The framing is deliberately collaborative. Anthropic argues that frontier developers, software vendors, security researchers, open-source maintainers and governments must act together, summarised in its own words as "No single organization can do this alone."

Glasswing is the clearest example yet of a lab treating a model's capability profile as a reason to change its distribution model. OpenAI had already assigned a high cyber-capability rating to GPT-5.3-Codex and GPT-5.4 and introduced trusted-access programmes for vetted defenders; Anthropic goes further by withholding general availability entirely. Security commentators, including Bruce Schneier, noted that the approach effectively creates a period in which a small number of large firms have a vulnerability-discovery advantage, and asked how long that asymmetry can be maintained once comparable open-weight models appear. Anthropic later expanded the programme and, in June, said it intended to bring Mythos-class models to public release with additional safeguards.

For CISOs the immediate consequence is a change in the threat model. If frontier models can find exploitable bugs at scale in mature software, patch cadence and the depth of the backlog become urgent metrics.

What it means for leaders

  • Shorten patch windows now. Expect a surge in disclosed vulnerabilities in foundational software during 2026 as Glasswing findings are shared; measure mean time to remediate on internet-facing and open-source components.
  • Engage through your vendors. Most organisations will not get direct Mythos access; ask cloud providers, endpoint vendors and open-source foundations how they are applying Glasswing results to products you run.
  • Update AI risk registers for dual-use capability. NIST AI RMF and ISO/IEC 42001 require assessing misuse potential; note that vendors themselves now rate flagship models as high cyber risk.
  • Prepare governance for tiered access. Trusted-access schemes involve identity verification and use-case attestations; decide who in your organisation may apply and how usage is monitored.
  • Test your own code with AI-assisted review. Defensive use of capable models for static analysis and fuzzing is becoming standard; include it in secure-development lifecycle policies.

Comments

No comments yet. Be the first to comment.