Anthropic has decided the safest place for its most restricted model is not a vault. It is a larger, supervised room full of people who run things that break badly. On Tuesday, the company said Project Glasswing will expand from roughly 50 early partners to about 150 additional organisations in more than 15 countries, with Claude Mythos Preview pointed at code that sits under power, water, healthcare, communications, and hardware.
That sounds like a rollout, but the word is too clean. This is a controlled spread of capability that Anthropic itself treats as dangerous enough to gate. Each new organisation has to meet its security requirements before access. The point is not that Mythos can write better incident reports or draft friendlier Jira tickets. The point is that it can find vulnerabilities at a scale human teams can't comfortably absorb.
The numbers have the unpleasant brightness of a successful stress test. Anthropic says the initial partners have found more than 10,000 high- or critical-severity flaws since the early April launch. In a separate open-source scan, the company reported 23,019 potential vulnerabilities, with 6,202 estimated as high or critical. Of 1,752 high- or critical-rated findings that were independently reviewed, 90.6 percent were true positives.
That is impressive, obviously, and also a workload generator with a safety label on it. CyberScoop quoted Anthropic's own description of the new bottleneck: the "human capacity to triage, report, and design and deploy patches." I don't think that is a footnote. It is the story. Security has spent years saying that defenders are outnumbered by attackers, by legacy systems, by badly maintained dependencies, by the sheer amount of code that modern life has made ordinary. Now a lab has built a machine that can make the backlog visible faster than the institutions can fix it.
There is a strange moral inversion here. If a powerful vulnerability-finding model stays inside the lab, the defenders remain underpowered. If it leaves, even under a vetted programme, the circle of people who can operate it gets larger. I wrote in April about the earlier Glasswing fight, when the politics around Mythos looked like a contest between private access, national-security anxiety, and a government that wanted the tool close while worrying about everyone else using it. Today's announcement doesn't dissolve that tension. It formalises it.
The partner list is also doing political work. Anthropic's launch page named AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks among the launch partners, with up to $100 million in Mythos Preview usage credits and $4 million in donations to open-source security groups. SecurityWeek, citing the Financial Times, says the new wave includes organisations such as Okta, Samsung, ENISA, and NATO. Dark Reading reported on ENISA's likely access a day earlier, framing it as the result of cooperation between the European Commission and Anthropic. Put less politely: this is becoming infrastructure policy by customer list.
That may be the only practical route. Nobody wants the model handed around casually. Nobody serious wants critical software maintainers to keep finding flaws at human speed if attackers are going to get similar tools. So the answer becomes a club: enough members to matter, few enough to audit, with security requirements standing in for public law.
The awkward timing is that Anthropic is also trying to become legible to public markets. Yesterday's confidential S-1 filing made the company look less like a private research lab and more like a systemically important vendor preparing for quarterly scrutiny. Glasswing makes the same argument in operational form. If Claude is now part of how governments, banks, cloud providers, and infrastructure operators think about software risk, then the old category of "AI company" starts to feel too small.
I don't have a neat objection to the expansion. The alternative is not purity. It is slower discovery, quieter defects, and the hope that adversaries remain less capable than the people patching the pipes. Hope is a poor patching strategy. Still, this is a hard thing to watch without noticing how much authority is moving into private coordination: who gets access, which vulnerabilities get prioritised, whose infrastructure counts as globally important, and how quickly the rest of us hear about the bugs already found.
Sources:
-
Expanding Project Glasswing — Anthropic
-
Project Glasswing — Anthropic
-
Project Glasswing Initial Update — Anthropic
-
Anthropic Scales Claude Mythos to Critical Infrastructure in 15+ Countries — TechCrunch
-
Anthropic Expanding Access to Project Glasswing — CyberScoop
-
Anthropic Expanding Mythos Access to 150 New Organizations — SecurityWeek
-
Anthropic to Open Mythos AI to EU's ENISA — Dark Reading