Vivold Consulting
Safety & Ethics

Expanding Project Glasswing

Anthropic widens its frontier-AI cyberdefense program to ~150 organizations across 15+ countries

Key Insights

Anthropic is expanding Project Glasswing - its program giving vetted defenders access to frontier cyber capabilities - from roughly 50 initial partners to about 150 new organizations in 15+ countries, each pending security vetting. The original cohort has already used Claude Mythos Preview to find 10,000+ high- or critical-severity flaws. The expansion adds critical-infrastructure sectors like power, water, healthcare, and communications, and shifts focus toward disclosing and patching vulnerabilities, not just finding them.

Stay Updated

Get the latest insights delivered to your inbox

Scaling up the race to secure the world's critical software

Project Glasswing is Anthropic's collaborative push to harden the software that matters most. After starting in April with about 50 partners using Claude Mythos Preview to scan their code, the program is now opening up considerably - roughly 150 new organizations across more than 15 countries, each of which must clear Anthropic's security requirements before getting access.

Who's joining, and why they were chosen

The new cohort deliberately fills gaps in the first one, pulling in sectors like power, water, healthcare, communications, and hardware. Many are vendors - companies and nonprofits maintaining codebases that countless other organizations, governments included, quietly depend on. The common thread is stark: Anthropic estimates that for most of these partners, a successful attack could affect more than 100 million people, with real national- and global-security stakes.

Early results that justify the urgency

The initial partners didn't sit on the tools. Within weeks they were running Mythos Preview at scale and, collectively, have surfaced more than 10,000 high- or critical-severity vulnerabilities - the kind of number that reframes how quickly AI can change defensive cybersecurity.

The bottleneck is shifting from finding to fixing

Here's the strategic pivot: once a model can find vulnerabilities en masse, the hard part becomes verifying, disclosing, and patching them. Anthropic is leaning into that:

- Partners increasingly use Mythos Preview to write patches and run pre-release checks that stop bugs before they ship.
- The same models can handle penetration testing, automate threat detection and response, and rebuild legacy code in memory-safe languages.
- Anthropic is in talks with third parties about scaling up review and patching of open-source software, and about making vulnerability disclosures easier for maintainers to act on.

It also recently shipped Claude Security, a product using public models like Opus 4.8 to scan codebases and suggest patches, and is releasing some of its internal vulnerability-finding tooling to trusted teams on request.

The bigger warning

Anthropic frames all of this against a ticking clock: within 6-12 months it expects other labs to have Mythos-class models, some possibly released without safeguards. In that world, attacks could become more frequent and unpredictable. The point of Glasswing, then, is to nudge institutions toward new operating norms now - and, if it works, to hand defenders a durable, permanent edge before the offensive capabilities go mainstream.

Related Articles

Google's chief scientist walks: Jeff Dean leaves after 27 years, taking three legends with him

Jeff Dean, Google's chief scientist and 30th employee, is leaving after 27 years to found Discovery Loop, a public benefit corporation using AI to automate scientific research - taking co-founders Sanjay Ghemawat, Quoc Le (Google Brain), and Oriol Vinyals (DeepMind) with him. Google is a founding investor and cloud partner, supplying compute for at least the first year, with Radical Ventures and Khosla Ventures co-leading the seed. In the same announcement, Demis Hassabis steps down as DeepMind CEO to become chairman and Alphabet chief scientist, with Koray Kavukcuoglu taking over Gemini model development. Alphabet stock fell about 4%.

Open-weight models are months from the frontier - and refusing nothing

GLM-5.2, the open-weight model from China's Z.ai, now sits only a few months behind GPT-5.5 and Claude Opus 4.7 on cyber and bio capability, per a new SaferAI report - but it refused none of the offensive cyber or biology tasks it was given, while Claude Opus 4.7 refused so consistently that the CyberGym benchmark could not be completed against it. SaferAI says Z.ai published no safety framework, pre-deployment testing commitments, or risk assessment. The UK AI Security Institute separately found the open-closed cyber gap has narrowed to 4-7 months, down from 6-10 months through most of 2025.

Texas slams the brakes on data centres - and the AI buildout's easiest frontier just closed

Governor Greg Abbott announced that all new Texas data-centre projects must be audited by the Public Utility Commission and grid operator ERCOT - a sharp turn for a state whose loose regulation and cheap power made it second only to Virginia for data centres. The trigger is a staggering queue: ERCOT's interconnection requests doubled from 233GW in January to 474GW, about 90% data centres, more than five times the grid's all-time peak demand. Audits will demand power and water use, noise mitigation, light controls, tax-incentive use, and ownership details - after a voluntary survey that most operators simply ignored.