Full Breakdown
Anthropic Expands Project Glasswing Access to 150 New Organizations
6/3/2026, 8:57:58 PM
Anthropic Expands Project Glasswing to 150 New Organizations
On 2 June 2026 Anthropic announced that roughly 150 additional firms and agencies in more than 15 countries will receive access to Claude Mythos Preview, the company’s AI model capable of locating and exploiting software vulnerabilities. The expansion adds sectors that were under-represented in the original cohort—power, water, healthcare, communications and hardware—and brings the total partner count to about 200. Anthropic said each new participant must satisfy security requirements before gaining model access.
Background: Project Glasswing and the Mythos Model
Project Glasswing launched in April 2026 with about 50 trusted partners. The initiative provides selected organizations with Claude Mythos Preview, a frontier-model AI that can both discover and simulate exploitation of code flaws. Anthropic restricts distribution because the model’s capabilities are dual-use, offering defensive benefits while also enabling sophisticated attacks.
Timeline of Key Milestones
- April 2026 – Project Glasswing begins, 50 partners receive Mythos preview.
- 2 June 2026 – Announcement of 150-partner expansion; EU agency ENISA invited.
- 2 June 2026 – Anthropic files a confidential IPO prospectus with the SEC.
- 3 June 2026 – Reports confirm participation of NATO, ENISA, Okta, Samsung, SK Hynix, SK Telecom and other critical-infrastructure operators.
Scale and Scope: Data & Statistics
- ?150 new organizations, >15 countries -> total ? 200 partners.
- >10,000 high- or critical-severity vulnerabilities identified by early partners.
- Anthropic estimates a successful breach of any partner’s codebase could affect >100 million people.
- Reported participants include Apple, Nvidia, Microsoft, CrowdStrike, Palo Alto Networks, Rubrik, Okta, Samsung, NATO and ENISA.
Why It Matters: Cybersecurity Implications
The rollout underscores growing demand for AI-driven security tools as threat actors adopt comparable technologies. By aggregating advanced vulnerability-hunting capability, Anthropic aims to shift the defensive burden from reactive patching to proactive discovery. The move also intensifies competition with OpenAI, which has begun granting its own cyber-model GPT-5.5-Cyber to major U.K. banks. Regulators stress the need for robust safeguards because the same model can be weaponized, raising policy questions about responsible AI deployment in critical infrastructure.
Official Statements & Responses
Anthropic stated that the expansion “aligns with our long-term goal of making all software more secure” and that each partner “must meet our security requirements before they gain access.” A European Commission official noted that the EU must establish a “mechanism to access the model with proper security safeguards.” Bank of England Governor Andrew Bailey said U.K. banks “don’t have access to Mythos at the moment and that’s an issue that is very important,” while Canadian AI Minister Evan Solomon confirmed Canada’s participation in Project Glasswing.
Criticism & Opposition
Security analysts have warned that limited, opaque access may not constitute a comprehensive defense strategy and that the model’s dual-use nature could accelerate malicious exploitation. Open-source advocates express concern that future releases without strong safeguards could undermine community-driven security efforts. Competitors argue that Anthropic’s restrictive distribution contrasts with OpenAI’s broader rollout, potentially slowing collective defensive progress.
Conflicting Reports & Gaps
Sources differ on the exact list of new participants: some name Okta, Samsung and NATO, while others keep the roster confidential. The number of countries is described as “more than 15” in some reports and “15 additional” in others. Details on the technical safeguards under development remain unspecified, and the timeline for formal EU access mechanisms is not yet defined.
Verbatim Quotes
- “Following several weeks of close collaboration with our Project Glasswing partners, the security industry, open-source software maintainers, and the US government, we’re extending the partnership to approximately 150 new organizations.” — Anthropic spokesperson
- “What each partner has in common is that a successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security.” — Anthropic
- “Cheap, fast AI models with powerful cyber capabilities are around the corner.” — Anthropic
- “Cyber is a dual-use technology … it’s also very good at cyber warfare,” — Daniela Amodei, co-founder and president, Anthropic
- “We decided that we can’t put this into general availability right now because we believe it’s going to cause a lot of problems in the world if we do.” — Daniela Amodei
- “don’t have access to Mythos at the moment and that’s an issue that is very important. But… Mythos isn’t the only model out there,” — Andrew Bailey, Governor, Bank of England
What’s Next
Anthropic says it will release Mythos-class models to all customers in the coming weeks, contingent on “robust safeguards.” The company plans further expansions of Project Glasswing to additional critical-infrastructure providers, open-source maintainers and safety-testing teams. The pending IPO is expected to fund continued development, while regulators worldwide are likely to shape emerging standards for AI-enabled cybersecurity.
