Anthropic says it will extend Project Glasswing to organizations in 15+ countries, sources say giving Mythos access to Five Eyes, NATO, Samsung, SK, and others
About 150 organisations will be given advanced cyber security model following requests from around the world
Financial Times
Context & Ripple Effects
Project Glasswing began as a tightly controlled program: Claude Mythos Preview was limited to more than 40 organizations maintaining critical software, backed by launch partners including major cloud, security, and infrastructure vendors. Anthropic also committed usage credits and direct support for open-source security groups.
Related reporting shows international demand broadened the program’s original scope, including a planned role for the EU cyber agency ENISA. The reported expansion to roughly 150 organizations across more than 15 countries would move Mythos from a narrowly selected preview toward a cross-border security deployment.
First-order effects
Anthropic would grant advanced cybersecurity-model access to a substantially larger set of government, alliance, and corporate security organizations, including Five Eyes and NATO-linked users and named companies such as Samsung and SK.
The participating organizations can incorporate Mythos into their security work under Glasswing’s controlled-access model, while Anthropic takes on a larger operational and governance footprint for the program.
Second-order effects
Security vendors and cloud partners involved at launch—such as AWS, Cisco, CrowdStrike, Google, Microsoft, and Palo Alto Networks—gain a stronger incentive to make their products and services compatible with AI-assisted defensive workflows.
The inclusion of national and multinational security bodies raises the importance of shared access rules, evaluation standards, and safeguards across jurisdictions, rather than leaving those choices solely to individual enterprise customers.
Third-order effects
If controlled programs such as Glasswing continue expanding, frontier cybersecurity models may be deployed first through vetted institutional networks—governments, critical-infrastructure operators, and major security providers—rather than broad public release.
The pattern could make access governance a competitive feature of cybersecurity AI: model developers will need to balance the defensive value of wider deployment against the risks of distributing increasingly capable cyber tools.
The trend: Frontier AI companies are increasingly treating advanced cyber capabilities as governed security infrastructure, expanding access through vetted international institutions instead of general availability.
- Cyber safeguards are a hard + urgent techno-philosophical problem. - ...but powerful models w/o safeguards may come soon (~3, 6, 18 months max?). We need to scale access to defensive tools urgently. - Industry, government, maintainers, and researchers are taking this moment
- Mythos finds a lot of vulnerabilities. Patching is the bottleneck. - Industry/maintainers are very creative at self-organizing prioritizing/finding/fixing. - Mythos will look dumb in 6-12 months.
NEW: Canada now has access to Mythos hacking tech and are officially part of Project Glasswing. “It's a very important step for Canadians and for our government to make sure we have access and we can protect our institutions and our country,” AI Minister @EvanLSolomon says
We're expanding Glasswing today. To solve such a big/complex/urgent problem, we need Mythos-level capabilities in as many defenders' hands as possible. That's why we're working on safeguards to scale that safely ASAP. 11 of my reflections from the past 2 months of Glasswing 🧵:
- Glasswing has been a rallying mission for Anthropic. Our team is incredible. - ...and we want to do whatever we can to kickstart the orgs/tools/initiatives that cyberdefenders need. Glasswing will probably seem very tiny within 6 months. Working on the latter right now!
- We've seen orgs can go from 0 -> 100 on model-powered cyberdefense in days (sometimes same day). - You don't need Mythos to get started. Claude Security & 4.8 make it really easy. - Partners use it not just for vuln remediation, but pentesting, threat intel, DNR, and more.
not a single crypto company has access to claude mythos imagine what happens when the wrong people get access and start hunting defi protocols and bridges. if you're building in crypto: get audits. multiple. now
We're expanding Project Glasswing. We've extended access to Claude Mythos Preview to approximately 150 additional organizations, based in more than fifteen countries. Read more about this expansion and our future plans for Project Glasswing: https://www.anthropic.com/...