AI News
AI News AgentBusinessAnthropic3 min read

Anthropic expands Project Glasswing with defensive AI

Anthropic is expanding Project Glasswing to around 150 organizations in more than 15 countries to detect and fix vulnerabilities in critical software. The company says the first participants have already found more than 10,000 high- or critical-severity flaws and warns that models capable of attacking systems could become widespread within six to twelve months.

Anthropic is expanding Project Glasswing to around 150 new organizations so they can use advanced AI to find and fix security flaws in critical software. The program had already helped identify more than 10,000 high- or critical-severity vulnerabilities in the systems of its first participants.

The new phase follows several weeks of work with companies in the sector, open-source project maintainers, and the United States government. The organizations joining the program are spread across more than 15 countries and must meet Anthropic’s security requirements before gaining access.

A network focused on essential services

The first Project Glasswing group was underrepresented in sectors such as energy and water. The expansion adds organizations from:

  • Electricity and other energy services
  • Water
  • Healthcare
  • Communications
  • Hardware
  • Open-source software used by many companies and governments

The main criterion is not the organization’s size, but the impact an attack on its code could have. Anthropic estimates that, for most new partners, a serious attack could affect more than 100 million people, with consequences for national and global security.

The first participants have used Claude Mythos Preview to review large amounts of code, share working methods, and verify results with other security teams. The goal is to extend these practices to the millions of companies and developers exposed to attacks.

The problem is no longer just finding flaws

Models with advanced cybersecurity capabilities can locate vulnerabilities much faster than traditional processes. But finding them is only the beginning. The bottleneck is now verifying each finding, notifying those responsible, and publishing a fix without introducing new errors.

That is why many Project Glasswing partners are already using Claude Mythos Preview to:

  • Draft patches
  • Review code before release
  • Simulate attacks through penetration testing
  • Automate threat detection and response
  • Modernize legacy code with languages that reduce certain memory-related risks

Anthropic is also developing Claude Security, a product based on its most advanced public models, such as Claude Opus 4.8, to analyze code and suggest fixes. It also plans to share its internal tools on request with trusted security teams.

The warning: offensive models are getting closer

Anthropic expects other companies to have models with capabilities similar to Mythos within six to twelve months. Some could reach the market with inadequate safety measures, increasing the frequency and variety of cyberattacks.

The company acknowledges that safeguards are not yet strong or precise enough to offer these capabilities to everyone without making malicious use easier. Cybersecurity has a difficult problem: the same tools can be used to protect a system or attack it.

What changes for companies and users

In the short term, access will remain limited to selected organizations, not every company or developer. Anthropic wants to expand the program to more essential infrastructure providers, major open-source projects, and teams testing the security of these models.

It is also preparing a cyber verification program to give more organizations Mythos-level capabilities, but only for specific defensive tasks. In the long term, the company wants hundreds of thousands of organizations, researchers, and maintainers to be able to use advanced tools to review, fix, and protect software.

The central idea behind Project Glasswing is that finding vulnerabilities should no longer be AI’s main advantage. Success will be measured by whether defenders can verify and repair flaws before someone exploits them.

Anthropic expands Project Glasswing with defensive AI | neversleep.ai