Anthropic Extends Project Glasswing To 150 More Organizations Across 15+ Countries

Anthropic is adding about 150 new organizations across more than 15 countries to Project Glasswing, giving critical infrastructure operators access to Claude Mythos Preview for defensive cyber work.

Anthropic Extends Project Glasswing To 150 More Organizations Across 15+ Countries

Anthropic is extending Project Glasswing to approximately 150 new partner organizations across more than 15 countries, the company said on June 2, 2026, dramatically widening access to Claude Mythos Preview for defensive cybersecurity work. The expansion follows roughly two months in which the program’s first 50 partners used Mythos Preview to surface more than 10,000 high- or critical-severity software vulnerabilities.

Who Just Got Access

The new cohort spans industries that were thin in the initial group, including electric power, water utilities, healthcare, communications and hardware vendors. Many of the new partners are open-source software maintainers and nonprofits whose codebases are relied on by governments and other major institutions. Anthropic also recently admitted the European Union’s cybersecurity agency, ENISA, into Project Glasswing.

What Glasswing Members Are Actually Doing

Existing partners are using Claude Mythos Preview to scan codebases, write patches, vet software for vulnerabilities before release, run penetration tests, automate threat detection and even translate legacy code into memory-safe languages. "What each partner has in common is that a successful attack on their codebase could be catastrophic," Anthropic said in its announcement, estimating that a major attack on most partners could affect more than 100 million people.

Claude AI website displayed on a laptop as Anthropic expands Project Glasswing access

Mythos-Class Capabilities And The Race To Defend

Anthropic has been warning that "Mythos-class" cyber capabilities will appear from other AI labs within 6 to 12 months, and could be released without comparable safeguards. The company says its role is twofold: provide safe access to powerful tooling for defenders, and gradually shift focus from finding bugs to verifying, disclosing and patching them. Anthropic also recently released Claude Security, a product that uses Claude Opus 4.8 to scan codebases and suggest patches at general-access scale.

The Patch Bottleneck

The bigger industry problem now is patching velocity. Mythos-class models can surface vulnerabilities faster than open-source maintainers can triage, fix and disclose them. Anthropic said it is in talks with third parties about scaling up open-source patching and is preparing best practices for disclosing vulnerabilities to maintainers. The company also plans to expand its Cyber Verification Program so more organizations can use Mythos-class capabilities for specific defensive tasks. Anthropic this week also filed confidentially for an IPO with the SEC.

What Comes Next

Anthropic said future expansions will prioritise more essential infrastructure providers, critical open-source maintainers and safety testers across the United States and abroad. The company is still working on safeguards strong and precise enough to release Mythos-level capabilities publicly without enabling abuse — a release it has said it expects "in the coming weeks."

Reporting based on coverage from Anthropic, Cybersecurity Dive, Help Net Security and TechCrunch.

Category: Cyber Security

Tags: AI Security Cybersecurity Infrastructure Partnership

Related Articles