Anthropic, 12 partners launch Project Glasswing AI security

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic announced Project Glasswing on April 7, 2026, uniting AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks to secure critical software using a new frontier AI model.
- Claude Mythos Preview, an unreleased Anthropic model, has autonomously found thousands of high-severity zero-day vulnerabilities, including in every major operating system and web browser — flaws in some cases that had survived decades of human review and millions of automated tests.
- Among the model's discoveries: a 27-year-old OpenBSD vulnerability that let attackers remotely crash machines by connecting to them, a 16-year-old FFmpeg flaw missed by five million prior automated test runs, and a chained Linux kernel exploit that escalated ordinary user access to complete system control — all now patched.
- Anthropic is committing $100M in usage credits for Mythos Preview across Project Glasswing partners and 40+ additional organizations that maintain critical software, plus $4M in donations split between the Linux Foundation ($2.5M to Alpha-Omega and OpenSSF) and the Apache Software Foundation ($1.5M).
- After the research preview, Mythos Preview will be available to participants at $25 per million input tokens and $125 per million output tokens via the Claude API, Amazon Bedrock, Google Cloud's Vertex AI, and Microsoft Foundry.
- Anthropic stated it does not plan to make Mythos Preview generally available, and will first launch new safeguards with an upcoming Claude Opus model — which it says does not pose the same level of risk — before broader Mythos-class deployment.
Why it matters: Anthropic is betting $100M in usage credits and mobilizing 12 major partners to shrink the window before AI-driven vulnerability discovery spreads beyond actors committed to safe deployment. With the model autonomously finding flaws like a 27-year-old OpenBSD bug, the launch signals that frontier-model cyber capabilities now demand coordinated industry defensive action before these same skills proliferate.

