Anthropic opens cyber AI to 150 critical infrastructure operators
October 7, 2026

Project Glasswing is expanding to about 150 new organizations. The real bottleneck is no longer finding flaws, but verifying, disclosing, and patching thousands of them.
What this is about
Anthropic is expanding Project Glasswing to about 150 organizations in more than 15 countries. They include operators and suppliers in power, water, healthcare, communications, and hardware. After security vetting, they receive access to Claude Mythos Preview, a model designed to search large codebases for vulnerabilities.
The first cohort of roughly 50 partners had already reported more than 10,000 high- or critical-severity flaws, according to Anthropic. This next phase is therefore not a routine product launch: it tests whether organizations can practically handle a flood of machine-found vulnerabilities.
What Project Glasswing actually does
Partners use Mythos Preview to inspect source code, describe possible attack paths, and in some cases suggest patches. Anthropic also provides vetted security teams with tools that support search and assessment. Access is not generally available because the same capabilities could help attackers.
The expansion focuses on organizations whose software supports many other systems. Anthropic estimates that a major attack on most selected partners could affect more than 100 million people each. That is a company estimate, not an independently verified forecast.
Why it matters
Security work has often been constrained by scarce review teams and slow manual analysis. A model can accelerate discovery, but every report still has to be verified, prioritized, responsibly disclosed, and fixed. Anthropic now identifies those steps as the new bottleneck.
That shifts the distribution of risk. If models produce tens of thousands of plausible findings, defensive capacity grows, but unverified reports can overwhelm maintainers and published details can guide attackers. Reuters reported the broader access on October 6, 2026, while several security outlets covered the scale and reduced restrictions for vetted teams.
In plain language
Imagine a home inspection where a scanner marks a thousand suspicious spots in minutes. The scanner saves search time, but a professional still has to determine whether each stain is really a leaking pipe, which wall to open first, and how to repair it. The model does not remove that work.
A practical example
A power-grid operator scans 20 million lines of code. The model flags 2,000 locations and rates 120 as potentially critical. An internal team confirms 18 real flaws, rejects 82 false alarms, and sends 20 for more testing. Fixing five confirmed issues within a week would be useful. Sending all 120 unverified alerts to developers could instead bury the important warnings in noise.
Scope and limits
- The figures mainly come from Anthropic and participating partners; no complete independent audit of the findings is available.
- A model finding is not automatically an exploitable vulnerability. False positives and incomplete attack chains remain possible.
- Controlled access does not solve the dual-use problem. Anthropic says robust safeguards for general availability do not yet exist.
SEO & GEO keywords
Anthropic, Project Glasswing, Claude Mythos Preview, AI security, vulnerability discovery, critical infrastructure, cyber defense, responsible disclosure, software security, patch management
π‘ In plain English
Anthropic is giving about 150 vetted organizations access to a powerful vulnerability-finding model. The potential benefit is large, but people still have to verify, prioritize, and safely fix its findings.
Key Takeaways
- βAbout 150 new organizations in more than 15 countries are set to receive access.
- βThe first cohort found more than 10,000 high- or critical-severity flaws, according to Anthropic.
- βVerification, disclosure, and patching are becoming the bottleneck.
- βAccess remains controlled because the capabilities could be used offensively.
- βNo complete independent audit of the published figures is available.
FAQ
What is Project Glasswing?
It is Anthropic's program in which vetted partners use an advanced cyber model to find software vulnerabilities.
Who gets access?
The expansion covers about 150 vetted organizations in more than 15 countries, including critical-infrastructure operators.
Is every model finding a real flaw?
No. Experts must verify, prioritize, and safely fix each finding.