Anthropic has developed Claude Mythos, a controversial general-purpose frontier model that can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.
Anthropic revealed the model in early April 2026 as Mythos Preview. It forms part of the company’s broader Claude family of AI systems, which compete with models such as OpenAI’s ChatGPT and Google’s Gemini.
Given the unprecedented competition to develop successful new AI products, Anthropic has taken an exceptional measure – it has not made the model available for general use. It has instead provided controlled access through a new initiative, which will be known as ‘Project Glasswing’
In particular, this careful approach has been prompted by the capabilities of the new model, for both good and harmful applications.
In particular, this powerful model has autonomously identified thousands of high-severity vulnerabilities, including zero-day flaws in every major operating system and web browser. Examples include a 27-year-old vulnerability that allows remote crashes in OpenBSD, a free open-source, Unix-like operating system known for its proactive security. Also a 16-year-old flaw in FFmpeg, another open-source framework used to transcode and play almost any audio or video format.
Project Glasswing
Anthropic launched Project Glasswing to allow select organisations to use the model for defensive cybersecurity purposes. Partners include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, Microsoft, NVIDIA, Palo Alto Networks and the Linux Foundation. Access has also been extended to more than 40 additional organisations responsible for critical software infrastructure.
Anthropic has offered up to $100 million in usage credits and $4 million in donations to support vulnerability fixes and open-source security projects.
The company has stated that, given the pace of AI development, such capabilities could spread beyond organisations committed to safe deployment, with potential consequences for economies, public safety and national security.
Engagement with the US Government
The company is currently engaged in legal proceedings with the US Department of Defense after it was designated a supply-chain risk. However, The White House described a recent meeting between Anthropic chief executive Dario Amodei and senior officials, including Treasury Secretary Scott Bessent, as “productive and constructive”.
Discussions covered collaboration on scaling the technology safely and balancing innovation with security regarding the model’s offensive and defensive cyber capabilities.
Access for UK Financial Institutions
Anthropic plans to extend access to UK banks following initial limited release to primarily US-based businesses.
Finance ministers, central bankers and regulators have discussed the model at recent international meetings. Canadian Finance Minister François-Philippe Champagne described it as an “unknown unknown” requiring safeguards for financial-system resilience. Bank of England Governor Andrew Bailey called it a “very serious challenge”, while European Central Bank President Christine Lagarde noted the need for governance frameworks.
In expert comment, Jamie Moles, Senior Technical Manager at ExtraHop, noted “The recent warnings from finance ministers highlight the concerns of deploying AI models like Mythos and their impact on security for the global banking industry. While innovation is vital, the integration of such powerful tools into sensitive financial infrastructure demands a more cautious and transparent approach to risk management.
“Anthropic, and any company developing powerful AI models for mass deployment, must deploy these innovations responsibly to ensure its technology does not compromise the stability of systems the public relies on every day.”
“Close collaboration with financial regulators must be a priority in order to align its advancements with the stringent safety standards necessary to protect global financial security.” Moles concludes.
Cyber Capabilities Evaluation
The UK AI Safety Institute has tested Claude Mythos Preview and found significant gains in cybersecurity performance compared with earlier models. The model achieved a 73 per cent success rate on expert-level Capture-the-Flag challenges and fully solved a complex 32-step corporate network attack simulation in some attempts.
The institute noted that evaluations did not include real-world defences such as active monitoring, and the model’s effectiveness against well-defended systems is not yet clear. It described the technology as dual-use, with potential defensive benefits if used responsibly.
Image: Maksim Tkachenko