Anthropic is significantly expanding the number of organizations that have access to its powerful Claude Mythos Preview AI model, a move that reflects growing interest in Mythos’s vulnerability-hunting capabilities within government agencies and critical infrastructure sectors.
“Following several weeks of close collaboration with our Project Glasswing partners, the security industry, open-source software maintainers, and the U.S. government, we’re extending the partnership to approximately 150 new organizations,” Anthropic said in a statement on Tuesday.
The new organizations, which are based in more than 15 countries, include infrastructure operators in sectors that weren’t represented in Project Glasswing’s membership, such as power, water, healthcare and telecommunications. Other new members include hardware vendors and critical software maintainers, including nonprofit groups.
“What each partner has in common is that a successful attack on their codebase could be catastrophic,” Anthropic said. “For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security.”
Anthropic also recently admitted the European Union's cybersecurity agency, ENISA, into Project Glasswing.
Sea change in cybersecurity
Mythos has already been accelerating the process of finding and fixing serious software flaws. Existing Project Glasswing members use the AI model not only to write patches for vulnerabilities but also to vet software for flaws before its release. Some members use Mythos for penetration testing, threat detection and translating code into memory-safe languages, according to Anthropic.
The company said it was exploring how Mythos could help open-source maintainers more quickly triage vulnerability reports, which have skyrocketed in the AI era. It also plans to publish best practices for reporting vulnerabilities in open-source projects, which could address a significant source of tension for those developers.
Room to grow
Tuesday’s membership expansion won’t be the last for Project Glasswing. Anthropic said it will continue to add “essential infrastructure providers, maintainers of critical open-source software, and safety testers” to the group’s roster. Future members will also expand the group’s international representation; Anthropic said it intends to “expand our geographical reach much further.”
But even as more companies clamor for membership in Project Glasswing, Anthropic will never be able to manually enroll every organization that needs Mythos’s help finding and fixing vulnerabilities. To prevent hackers from using similar AI models to wreak havoc on global commerce and civil society, it said, “hundreds of thousands of organizations, researchers, and maintainers will likely need access” to Mythos and related models.
With that in mind, Anthropic — which recently filed to go public in what will be one of the most closely watched initial public offerings in decades — is planning to release Mythos to the public. (The company said last week that it “expect[s] to be able to bring Mythos-class models to all our customers in the coming weeks.”) But to do that, it said on Tuesday, it will need to add “robust safeguards” that prevent malicious actors from abusing Mythos’s powers.
“Project Glasswing has taught us a great deal about how to respond when models cross important capability thresholds,” Anthropic said in its statement. “If we’re successful, we hope to enable a permanent advantage for defenders.”