Safety3 min read

Anthropic Expands AI Security Program to 150 New Partners

June 5, 2026Synthesized from 2 sources: Anthropic, TLDR AI

Anthropic has added 150 new organisations across 15 countries to its AI-powered security scanning program, Project Glasswing, extending access to power, water, healthcare, and communications providers whose systems, if breached, could affect more than 100 million people each.

Anthropic's Project Glasswing started as a controlled experiment. In April 2026, the company gave roughly 50 carefully selected organisations access to Claude Mythos Preview, a powerful AI model that had not been released to the public. The reason for the secrecy was straightforward: the model had turned out to be extraordinarily good at finding and exploiting weaknesses in software, good enough that Anthropic was worried about what would happen if the wrong people got hold of it.

The first results were striking. Within a single month, those 50 partners collectively found more than 10,000 serious security flaws across critical software systems. Cloudflare alone found 2,000 bugs, 400 of which were rated high or critical severity, with a false-positive rate that its security team judged to be better than human testers. Mozilla found 271 vulnerabilities in Firefox. The AI also uncovered a 27-year-old flaw in OpenBSD, an operating system specifically built with security in mind, using fewer than a thousand automated attempts at a total cost of under $20,000.

Anthropuc is now extending access to 150 additional organisations spanning more than 15 countries, including sectors that were barely represented in the first round: power, water, healthcare, communications, and hardware. Anthropic estimates that a major attack on most of these partners could affect more than 100 million people, with serious consequences for national and global security.

The harder problem, though, is not finding the flaws. It is fixing them. More than 99% of the vulnerabilities Mythos has found remain unpatched. The software industry's usual process for dealing with newly discovered weaknesses was designed for a world where humans found vulnerabilities slowly, one at a time. An AI that surfaces thousands in weeks breaks that process entirely. Anthropic acknowledges this directly: the bottleneck has shifted from finding problems to verifying, disclosing, and patching them fast enough.

Anthroptic has released a separate product, Claude Security, which uses its publicly available models to scan codebases and suggest fixes. It has also begun sharing the internal scanning tools developed for Glasswing with trusted security teams, and is working with the Open Source Security Foundation to help the people who maintain free, publicly available software that underpins most of the internet.

The urgency behind all of this comes from Anthropic's own timeline. The company expects that within six to twelve months, other AI developers will have models with similar capabilities, and some may release them without the safeguards Anthropic has built. That would hand attackers the same AI-powered tools that defenders are only just beginning to use. CrowdStrike's chief technology officer put it plainly: the window between a vulnerability being discovered and being exploited by an attacker has already collapsed from months to minutes.

For business operators outside the technology sector, the practical implication is this: the software your organisation relies on, the accounting platforms, the logistics systems, the communications tools, is built on layers of open-source code maintained by small teams with limited resources. Many of the flaws Mythos is now finding in that code have existed for years, sometimes decades. AI will make those flaws easier to find and exploit at scale. The organisations in Project Glasswing are getting a head start on patching them. Everyone else is waiting.

Anthroptic filed its IPO paperwork with US regulators on June 1, one day before this expansion announcement, targeting a public listing as early as October 2026. The timing is worth noting: a high-profile security program covering 200-plus organisations across 15 countries, announced alongside an IPO filing, is good for business as much as it is good for the internet. Both things can be true. The program is real, the vulnerabilities are real, and the threat from AI-powered attackers is real. Whether the patching happens fast enough is the question no one has answered yet.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable