Skip to content
Menu
Menu

Anthropic Lets More Vetted Security Teams Test the Hacking Abilities of Its Most Powerful AI Models

Anthropic is expanding Project Glasswing, its cybersecurity testing program, to smaller security firms, open-source maintainers, and individual researchers.

 

Anthropic said on Oct. 6 that it is expanding Project Glasswing, a program that lets approved organizations use its most powerful AI models to find and fix software security flaws and test their own defenses. Until now, Anthropic limited participants to about 200 organizations that build or maintain widely used software or run services such as power and water. Smaller security firms, open-source maintainers, and individual researchers can now apply.

Why Anthropic started Project Glasswing

When Mythos (then Claude Mythos Preview) launched, it found thousands of cyber vulnerabilities, including those in “every major operating system and web browser.” Some of the exposed vulnerabilities went back over 25 years. Anthropic was concerned these capabilities could fall into the hands of cyber criminals and be used to exploit vulnerabilities at scale.

Anthropic created the Glasswing project and limited the release to a small set of partners, among them Amazon Web Services, Apple, Google, JPMorganChase, and Microsoft, to find and fix flaws in their own software and in open-source software.

In June, Anthropic said it expects other AI companies to have models as capable as Mythos within six to 12 months, and that some could release them without safeguards against misuse. Anthropic describes Glasswing as a way to fix software and set rules for how these models are used before that happens.

The models Anthropic sells to the public, including Claude Opus and Claude Sonnet, block most hacking-related requests.

Glasswing partners found at least 129,000 flaws

Glasswing partners found at least 129,000 verified software flaws between April and July 2026, Anthropic said, and its own scanning of open-source software found 5,500 more between April and October. More than 33,000 of the combined total have been rated critical or high severity so far.

Anthropic said the count is likely too low, because it comes from a survey of only some partners, and that it expects the true number to be at least five times higher.

More organizations can now apply, at three levels

Anthropic merged Glasswing with its Cyber Verification Program, which lets vetted security teams test its Opus and Sonnet models with fewer cybersecurity blocks. The revised program has three levels, and all three cover Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. The higher the level, the fewer requests the models block and the more Anthropic checks about the applicant.

Defense Access covers protecting systems, such as responding to an attack or confirming that a reported flaw is real. Security teams at companies and government bodies, hospitals, utilities, people who maintain open-source software, and individual researchers with a record of reporting flaws can apply. Anthropic said it aims to answer applications within a few days.

Red Team Access lets organizations attack a system to find weak points, but only against systems they are authorized to test. Individuals cannot apply, and Anthropic said review takes a few weeks.

Specialized Access has the fewest blocks. Anthropic reserves it for a limited number of organizations authorized to test systems such as power grids, flight systems, and the systems banks use to transfer money. Anthropic said it reviews each applicant with the US government. Existing Glasswing partners move to this level.

Anthropic said it will publish more on its work securing open-source software and critical infrastructure in the coming weeks.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!