Anthropic brings Mythos 5 to enterprise security
Corporate scanners get cyber model findings while direct prompts stay locked.
In a nutshell
Anthropic has contained its most capable cyber model by turning an accidental data leak into an enterprise scanning architecture rather than an open product. Project Glasswing organized roughly 50 critical infrastructure operators to hunt software flaws before expanding toward 200 vetted entities, weathering an export-control shutdown along the way. By routing commercial code analysis through Claude Security without releasing unrestricted prompts, the company gives defenders automated vulnerability reports while attempting to prevent the technology from aiding offensive cyber operations.
Highlights
- Project Glasswing brought roughly 50 founding organizations together to test Anthropic's Mythos Preview model.
- Glasswing partners detected more than 10,000 high- or critical-severity software vulnerabilities during initial testing.
- US export-control orders prompted a global shutdown of Fable 5 and Mythos 5 on June 12 before access resumed on July 1.
- Claude Enterprise subscribers can run Mythos 5 scans inside Claude Security while direct prompting remains blocked.
- Anthropic established a 35 million dollar Defender Advantage Fund to support model-assisted defense initiatives.
From the Editor’s Diary
Powerful dual-use software can reach commercial markets safely when vendors constrain delivery to structured results rather than open interfaces. The durable challenge is whether manual verification can match automated flaw generation before defensive advantages dissolve.
Who's involved
Anthropic
San Francisco artificial intelligence firm building the Claude models, including the guarded Mythos series
goal → arm corporate defenders with advanced automated cyber tools while blocking offensive use
Project Glasswing partners
group of technology vendors, utility operators, open-source bodies and state-backed defenders with controlled access
goal → locate and fix software flaws before equivalent models reach malicious actors
Claude Enterprise customers
commercial subscribers running business services, including the Claude Security vulnerability scanner
goal → deploy automated vulnerability detection and code fixes without raw model prompting
United States government
federal regulators holding export-control and national-security oversight across AI deployments
goal → halt the uncontrolled spread of dangerous frontier cyber systems while supporting defenders
UK AI Security Institute
British state technical evaluation body testing frontier AI model safety
goal → measure whether claims about autonomous cyber attack skills stand up in laboratory tests
Microsoft
cloud and software corporation that joined Project Glasswing as a founding member
goal → embed Mythos-level vulnerability detection directly into core software engineering workflows
Open-source maintainers
independent developers maintaining free software codebases embedded across global tech infrastructure
goal → inspect, validate and remediate an expanding wave of model-generated vulnerability reports
In short
TL;DR: Anthropic has brought its Mythos 5 cyber model to corporate security teams through structured scans while keeping direct access strictly locked. The move lets defenders use cutting-edge vulnerability hunting without exposing the raw tool to potential attackers.
Q: How is Anthropic deploying its most potent cyber model without releasing a dangerous offensive tool?
- It restricted early testing to roughly 50 infrastructure partners under Project Glasswing.
Previously in this story

Anthropic locks new code scanner against hacker abuse
25 August 2026Anthropic released an automated cybersecurity tool for enterprise clients while blocking users from writing exploits.
How it unfolded
Data leak exposes Anthropic cyber model
A publishing lapse inside Anthropic revealed the existence of its guarded cyber model before the company planned to make it public. Fortune reporter Beatrice Nolan reported that technical draft records left in an open data cache described an unreleased system named Claude Mythos alongside warnings of acute cybersecurity hazards. Anthropic confirmed to the publication that early-access customers were testing the software, describing its capabilities as a step change in performance. The accidental disclosure forced the startup to explain how it planned to manage a system capable of finding and exploiting software flaws.
Glasswing builds a defensive coalition around preview
Two weeks after the cache exposure, Anthropic turned the breach into an organized, invite-only defensive initiative dubbed Project Glasswing. Instead of releasing Mythos Preview generally, the developer granted controlled access to 12 founding members alongside more than 40 other software infrastructure operators, producing roughly 50 original partners. The goal was to give critical defenders an advance window to locate and remediate bugs before offensive actors matched the technology. Independent scrutiny by the UK AI Security Institute confirmed the model completed a multi-step corporate network intrusion simulation, though testers cautioned that isolated lab trials do not mirror real-world corporate networks.
Guarded enterprise scanner opens parallel track
While Mythos Preview remained sealed inside Glasswing, Anthropic constructed a separate track for ordinary corporate customers using heavier automated guardrails. The company released Claude Opus 4.7 equipped with cyber filters designed to intercept risky security inputs, intending to use real-world filtering data to refine eventual Mythos rollouts. Founding partner Microsoft moved in parallel to fold Mythos capabilities into its internal software development and security pipelines. By late April, Anthropic opened a public beta of Claude Security for corporate accounts, letting businesses scan software codebases using Opus 4.7 while keeping Mythos locked behind closed doors.
Flaw discovery accelerates past human patching capacity
Field testing soon demonstrated that the primary constraint was human capacity to verify and resolve code flaws rather than the software's ability to discover them. Anthropic and its initial Glasswing partners uncovered more than 10,000 high- or critical-severity vulnerabilities in weeks, while ordinary Claude Security users fixed over 2,100 issues via Opus 4.7. The resulting verification and coordinated disclosure backlogs showed defensive operations needed wider organizational scale. In response, Anthropic moved to expand Project Glasswing from roughly 50 partners toward approximately 200 institutions across more than 15 countries, subject to security clearances.
Export controls halt rollout of upgraded Mythos 5
Anthropic upgraded the restricted system to Claude Mythos 5 on June 9, pairing it with Claude Fable 5, a twin engine fitted with strict public guardrails. Mythos 5 was reserved for vetted Glasswing members, but the rollout stalled three days later when US export officials intervened over foreign national access. Because the developer could not instantly separate accounts by user nationality, it deactivated both engines worldwide. Following talks, filter enhancements and official testing, authorities removed the export curbs, enabling Anthropic to restore service and re-engage vetted domestic partners while screening international participants.
Enterprise scanners connect to Mythos behind closed prompts
Anthropic resolved its distribution dilemma on August 21 by merging the gated model with its commercial enterprise scanner without granting direct access. Enterprise subscribers using the public-beta Claude Security tool can now scan software repositories with Mythos 5, but they receive only structured vulnerability reports, confidence scores and suggested patches. Unrestricted conversational prompting remains barred. Anthropic also announced a 35 million dollar Defender Advantage Fund, pledged to embed the engine into partner security software, and planned to broaden direct research access via a formal Cyber Verification Program.
Where things stand
Anthropic's high-end cyber deployment remains tightly controlled rather than publicly open. Project Glasswing has expanded from an initial circle of roughly 50 infrastructure operators toward approximately 200 vetted organizations, with direct Mythos 5 access requiring government-aligned vetting and a mandatory 30-day data-retention window for monitoring.
Commercial clients now access the engine's scanning power indirectly inside Claude Security, receiving filtered vulnerability data instead of open conversational prompts. Outstanding uncertainties include the rollout speed of the Cyber Verification Program, the final integration terms for third-party security software, and how regulators will react if future software bypasses compromise defensive controls.