Project Glasswing: How Anthropic Is Using AI to Secure Critical Software

Project Glasswing AI security

Project Glasswing is Anthropic’s initiative to use its most advanced AI to find and fix critical software vulnerabilities before attackers can exploit them. Backed by roughly 100 million dollars in usage credits and partnered with around 200 organisations across more than 15 countries, it has already surfaced more than ten thousand high- and critical-severity flaws.

What Project Glasswing is

Announced by Anthropic in 2026, Project Glasswing uses an advanced internal model, Claude Mythos, to autonomously analyse large codebases, uncover security flaws, and propose fixes at scale. The premise is simple and uncomfortable: if frontier AI can find vulnerabilities faster than humans, defenders should reach that capability before attackers do.

The scale of it

Anthropic committed up to 100 million dollars in usage credits and a further 4 million dollars in donations to open-source security organisations. What began with around 50 partners using Claude Mythos Preview expanded to roughly 200 organisations across 15-plus countries. Together they have identified more than 10,000 high- or critical-severity vulnerabilities in some of the world’s most systemically important software, with organisations such as ICE, NYSE, and Rubrik running the model against their own infrastructure.

AI-assisted software security
AI-assisted software security

Why this changes the security equation

Progress in software security has long been limited by how quickly people can find new vulnerabilities. An AI model that reads and reasons over enormous codebases removes that bottleneck, exposing flaws that have been hiding in plain sight for years. That is a powerful shift for defenders, and a warning: the same capability in the wrong hands accelerates attacks just as effectively. Glasswing is, in effect, a race to find the holes first.

pic in 2026, Project Glasswing uses an advanced internal model, Claude Mythos, to autonomously analyse large codebases, uncover security flaws, and propose fixes at scale.

How it compares to other efforts

Glasswing sits alongside industry security programmes such as Microsoft’s Secure Future Initiative and Google’s CoSAI, but its approach is distinct: it puts a frontier model directly to work on vulnerability discovery across many organisations at once, rather than hardening a single company’s stack. Anthropic frames it as a starting point, arguing that no single organisation, frontier labs, software companies, security researchers, open-source maintainers, or governments, can secure critical software alone.

AI-assisted software security illustration
AI-assisted software security

What it means for businesses

For most companies, the lesson is not to wait for an invitation to a programme like this. It is that AI-assisted vulnerability discovery is becoming standard practice on both sides. Reviewing dependencies, keeping software patched, and treating security as continuous rather than periodic all matter more in a world where flaws can be found at machine speed. Teams that build software should assume their code will be analysed by AI, and design for that reality.

Key takeaways

  • Project Glasswing uses Anthropic’s Claude Mythos to find and fix critical software vulnerabilities at scale.
  • It is backed by about 100 million dollars in credits and roughly 200 partner organisations across 15-plus countries.
  • Partners have found more than 10,000 high- or critical-severity flaws.
  • AI removes the long-standing bottleneck in vulnerability discovery, for defenders and attackers alike.

Related reading

Qwegle helps businesses stay secure through cybersecurity and secure software development.

Frequently asked questions

What is Project Glasswing?

An Anthropic initiative that uses its advanced Claude Mythos model to autonomously find and help fix critical software vulnerabilities across many organisations.

How much has Anthropic committed to it?

Up to 100 million dollars in usage credits, plus 4 million dollars in donations to open-source security organisations.

How many vulnerabilities has it found?

Partners have collectively identified more than 10,000 high- and critical-severity vulnerabilities in systemically important software.

Sources: Anthropic; TechCrunch; IBM; Computing; Digital Applied (2026).

Tags
Auther
Published Date

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

Related articles

Contact us

Partner with Us for Comprehensive IT

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Your benefits:
What happens next?
1

We Schedule a call at your convenience 

2

We do a discovery and consulting meting 

3

We prepare a proposal 

Schedule a Free Consultation