Anthropic Opens Up Project Glasswing: AI Cyber Model Mythos Can Now Share Threat Findings
Anthropic has revised Project Glasswing restrictions, allowing partners using its Mythos defensive cybersecurity AI model to share threat findings, vulnerability data, and mitigation tools more broadly across the security ecosystem.

Cybersecurity analyst in a research lab reviewing AI-generated threat intelligence data from Anthropic's Mythos model
Anthropic has revised the information-sharing restrictions governing Project Glasswing, its controlled initiative for testing the Mythos AI model, allowing participating organisations to more broadly disclose cyber threat findings, defensive tools, and vulnerability intelligence with stakeholders beyond the programme's immediate partners.
Mythos, unveiled in April 2026, is a specialised version of Anthropic's Claude AI system built exclusively for defensive cybersecurity applications. The model is described as possessing advanced coding and analytical capabilities capable of identifying software vulnerabilities and generating methods to address them at a highly sophisticated level. The programme currently includes select organisations and major technology companies including Amazon, Microsoft, Nvidia, and Apple.
Under the original configuration of Project Glasswing, participating organisations had incorporated confidentiality protections into their partner agreements, primarily at the request of organisations concerned about exposing sensitive security research or drawing unwanted attention from threat actors. Anthropic has confirmed that no formal non-disclosure agreement specific to Glasswing existed, but that those embedded restrictions are now being adapted as the initiative matures.
The revised guidelines permit participating organisations to share findings, tools, code, and best practices with external security teams, regulators, government agencies, industry groups, open-source maintainers, media organisations, and the wider public, provided disclosures adhere to responsible cybersecurity reporting practices. Anthropic described the intent as achieving maximum defensive impact through faster coordination across the broader security ecosystem.
The announcement carries significant implications for enterprise security teams across the GCC and MENA region. As organisations in the Gulf increasingly adopt AI-integrated security operations, the availability of shared vulnerability intelligence and AI-generated defensive tools from a programme of this scale could directly benefit regional security operations centres, threat intelligence programmes, and government cyber agencies. Recent research has already flagged that AI is accelerating the speed and scale of credential and system attacks targeting Middle East organisations, making access to defensive AI tools more urgent.
The deployment of Mythos has already extended into federal government infrastructure, with a senior US Department of Defense official confirming last week that the Pentagon is actively using the model to identify and patch software vulnerabilities across federal systems. The official noted this deployment is occurring during a broader transition away from certain Anthropic systems within parts of the US government infrastructure, suggesting a rapidly evolving operational picture for AI-assisted cyber defence.
Experts have raised the dual-use question openly: Mythos is capable enough to identify exploitable vulnerabilities, not just patch them. Anthropic has positioned the tool strictly for defensive use, and the expanded sharing guidelines include the expectation that partners follow responsible disclosure practices. Whether those guardrails hold at scale, as findings circulate beyond the original partner circle, remains an active area of scrutiny. For GCC organisations, AI sovereignty and the question of who holds operational control over AI systems has become the defining governance concern, making Anthropic's approach to controlled access a model worth watching closely.
For security leaders and CISOs evaluating their own AI cybersecurity tooling strategies, Project Glasswing represents an early reference point for how AI models specifically trained on security tasks are beginning to move from closed research environments into AI-native unified security operations and open intelligence sharing. The intersection of AI capability and cybersecurity governance will continue to define how this technology is adopted responsibly across both public and private sector environments.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.