# Project Glasswing: Anthropic's $100M Defensive-Cybersecurity Initiative | Alher Tech

> Project Glasswing pairs Claude Mythos with 12 founding partners and ~40 vetted critical-infrastructure operators. Programme structure, partner obligations and RSP relationship.

- Canonical page: https://alhertech.com/en/claude-mythos/glasswing/
- Site: Alher Tech (custom software, AI agents and SEO engineering, https://alhertech.com/)
- Contact: https://alhertech.com/en/contact/

---

Project Glasswing is Anthropic's controlled-access programme for Claude Mythos. It pairs the model with 12 founding partners and ~40 vetted operators of critical infrastructure, with a single mandate: find and patch high-impact vulnerabilities before adversaries can. This page is the operator-grade reference for how the programme is structured, what partners commit to and how it interacts with Anthropic's Responsible Scaling Policy.

Updated: May 9, 2026

## Programme structure

Glasswing runs as a 12-month controlled preview anchored on three pillars: (1) Founding Partners, 12 organisations with the largest critical-infrastructure footprint, each receiving direct partnership engineering support; (2) Critical Infrastructure Operators, ~40 vetted entities running national-scale telecoms, energy, healthcare and financial systems; (3) Open-Source Maintainers, selected projects from the Linux kernel, BSD families, Postgres, OpenSSL and similar via the 'Claude for Open Source' lane. All three tiers share the same 135-day disclosure timeline.

## Confirmed launch partners

Of the 12 founding partners, four are public: Amazon, Apple, Google and Microsoft. The other eight are vetted critical-infrastructure operators that Anthropic has confirmed exist but not named: typically Tier-1 telecoms, financial market infrastructure operators, and US / EU national security partners under coordinated AISI / NCSC oversight. The ~28 expansion-cohort organisations remain confidential.

## What partners commit to

Every Glasswing contract carries five obligations: defensive-only use, 135-day disclosure window before any finding is publicised, a security-team SPOC reachable inside 4 hours, no exposure of the model to external users, and no resale of model output as a service. Anthropic retains the right to revoke access on violation. AISI publishes an aggregated annual report on programme outcomes: vulnerability counts, patch latencies and disclosure timelines without identifying individual partners.

## Relationship to the Responsible Scaling Policy

Mythos's autonomous-cyber capabilities pushed it past the threshold that triggers Anthropic's Responsible Scaling Policy (RSP) for restricted deployment. Glasswing is the operational form of that restriction: it gives Anthropic a controlled deployment surface where the capability is useful (defensive value) without being broadly accessible (offensive risk). The 244-page Mythos system card documents the threat model the RSP committee accepted before greenlighting the preview.

## What happens after the 12-month preview

Anthropic has not committed to a path beyond the 12-month preview. Three plausible outcomes: (1) extension as a permanent restricted-access programme; (2) graduated public release with hardened safety mitigations and a higher list price; (3) absorption into a successor model where capabilities are unbundled: for example, code editing without autonomous cyber. The RSP committee's decision will hinge on the outcome of the AISI annual report and the rate of replication by competing labs.

## Frequently asked questions

### Why "Glasswing"?

The glasswing butterfly is famously transparent. Anthropic chose the name to signal the programme's commitment to transparent disclosure: partner findings, audit summaries and the AISI report are all published in aggregate.

### Is Glasswing a regulatory body?

No. Glasswing is an Anthropic programme. It coordinates with AISI in the UK and the US AI Safety Institute, but it does not enforce regulation: partners are bound by contractual obligations, not law.
