All news
AI SafetyJun 7, 2026

Anthropic widens access to its vulnerability-hunting Mythos AI across the EU and NATO

Anthropic expanded Project Glasswing — its controlled-access program around Claude Mythos, a model it says has autonomously found over 10,000 critical zero-day vulnerabilities — to roughly 150 organizations across 15+ countries, including Samsung, SK Hynix, and NATO. ENISA, the EU's cyber agency, became the first EU institution admitted, resolving a tense transatlantic standoff over access. The gating is the whole design: this is a capability being distributed through a membership list, not a product launch.

Why it matters: A model that can autonomously surface zero-days at the scale claimed is the textbook definition of dual-use — the same capability that lets a defender find and fix flaws first lets an attacker weaponize them, and the only thing separating those outcomes is who holds the keys. That's why the access list, not the technology, is the story: Anthropic is effectively acting as a gatekeeper deciding which companies and governments get a decisive advantage in the vulnerability race, a role that used to belong to nation-states and their intelligence agencies. The transatlantic standoff over ENISA's admission is a preview of a coming category of conflict — allied governments negotiating over access to privately held AI capabilities that carry strategic weight. For the security industry, the arrival of autonomous zero-day discovery at scale compresses the defender's timeline dramatically; the assumption that you have months between disclosure and exploitation may not survive tools like this. And it raises an uncomfortable governance question the controlled-access model only partly answers: what happens the first time a capability this potent leaks, is stolen, or gets replicated by a lab with looser controls?

Read the full story at TechCrunch
Share

Comments