Anthropic lets Project Glasswing partners share Mythos findings wider

Anthropic has revised its disclosure policy for Mythos, its unreleased cybersecurity-focused AI model in Project Glasswing. Partners can now share vulnerability findings with other security teams, regulators, open-source maintainers, the media and the public, subject to responsible-disclosure rules.

Anthropic lets Project Glasswing partners share Mythos findings wider

Anthropic said on Monday that it is changing how findings from Mythos, its unreleased cybersecurity-focused AI model, can be shared inside and outside Project Glasswing. The update lets partners in the controlled-access programme pass vulnerability information to other defenders and stakeholders, rather than keeping those findings confined to the original partner organisation.

Under the revised policy, partners can share Mythos-related cyber threat information with security teams at other companies, industry bodies, regulators, government agencies, open-source maintainers, the press and the public. Anthropic said that sharing still has to follow responsible-disclosure norms, which means the information is supposed to be handled in a coordinated way rather than dumped publicly without safeguards.

⚡ New to this?

This matters because a zero-day vulnerability is a flaw that attackers can use before a patch exists. Anthropic is saying its AI model, Mythos, has been finding a lot of these flaws, and now more defenders and regulators can receive that information. Responsible disclosure means the findings are shared in a controlled way so patches can happen before details are made public.

🦞 OpenClaw angle

If you run self-hosted AI security tooling, treat this as a sign to design for controlled sharing from day one. Build export paths that let your system send findings to customers, upstream maintainers, and regulators under role-based approval and disclosure windows, instead of keeping reports trapped in one tenant.

Also separate exploit detail from remediation detail in your pipelines. Store enough evidence for patching and triage, but gate any weaponisable output behind human review so your automation can support disclosure without turning a finding into a ready-made exploit.

That is a broader posture than Anthropic’s earlier policy. Before this change, findings were held within the partner programme and reported up to Anthropic itself, rather than moving outward to the wider defender community. The company is now allowing a wider set of parties to receive the information when they may be exposed to the same vulnerabilities.

The change matters because of what Mythos has been finding in testing. According to Anthropic’s own disclosures, the model has identified thousands of zero-day vulnerabilities across major operating systems and browsers in internal tests. Anthropic has also said Mythos has been able to develop working exploits against those flaws on the first attempt in more than 83% of cases.

Project Glasswing’s partner list includes Amazon Web Services, Apple, Google, Microsoft, Nvidia, Cisco and JPMorgan, among others. Anthropic said the programme includes about 40 to 50 organisations, which makes the findings circulating inside it relevant to a large slice of the modern enterprise attack surface.

The disclosure shift also lands as Anthropic is working through a set of regulatory and government conversations around Mythos. The company is preparing to brief the Financial Stability Board on what the model has found inside financial-services infrastructure, at Bank of England Governor Andrew Bailey’s request. According to the article, ASIC, the Federal Reserve, the Bank of England, the European Central Bank, the US Treasury and several Asian regulators are part of the coordinated monitoring group.

The article says regulators on those tracks have been pressing privately for vulnerability findings not to remain locked inside a partner programme that excludes most of the financial-supervision community. The revised sharing policy appears to move Anthropic closer to that request, at least operationally.

There is also a separate government use case in play. The Defense Department’s top technology official said last week that the Pentagon has been deploying Mythos to find and patch software vulnerabilities across the US government, while also moving away from Anthropic itself. UK banks received their own Mythos briefing earlier this month, and the new sharing rules mean those briefings can now flow further downstream than before.

Anthropic’s revised policy does not remove the requirement for responsible disclosure, including patching windows and limits on weaponisable detail. It does, however, widen who can receive Mythos findings and marks the clearest operational change to Project Glasswing since the model was first announced in April.

Source: The Next Web ↗

More from Security News