Project Glasswing
When AI reads the world's source code
On 7 April 2026, Anthropic launched an alliance with twelve of the largest technology and finance companies to point a frontier AI model at the software the world runs on. Within eight weeks it had found more than 10,000 high- and critical-severity vulnerabilities.
The finding side of security has changed permanently. The patching side has not.
Overview
Project Glasswing is a joint initiative announced by Anthropic on 7 April 2026 to apply frontier AI capabilities to securing critical software infrastructure. Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks joined as launch partners, and more than 40 further organisations were given access. The programme is backed by 100 million US dollars in model credits and 4 million dollars in direct grants to open-source security organisations.
The name refers to the glasswing butterfly, Greta oto, whose transparent wings let it hide in plain sight. It is a precise metaphor for the subject: vulnerabilities that sat undiscovered in widely used software for years, sometimes decades, in plain view of everyone.
How the programme unfolded
Twelve partners, one model, 104 million dollars
Anthropic announces Project Glasswing with twelve launch partners from technology, finance and open source. The commitment consists of 100 million US dollars in model usage credits plus 4 million dollars in grants to open-source security organisations - at the time the largest single coordinated commitment by a private company to defensive AI security.
Claude Mythos Preview goes hunting
The programme runs on Claude Mythos Preview, an unreleased frontier model whose cybersecurity safeguards are lifted for verified defenders. Anthropic's Frontier Red Team publishes the methodology: the model discovers a vulnerability, reproduces it to prove it is real, and proposes a patch. On CTI-REALM, Microsoft's security benchmark, it shows substantial gains over previous models.
More than 10,000 severe findings
Roughly eight weeks after launch, the initiative has identified more than 10,000 high- or critical-severity vulnerabilities across the world's most systemically important software. The Cloud Security Alliance publishes its analysis under a title that names the new problem exactly: AI discovery outpaces open-source patching capacity.
The number that should change your planning
Discovery is no longer the bottleneck
Months became minutes
CrowdStrike's CTO summarised the shift: the window between vulnerability discovery and exploitation has collapsed. What once took months now happens in minutes with AI.
Defenders got the same tool
The capability that finds a zero-day is the capability that patches it. Glasswing is the deliberate attempt to put it in defenders' hands first, at scale, before it arrives on the other side.
Patching is the new constraint
Ten thousand confirmed findings are only useful if someone can triage, fix and ship them. For most organisations, and for most open-source maintainers, that capacity has not grown at all.
What this means for your organisation
The honest reading is that the asymmetry has narrowed on the discovery side and widened on the response side. A frontier model can now audit a codebase that no human team would have the time to read. That helps defenders enormously, and it means an attacker with comparable access is no longer limited by how many skilled people they can hire.
What follows in practice is unglamorous and well understood: know what software you actually run, keep a usable software bill of materials, and be able to answer within hours rather than weeks whether a newly published vulnerability affects you. Organisations that already have that in place will experience the coming years as manageable. Organisations that do not will experience them as a series of surprises.
There is a genuine opportunity here as well. The same models that find vulnerabilities can review your own code, and they do it at a cost that puts serious security review within reach of mid-sized companies for the first time. Security review used to be a budget line only large enterprises could justify. That is changing.
Capability behind a verified door
The pattern generalises. Inside a company, the question is the same one at a smaller scale: which capabilities should be available to everyone, which ones require a verified need, and who decides. An AI assistant that can read every contract in the company is useful to legal and inappropriate for an intern in marketing. The answer is not to block the capability but to gate it on role and documented purpose, which is exactly what a serious AI platform has to make possible.
For regulated industries this is not optional. The documentation duties in the EU AI Act point in the same direction: know what your systems can do, know who may use them, and be able to show what happened.
Is your organisation ready for AI-speed vulnerability discovery?
We look at your AI and software landscape with you: where you are exposed, which processes need to get faster, and where AI can strengthen your defence rather than just your attack surface.
Arrange a conversationWorkshops and seminars on this subject
Build the internal understanding your team needs to work with these tools safely

Business Process Analysis and Optimization
Get a comprehensive process analysis for one of your company's most important process flows and optimize it using specific AI.

AI Consulting
Your path to efficient use of Artificial Intelligence

AI Development
From idea to implementation of your individual AI solutions

AI Use Case Workshop
See what opportunities AI reveals in your company with our AI Use Case Workshop: Analysis, strategy, and solid recommendations for sustainable business success

AI Coding Workshop
Revolutionize your development processes with AI-powered coding tools and methods

AI Prompting Workshop
Enable yourself and your team to use the latest GPT models in a targeted and effective way and automate tedious work
Your first step to AI success

Your contact
Ilirjan Bytyqi, M.Sc.Operations Manager at Ziya GmbH- Write to us
- info@ziya.de
- Call us
- +49 15209215910