Skip to content
You can now search across every topic, entity and event.What's new
AI: Jobs, Power & Money
27JUL

Anthropic drops ASL, expands Glasswing partners

3 min read
10:02UTC

Anthropic's 244-page Alignment Risk Update for Claude Mythos Preview abandoned the AI Safety Level capability threshold framework for autonomy-focused threat models, and added Broadcom, CrowdStrike, NVIDIA, Palo Alto Networks and Cisco to the Glasswing partner list.

EconomicDeveloping
Key takeaway

Anthropic replaced capability thresholds with autonomy-focused risk measurement, forcing Glasswing partners to rebuild their internal frameworks during live deployment.

Anthropic published a 244-page Alignment Risk Update for Claude Mythos Preview on 7 April 2026, formally abandoning its AI Safety Level (ASL) capability-threshold framework in favour of autonomy-focused threat models. The same update expanded Project Glasswing to add Broadcom, CrowdStrike, Nvidia, Palo Alto Networks and Cisco alongside the original twelve founding partners announced on 8 April . The Glasswing Programme is backed by $100 million in model usage credits, distributing restricted Mythos access to selected partner organisations under coordinated-disclosure terms.

The ASL framework classified risk by capability thresholds: a model crossed a line when it demonstrated a specified skill, and escalating mitigations followed. Its autonomy-focused replacement measures risk by sustained multi-step execution, aligning with the attack-chaining dimension AISI separately confirmed. All Glasswing partners therefore have to rewrite the internal risk frameworks they were running under ASL, mid-deployment, during live coordinated disclosure.

The update discloses that over 99% of the vulnerabilities Mythos discovered during its vulnerability research programme remain unpatched, with coordinated disclosure still in progress. For the Glasswing partners, that means the security posture of the operating systems and browsers their staff use daily is currently weaker than it was before Mythos began running, because Mythos has a list of undisclosed paths into software they all depend on. CrowdStrike and Palo Alto Networks, newly added as of 7 April, are among the security vendors most directly affected by that exposure.

The methodology shift also changes what frontier AI risk governance looks like. Capability thresholds produced discrete pass/fail tests that could be regulated; autonomy thresholds require ongoing observation of how a model behaves across time and tasks, which is closer to financial-market supervision than to product certification. The Bank of England's April directive to the FCA on agentic AI in payments, carried elsewhere in this update, proceeds from the same premise.

Deep Analysis

In plain English

Anthropic published a 244-page document about the risks of its most advanced AI, Mythos, and at the same time changed how it assesses those risks; scrapping a system based on specific measurable capabilities in favour of a broader focus on the AI's ability to act autonomously. The document also revealed that over 99% of the security vulnerabilities Mythos discovered in real software are still unfixed. Anthropic also expanded the list of companies with access to Mythos to include chip maker Broadcom and security firm CrowdStrike, among others.

Deep Analysis
Root Causes

The 99%-unpatched vulnerability figure is a structural consequence of coordinated disclosure norms that were designed for vulnerabilities in known software products, not for an AI model capable of discovering novel vulnerability classes at scale.

Standard coordinated disclosure gives vendors 90 days to patch before public release. Mythos appears to have discovered vulnerabilities faster than the vendor-patch cycle can absorb; a structural mismatch between the speed of AI-driven discovery and the speed of human-driven remediation.

The Glasswing expansion to include Broadcom, CrowdStrike, NVIDIA, Palo Alto Networks and Cisco alongside the original twelve partners concentrates privileged access to a model with confirmed unpatched vulnerability knowledge inside exactly the firms whose products contain those vulnerabilities.

This is not necessarily imprudent (coordinated disclosure requires giving the affected party the information) but it means the security perimeter for the unpatched vulnerability set is now co-extensive with the Glasswing partner list.

First Reported In

Update #6 · Three federal surveys, one 34-to-1 gap

Axios· 16 Apr 2026
Read original
Causes and effects
This Event
Anthropic drops ASL, expands Glasswing partners
A methodology shift that forces all Glasswing partners to rebuild their internal risk frameworks mid-deployment, while over 99% of Mythos-discovered vulnerabilities remain unpatched during coordinated disclosure.
Different Perspectives
European Commission
European Commission
The European Commission's draft Annex III guidelines, closed for comment on 23 July, treat algorithmic scoring in recruitment, pay and termination as high-risk regardless of whether a human signs off, echoing Spain's Audiencia Nacional ruling 101/2026 on concealed scheduling algorithms. Brussels is shifting the fight from counting AI job losses to assigning legal liability for the tools themselves.
Office for National Statistics
Office for National Statistics
The Office for National Statistics recorded UK vacancies rising to 712,000 on 21 July, the first quarterly increase this beat has tracked, with payrolled employment down 85,000 on the year against May's 210,000 fall. The bulletin names no AI cause anywhere, and that is the point: nothing in the release confirms the displacement story it gets cited to support.
Christian Klein, SAP
Christian Klein, SAP
Christian Klein told investors on 23 July that SAP's research headcount will not grow for twelve months because AI agents and their token costs are absorbing the work, not because SAP is cutting jobs. He frames it as commercial arithmetic: the cost of AI-assisted coding tokens plus the salaries specialist AI hires command, not people being replaced by machines.
Betsey Stevenson, University of Michigan
Betsey Stevenson, University of Michigan
Betsey Stevenson argued that the 187,000 jobless-claims reading describes a market that hires little and fires little, not one AI is emptying. She said the real damage hides in eligibility rules and suppressed job postings, not in the headline layoff counts employers keep denying.
Comisiones Obreras, UGT and Concentrix's A Coruña works committee
Comisiones Obreras, UGT and Concentrix's A Coruña works committee
Comisiones Obreras, UGT and Concentrix's A Coruña works committee blamed Microsoft's push toward AI self-service for the 80 redundancies unions signed off on 22 July, not unavoidable business cause. A second Coruña procedure covering 80 more jobs runs to a 31 August deadline, and the unions want the state, not the employer, setting the pace of AI-driven cuts.
Stanford's 'We Must Act Now' signatories
Stanford's 'We Must Act Now' signatories
More than 200 academics, including 16 Nobel laureates, published a 13 July letter warning of AI-driven labour disruption, citing Daron Acemoglu's NBER estimate that AI's total factor productivity gain stays under 0.66% over ten years. The letter's own cited economics sit well below Goldman Sachs Research's 1.5-percentage-point estimate published the same week.