Skip to content
Briefings are running a touch slower this week while we rebuild the foundations.See roadmap
Iran Conflict 2026
30MAR

Anthropic withholds Mythos from public release

2 min read
08:00UTC

Anthropic's most capable model scored 83.1% on vulnerability reproduction but will not be released publicly, going instead to twelve partners through a $100 million restricted programme.

ConflictDeveloping
Key takeaway

Anthropic set the precedent for withholding a frontier model from public release over systemic risk.

Anthropic released Claude Mythos Preview exclusively to twelve partner organisations through Project Glasswing on 8 April 2026, backed by $100 million in model usage credits 1. The model autonomously identified thousands of zero-day vulnerabilities across every major operating system and browser, including a 27-year-old OpenBSD flaw that had survived five million automated tests. On the CyberGym benchmark it scored 83.1% on vulnerability reproduction, compared with 66.6% for Anthropic's previous top model.

Anthropic has explicitly stated it will not release Mythos to the public. The twelve Glasswing partners include AWS, Apple, Google, Microsoft, CrowdStrike, Palo Alto Networks, and JPMorgan. Goldman Sachs, another partner, published displacement research the same week showing AI substitutes 25,000 jobs per month , placing these institutions on both sides of the AI capability and labour displacement story.

A Tom's Hardware review challenged the marketing: the "thousands" claim rested on only 198 manual reviews, and many flagged flaws were in outdated software 2. The Bessent-Powell emergency meeting suggests federal regulators took the risk seriously regardless.

Deep Analysis

In plain English

Every major AI model so far has been made available to the public, either free or via subscription. Anthropic has broken that pattern. Claude Mythos Preview is restricted to twelve partner organisations, including tech giants and financial institutions. The model can automatically find previously unknown security flaws in software at a scale that has never been seen from an AI system. Anthropic's position is that the capability is powerful enough that releasing it widely would create unacceptable risk, the same software that makes it useful to defenders could be used by attackers. So it is being distributed under a controlled programme called Project Glasswing, with $100 million in subsidised usage credits. A technical review by Tom's Hardware found that some of the specific claims were overstated, but the underlying capability gap the model represents is real.

Deep Analysis
Root Causes

Anthropic's capability assessment rests on the CyberGym benchmark jump from 66.6% to 83.1%, a 16.5-percentage-point improvement in autonomous vulnerability reproduction. Anthropic's own research on 'observed exposure' shows computer programmers face 75% task coverage from Claude-class models; Mythos's security capabilities represent the first instance where the coverage figure has operational implications beyond individual productivity.

The restriction decision reflects Anthropic's founding premise that AI safety and capability development must remain linked. Project Glasswing's $100 million credit allocation is structured as a subsidy for defensive deployment, not a commercial launch, which is itself novel for a frontier model.

What could happen next?
  • Precedent

    The first frontier AI model explicitly withheld from public release establishes capability-gating as a legitimate deployment option for safety-constrained AI systems.

    Medium term · 0.85
  • Risk

    The twelve Glasswing partners, which include both defensive (CrowdStrike, Palo Alto) and dual-use (AWS, Google, Microsoft) organisations, may deploy Mythos capabilities in ways beyond Anthropic's stated defensive intent.

    Short term · 0.62
  • Opportunity

    Security professionals who can interpret and direct AI-identified vulnerability data at scale represent a new premium-tier role the model creates even as it automates routine scanning.

    Medium term · 0.71
First Reported In

Update #5 · The model they won't release

Anthropic· 10 Apr 2026
Read original
Different Perspectives
Gulf shipping and insurance markets
Gulf shipping and insurance markets
With Hormuz and Bab el-Mandeb both hostile at once, war-risk underwriters face their first dual-chokepoint pricing problem; the rerouting hedge that absorbed one closure is gone for Israeli-linked hulls. Any deal that reopens Hormuz without a Houthi stand-down clause delivers only partial shipping relief.
Russia and China
Russia and China
Russia and China met IAEA chief Grossi jointly in Geneva on 5 June to coordinate an advance blocking position against Washington's censure resolution, the first documented instance of proactive pre-session obstruction rather than reactive post-vote dissent. Beijing's move came four days after OFAC designated Shanghai Qianye Energy under Iran energy sanctions.
Saudi Arabia
Saudi Arabia
Saudi Arabia was left out of the emergency $4.01 billion Patriot waiver Qatar received on 2 May as its own PAC-3 stocks ran near-empty from intercepting Iranian salvoes over Aramco facilities. Riyadh is on a standard 18-month FMS queue behind a production line booked through 2030, with no equivalent priority to Qatar's Al Udeid basing role.
Houthis (Ansar Allah)
Houthis (Ansar Allah)
The Houthis declared a complete ban on Israeli Red Sea navigation on 8 June and struck Jaffa, their first attack on Israeli territory since April, seven days after the Tasnim authorisation to activate other fronts including Bab el-Mandeb. The declaration put both chokepoints under hostile authority simultaneously.
Iran
Iran
Iran agreed the 9 June mutual halt after the Mahshahr exchange and coordinated with Russia and China to block Washington's IAEA censure resolution, using the Board as a second front while the bilateral pause held on the military one. Tehran's acceptance of the Lebanon carve-out contradicts the linkage position it stated on 1 June.
Benjamin Netanyahu and the IDF
Benjamin Netanyahu and the IDF
Israel struck the Karun Petrochemical plant at Mahshahr on 8 June over Trump's explicit objection, then agreed a halt with Iran the following day scoped on Israeli terms with Lebanon carved out. Netanyahu's posture is that the IDF will not accept Iranian missile factories as off-limits regardless of US diplomatic timelines.