Artificial intelligence is beginning to change how security teams discover weaknesses in software.

Traditional vulnerability research requires highly skilled professionals to inspect code, test systems and investigate unusual behaviour. This work can be slow, expensive and difficult to scale across thousands of software projects.

Anthropic’s Project Glasswing is exploring whether advanced AI models can help defenders identify serious vulnerabilities before malicious actors exploit them.

The project provides selected security organisations with access to Claude Mythos Preview, an advanced model designed to support defensive cybersecurity work.

Anthropic says its initial partners used the model to identify more than 10,000 high-severity or critical-severity software vulnerabilities. The project is now expanding to approximately 150 additional organisations across more than 15 countries.

What is Project Glasswing?

Project Glasswing is a collaborative cybersecurity initiative created by Anthropic.

The project brings together technology companies, financial organisations, security providers, infrastructure operators and open-source software organisations.

Its launch partners included organisations such as Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks.

These organisations use Claude Mythos Preview as part of their defensive security work.

The goal is to give defenders early access to powerful AI capabilities so they can find and fix vulnerabilities before similar capabilities become widely available to attackers.

Project Glasswing is focused on software that supports critical infrastructure and services used by large numbers of people.

AI cybersecurity system identifying critical software vulnerabilities

How AI finds software vulnerabilities

Software vulnerabilities are weaknesses that may allow an attacker to access data, disrupt a service or control a system.

AI can support vulnerability detection by examining large amounts of source code and identifying patterns that may indicate unsafe behaviour.

A typical AI-assisted security workflow may include:

  • Scanning source code
  • Identifying suspicious functions
  • Tracing how data moves through a program
  • Testing possible attack paths
  • Explaining the potential impact
  • Suggesting areas for human investigation

The AI system does not simply search for a known keyword.

Advanced models can analyse relationships between different parts of the code and investigate how multiple weaknesses might combine.

This can help security teams review more software than they could examine manually.

However, a possible vulnerability identified by AI must still be verified before it is treated as a confirmed security issue.

What Project Glasswing has discovered

Anthropic initially gave approximately 50 partners access to Claude Mythos Preview.

According to the company, those partners used the model to find more than 10,000 high-severity or critical-severity vulnerabilities across important software systems.

Anthropic is now extending Project Glasswing to approximately 150 additional organisations.

These organisations operate in more than 15 countries, and many provide services that support critical infrastructure.

Each participant must meet Anthropic’s security requirements before receiving access.

The reported results suggest that advanced AI may significantly increase the number of software weaknesses that defenders can discover.

They also create a new operational challenge.

Finding vulnerabilities faster does not automatically mean they can be verified, disclosed and fixed at the same speed.

AI software vulnerability detection workflow from code scanning to human verification
AI can scan code, identify suspicious patterns and support human security teams during verification and remediation.

Why AI changes cybersecurity defence

Cybersecurity teams face an enormous amount of software.

Modern organisations depend on operating systems, cloud platforms, web applications, mobile applications, open-source libraries and internal tools.

Each system may contain millions of lines of code.

Human experts cannot manually inspect every component continuously.

AI can help increase coverage by reviewing code at scale and identifying areas that require expert attention.

This may help organisations:

  • Find vulnerabilities earlier
  • Review more applications
  • Reduce repetitive analysis
  • Prioritise serious risks
  • Improve security testing
  • Support smaller security teams
  • Protect critical infrastructure

AI may also help explain complex vulnerabilities in clearer language.

This can improve communication between developers, security researchers and business leaders.

Why human verification is still essential

AI-generated security findings can be incorrect.

A model may misunderstand the code, exaggerate the impact of an issue or fail to recognise an existing protection.

These incorrect findings are known as false positives.

Security teams must reproduce the issue, confirm the attack path and evaluate the real-world risk.

Human experts must also decide how and when the vulnerability should be disclosed.

Publishing technical details too early could give attackers useful information before a fix is available.

Responsible vulnerability handling usually involves communication with the software developer, coordinated testing, patch development and a controlled disclosure process.

AI can accelerate investigation, but it should not independently publish vulnerabilities or make final security decisions.

The challenge of fixing vulnerabilities at scale

Project Glasswing demonstrates that AI may find vulnerabilities faster than organisations can repair them.

Anthropic has said that progress is increasingly limited by the speed of verification, disclosure and patching rather than discovery alone.

Software maintainers may receive more reports than their teams can process.

Each finding requires investigation.

Developers must confirm the issue, understand the affected versions, create a patch, test the update and communicate with users.

Critical systems may require careful deployment because a rushed update could cause operational problems.

The next cybersecurity bottleneck may therefore be remediation capacity.

Organisations need better processes for turning AI-generated findings into verified and completed security improvements.

How organisations can use AI security responsibly

Companies should not give powerful AI security tools unrestricted access to every system.

A responsible programme should begin with clear scope and access controls.

Organisations should define which codebases may be scanned, who can review the results and how sensitive findings will be stored.

Security teams should also establish a verification process.

Every serious finding should be reviewed by a qualified professional before it is escalated.

A responsible workflow should include:

  • Approved systems and code repositories
  • Strict user access controls
  • Human verification
  • Secure storage of findings
  • Risk-based prioritisation
  • Coordinated vulnerability disclosure
  • Patch testing
  • Remediation tracking
  • Regular audits

Organisations should measure whether AI improves outcomes.

Useful metrics may include the number of verified vulnerabilities, false-positive rate, average verification time and average remediation time.

Responsible AI cybersecurity checklist for verification disclosure and software patching
Responsible AI security requires controlled access, human validation, coordinated disclosure and measurable remediation.

What this means for the future of cybersecurity

AI capabilities will become available to both defenders and attackers.

Security teams may use advanced models to find weaknesses, review code and improve incident response.

Attackers may use similar tools to search for vulnerabilities, create malicious code or automate reconnaissance.

This creates pressure to improve software security before offensive AI tools become more widely available.

Projects such as Glasswing attempt to give defenders an early advantage.

The long-term outcome will depend on whether organisations can use AI findings responsibly and fix vulnerabilities quickly.

Software security may increasingly become a race between automated discovery and effective remediation.

What happens next?

Anthropic plans to expand Project Glasswing further.

The company says it intends to prioritise additional critical infrastructure providers, maintainers of important open-source software and safety testers.

Future phases may provide more evidence about how well AI performs across different programming languages, industries and software environments.

The most important question is not only how many vulnerabilities AI can find.

It is whether security teams can verify, disclose and repair those vulnerabilities before they are exploited.

AI can increase defensive capability, but strong cybersecurity will still require skilled professionals, responsible processes and fast remediation.

Do you think AI will give defenders a lasting advantage, or will attackers eventually benefit from the same capabilities?

Official sources

Anthropic Project Glasswing announcement

Project Glasswing initial results

Stay Updated with AI Web Reporter

Follow us for clear AI news, practical analysis, and trusted industry updates.

No hype. Just signal. 📡

🌐 aiwebreporter.com

Leave A Reply

Categories
All copyright received© 2026 Ai Web Reporter.