In April 2026, Anthropic which develops the Claude family of large language models announced Project Glasswing, bringing major technology companies like Amazon, Google,Apple, Broadcom, Cisco, Palo Alto, Microsoft, NVDIA, Crowdstrike, JPMorgan Chase, Linux foundation, etc in one umbrella with an aim to secure worlds critical softwares. Even though thisproject was initiated in early 2026, it was kept as a secret project. Within few days’ announcement of the developed AI model “Claude Mythos Preview”, often known as Mythos, it could demonstrate identification of thousands of high-severity vulnerabilities that survived for years. Independent triage verified a 90.6% true-positive rate for these high-severity findings.The model could also generate working exploits automatically. Some of the vulnerabilities, which was not surfaced for long through traditional cyber security tools could be identified by Mythos in hours or minutes.
Anthropic restricted the access of Mythos only to the listed OEMs/Cybersecurity defenders, who were part of Project Glasswing.Project Glasswingenvisaged that the AI model be used only for defence and was the main reason to restrict the usage. It was realised by the developers that that same power which helps in finding problems can also be used for attack purposes through the vulnerabilities found. So, the restriction of access was to ensure that the model is not used for any offensive activities. Later the access, with special restrictive conditions were extended to some of the entities outside original Project Glasswing partners. Select Indian public entities, including CERT-In, and some of the critical private sector organizationscould gethighly restricted access to Mythos. Other projects/models of major players also started concentrating in the same lines andmade announcements. These include Google’s Big sleep &Codementor, OpenAI’s defensive AI initiatives, Microsoft’s Automated AI Red teaming & Code repair etc.
In second week of June 2026, the US government issued an emergency export control directive forcing Anthropic to block foreign nationals from using Mythos due to national security concerns, following reports of a potential security bypass or “jailbreak”. The ban was in force till end of June 2026.
The enormous number of vulnerabilities identified by Mythos in critical security applications, created havoc in the industry and the Governments, major industry players, global associations deliberated on the possible misuse of the model. The possibilities of the model was unpredictable, which can expose unidentified vulnerabilities in the critical infrastructures across the globe.
In the Indian context, Anthropic’sClaude Mythos AI model triggered high-level government alerts, financial sector regulatory checks, and debates over digital sovereignty since its preview launch in April 2026. Because Mythos can autonomously find and exploit deep software vulnerabilities at an extraordinary speed, the Government was concerned on the unique challenges posed by the model for India.Finance Minister convened urgent meetings with top Indian bank officials and corporations to address the severe cybersecurity threats posed by AI models capable of autonomously identifying thevulnerabilities in the systems including code vulnerabilities. Continuous meetings and deliberations were held, mainly in the banking sector coordinated by the regulator and public research firms in Banking sector such as IDRBT on counter measures to be taken by the entities. Reserve Bank of India instructed banks and regulated entities to evaluate and mitigate the severe cybersecurity risks posed by AI models like Anthropic’s Claude Mythos. Also, banks were directed to complete board-approved gap assessments and formulate time-bound action plans.
Subsequently on the concerns on digital sovereignty, India as part of the IndiaAI missioninitiated discussions with projects/entities like Sarvam.ai and BharatGen for building a sovereign localised AI security capabilities, to protect the digital assets and critical infrastructures in India.
-by Jyothish Jolisa
VP (Information Security) & CISO