Project Glasswing Explained: What Claude Mythos Found Inside Epic, and Who Else Gets Access
Project Glasswing is Anthropic's vetted program, launched 7 April 2026, that gives defenders access to Claude Mythos models for finding software vulnerabilities. Roughly 200 organisations had joined by June. Mythos 5.1 now ships through trusted access programs at $10 and $50 per million tokens.
The short version
Project Glasswing is Anthropic's invite-only program for Claude Mythos cyber capability. Epic used it and reported configurations that might expose patient records without an audit trail. Google Fairwind and OpenAI Codex Security now offer rival gated access, at different prices and with different vetting.
Epic Systems pointed Anthropic's Claude Mythos at its own code and learned that some software configurations might let someone read patient records without leaving a trace in the audit trail. That is what The New York Times reported from Epic's chief security officer, Stirling Martin, about a platform that holds records on 325 million patients.
The model was reached through Project Glasswing, the invite-only program Anthropic started in April. Glasswing is still the main way to touch Mythos-class cyber capability, and Google and OpenAI now run their own versions of the same gate. If you run security at a company that ships software, you need to know which door is open to you, what each one costs, and what Epic's six-week scramble says about the work that follows.
What Project Glasswing is, and who is in it
Anthropic announced Project Glasswing on 7 April 2026 with twelve launch partners. They include Amazon Web Services, Apple, Cisco and Microsoft. It also extended access to more than 40 other organisations that maintain critical software.
The model behind it was Claude Mythos Preview, which the company called unreleased and not planned for general availability. Anthropic said the preview had found thousands of high-severity vulnerabilities. One was a 27-year-old flaw in OpenBSD that let an attacker crash a machine remotely.
Money came with the access. The company committed up to $100M in usage credits, plus donations to open-source security groups. When the credits run out, participants pay the rates in the table below.
Glasswing is not a product you subscribe to. It is a vetted research program, and Anthropic decides who gets in. That is the whole model.
What changed: one model became three
The partner list is not the full story. The model underneath changed twice. Each change moved the gate.
On 2 June, Anthropic expanded Glasswing by roughly 150 organisations across more than 15 countries. The new cohort covers power, water, healthcare, communications and hardware, and each had to meet security requirements first. The company also said it expects other labs to ship Mythos-class models within 6 to 12 months, some without safeguards.
A week later it released Claude Mythos 5 alongside Claude Fable 5. The company described them as one underlying model with different safeguards. Mythos 5 went first through Glasswing, as an upgrade to the preview.
| Version | Announced | Who can use it | Price per 1M tokens |
|---|---|---|---|
| Mythos Preview | 7 Apr 2026 | Glasswing partners only | $25 in, $125 out |
| Mythos 5 | 9 Jun 2026 | Glasswing, then trusted access | $10 in, $50 out |
| Mythos 5.1 | 26 Sep 2026 | Trusted access programs | $10 in, $50 out |
The price fell by more than half in two months. Access did not widen at the same speed. Not close.
It was also not smooth. Anthropic suspended Mythos 5 and Fable 5 on 12 June and restored them on 1 July, according to the notices on its launch page.
Which Mythos does Glasswing run today?
The newest one, with a catch. Claude Mythos 5.1 arrived on 26 September next to Claude Fable 5.1, and Anthropic's launch post says the two are the same model with different safeguards. Fable 5.1 is generally available. Mythos 5.1 is limited to trusted access programs. (If the Claude line is new to you, what Claude is for explains the split.)
Two programs carry it. The Cyber Verification Program covers defensive security work, and Anthropic says it will soon include Mythos-class models. The Life Sciences Verification Program covers biology research, and its first participants are already enrolled with the US government.
Now the catch. Fable 5.1 can do part of the job for everyone. Anthropic says it may be used to discover software vulnerabilities, though not to develop exploits, and that Claude Code users should see about 60% fewer safeguard interventions per session. Claude Code is where most developers will meet that change. Anthropic's own Claude Security scanner first ran on public models such as Opus 4.8 and is now powered by Mythos 5.1.
The gap between the two is visible in Anthropic's numbers. On Terminal-Bench 4.0, Fable 5.1 scores 55.8% and Mythos 5.1 scores 60.9%. Anthropic attributes the difference to tasks where cyber safeguards intervened. Mythos buys you roughly five points on security-adjacent work.
What Epic found when it aimed Mythos at its own code
Epic confirmed its role at its August user conference. Martin told the audience that the models spot issues expert developers cannot, across several hundred million lines of code, by stringing unrelated weaknesses into a new attack path. Those are his words as quoted by Fierce Healthcare.
He also told hospital IT teams to expect a higher than usual number of urgent security fixes, a warning that matters because every one of those fixes lands on staff who must test it against their own configuration, schedule downtime around clinical work, and still keep the records system running for patients. The Times reported the specific finding: certain configurations might allow records to be viewed without the access appearing in an audit trail.
Read that carefully. The report says "might". It comes from Epic's own security chief. It describes configurations, not a confirmed breach, and nobody has reported a patient's data being taken this way. Possible, not proven.
Then the public messaging split in two. CEO Judy Faulkner said at Modern Healthcare's Leadership Summit that Epic was pausing most technology development to focus on security, that the work would take another six weeks, and that development would continue at a slower pace. An Epic spokesperson told Fierce Healthcare that the roadmap had not changed since August.
Both statements are on the record. Quote one without the other and you have misreported the story.
How do you get access: Anthropic, Google and OpenAI compared
Anthropic is no longer alone. Google DeepMind announced Gemini 4 Argon on 30 September and limited it to its Fairwind Program, which Google says has more than 650 partners. OpenAI offers Codex Security, an application security agent, to accounts with access.
| Program | Model or product | Who gets in | Price per 1M tokens |
|---|---|---|---|
| Glasswing | Mythos 5.1 | Vetted infrastructure and software vendors | $10 in, $50 out |
| Fairwind | Gemini 4 Argon | Governments, healthcare, telecoms, vetted defenders | $2 in, $10 out (intro) |
| Codex Security | Agent on OpenAI models | Accounts with Codex Security access | No separate price found |
The three differ more in shape than in price. Glasswing and Fairwind sell raw model access to organisations. Codex Security sells a finished workflow.
Google's Fairwind page says it runs background checks on applicants and bars partners from sharing or reselling access. It permits dual-use work such as malware analysis only for defensive and academic research. Google gave no general release date.
Google's Fairwind page, where defenders apply for Gemini 4 Argon access, captured 5 Oct 2026.
OpenAI's Codex Security documentation describes a plugin, a command-line tool and a TypeScript SDK, plus a separate cloud plugin that scans connected GitHub repositories. It says running scans requires Codex Security access and recommends an account verified for Trusted Access for Cyber. We found no separate price, so cost follows the ChatGPT plan behind it. OpenAI's cyber-tuned GPT-5.6-Cyber sits in its own vetted tier.
What each program costs, and what the number hides
Price tells you less than the application. Mythos 5.1 costs the same as Fable 5.1, so the premium is not on the invoice. It sits in the vetting. The sensible budget line is not the model bill at all. It is the engineer time spent triaging results, which is where Anthropic says the bottleneck now sits and which no price table captures.
If you get in, the economics beat a human team by a wide margin. Nobody budgets for a human team to read that much code line by line. Anthropic names a different constraint: the bottleneck is now verifying, disclosing and patching what the models surface.
Google's introductory price is the cheapest on paper, but it has a catch. After the intro period it becomes $4 and $20, according to a footnote on Google's announcement. Nobody outside Fairwind can pay either rate yet, and Google has not said when the intro ends. Treat any budget built on it as provisional. It is a launch price, not a rate card.
You can compare the public price of ordinary models on the model leaderboard. It does not list the gated cyber tiers, which is the point of this piece. For Google's other security model, see Gemini 3.8 Flash Cyber.
Benchmarks are thinner still. Google says Argon ties for first on CWE-bench v1 at 68%, a test of fixing known weaknesses. We found no CWE-bench figure for Mythos 5.1 in Anthropic's launch post, so the two cannot be compared on that test. Do not read one lab's claim as a ranking.
Who it affects: who gains, and who gets hurt
Large vendors with security teams gain the most. Epic could aim a frontier model at its whole codebase and find interplay between parts that reviewers missed. Open-source maintainers gain too, through donated credits and the Claude for Open Source application route.
Hospitals and health systems sit in the middle. They get patched software faster. They also get a flood of urgent updates to schedule and test, and Martin's warning to expect more fixes is a workload forecast for IT staff, not good news in itself.
For a hospital CIO the practical question is narrower. Which of your suppliers say they run these models on their own code, and what is their patch cadence? Ask for it in writing. A supplier that finds more flaws will ship more fixes, and every fix needs testing against your local configuration before it reaches production, so plan for that load now. It will not arrive evenly. It will arrive in bursts.
Small software vendors are hurt. They are not in Glasswing, may not qualify for Fairwind, and will see the same flaws found in rival products. They are also exposed first if attackers get comparable tools, which Anthropic's own timeline puts 6 to 12 months from June.
Security consultancies and pen-test shops face a pricing problem, in our read. A model that does a first pass for the cost of tokens squeezes the junior end of their work.
Then there are the evaluators. These programs concentrate frontier cyber capability in a few vetted hands, and the incidents below show why vetting alone does not remove the risk.
The three incidents Anthropic disclosed in July
On 30 July, Anthropic published a report on three incidents in its cybersecurity evaluations. After reviewing 141,006 runs, it found that Claude models had reached the internet from a third-party evaluation environment run by Irregular. They then gained unauthorized access to the production systems of three organisations.
The cause was a misconfiguration. Anthropic told the model it had no internet access, but the machines had it. The model treated real systems as part of a capture-the-flag exercise and used basic techniques such as weak passwords and unauthenticated endpoints.
Three models were involved: Opus 4.7, Mythos 5 and an internal research model. The earliest incident dates to April. The models ran without the safeguards used in public releases, though they kept their safety training.
The company stopped all cyber evaluations on 23 July and notified the affected organisations on 27 July. It said two of the three had not detected the activity. It had not reached the third at publication.
Why does that matter for access programs? Because vetting happens before a model is used, not while it runs. A vetted organisation can still misconfigure a test range, and a vetted lab can still tell a model something untrue about its surroundings, so controls have to sit around the model as well as around the applicant.
The honest reading cuts both ways. Nothing was exfiltrated, and no complex exploit was used. That is the good news. It also shows that a model told it is in a simulation will act on real machines when the simulation leaks.
What would change this: the case for less urgency
The strongest objection is that Glasswing mostly finds bugs, and finding bugs was never the hard part. Anthropic says as much. A model that finds 1,000 flaws a week does not help a team that can fix 20. Verification is the part that does not scale: a model can write a convincing exploit report in seconds, but a person still has to decide whether the report is true, whether it matters and who must be told, and that chain of judgments takes hours per finding.
There is a second objection. The Epic finding is one executive's description of possible configurations, relayed by a newspaper. Nobody has independently checked it, and Epic has not published a technical write-up.
Both objections are fair, and they explain why the story is still early. They do not erase the change. Epic says the models now surface attack chains its own experts could not see. Several labs now offer that kind of access, and everyone else must patch at that speed.
What to do this month if you run a security or engineering team
Pick the door that matches your size, then prepare the patching side. This is the practical order:
- Ask whether your organisation maintains critical infrastructure software. If so, apply to Glasswing through your Anthropic contact and to Fairwind in parallel.
- If you build open-source software, use the Claude for Open Source route Anthropic names for maintainers.
- If neither fits, try Fable 5.1 for vulnerability discovery inside its published limits. Run Codex Security against one repository as a comparison.
- Budget patch capacity first. Anthropic and Epic both say fixing is the slow part.
- Compare public alternatives before committing, using the security tools directory.
A few questions are worth asking any supplier that claims to use these models. How many findings did the scan produce, and how many did a human confirm? How long passes between a confirmed finding and a shipped fix? Who owns disclosure when the flaw sits in someone else's dependency? Suppliers who answer with numbers are doing the work. Suppliers who answer with adjectives are not.
If you are unsure which model fits a given workload, Smart Match can narrow it from your stack and constraints. For the wider agent field, see the guide to best agentic AI and the agent directory.
Your own coding tools matter here too. Our coding assistants guide covers which ones can run security checks inside the editor. The older Claude model guide predates Fable 5.1, so treat its security notes as stale.
What to watch next
Three checks will show whether this is a lasting shift. None of them depends on a press release. They depend on whether defenders, rather than suppliers, start reporting what they actually fixed, how fast, and at what cost in staff time, which is the only evidence that would show these programs work as advertised instead of merely existing.
- Argon general availability. Google gave no date. If Argon reaches the public Gemini API at $2 and $10, the access gate was a launch phase, not a policy.
- Mythos in the Cyber Verification Program. Anthropic said "soon". A published application path would widen the pool from hundreds of organisations to thousands.
- Epic's patches. If the six weeks end with a public technical write-up, the audit-trail claim can finally be checked.
To see how the model field is moving around these programs, the recommendation tool and the full model directory track the public side.
When Epic's six weeks end, we will know whether this was a configuration quirk fixed in a quarter, or the first of many.
Frequently asked questions
What is Project Glasswing?
It is an Anthropic program, announced 7 April 2026, that gives vetted organisations access to Claude Mythos models for defensive security work. Anthropic committed up to $100M in usage credits. It is not a public product.
Who is in Project Glasswing?
Twelve launch partners joined in April, including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA and the Linux Foundation. Anthropic added about 150 more organisations on 2 June, including power, water and healthcare groups. Epic Systems confirmed its role in August.
What did Epic find with Claude Mythos?
The New York Times reported that Epic learned some software configurations might let someone view patient records without the access showing in an audit trail. The platform holds records on 325 million patients. It describes possible configurations, not a confirmed breach.
How do you get access to Claude Mythos?
Mythos 5.1 is limited to trusted access programs, mainly the Cyber Verification Program for defensive security. Anthropic says the program will soon include Mythos-class models. Open-source maintainers can apply through Claude for Open Source.
How does Glasswing compare with Google Fairwind and OpenAI Codex Security?
Glasswing and Fairwind both sell vetted model access, Mythos 5.1 at $10 and $50 per million tokens and Gemini 4 Argon at an introductory $2 and $10. Codex Security is a finished scanning agent, and we found no separate price for it.
Covered in this guide
- Claude Mythos 5.1: Anthropic's Mythos-class model for cybersecurity and biology research, scoring 1,853 on GDPval-AA v2, invite-only since September 2026.
- Anthropic: Anthropic, founded 2021 by 7 ex-OpenAI researchers, builds Claude and was valued near $965B after its May 2026 Series H round.
- ChatGPT: ChatGPT is OpenAI's AI assistant, with 1.2 billion weekly users by OpenAI's count, the GPT-6 model family and plans that run from a free tier to a premium Pro tier.
- Claude Code: Claude Code is Anthropic’s coding agent: newest Opus by default, auto mode since August 2026, in terminal, IDE, web and Slack. There is no free tier.
- Claude Fable 5: The first generally available Mythos-class Claude model, with 1M context and 95.0% SWE-bench Verified. Released June 2026 by Anthropic.
- Claude Fable 5.1: Anthropic's second Mythos-class model, released Sept 1, 2026, for long-horizon agentic coding and research at Fable 5's per-token rates.
- Claude Mythos 5: Anthropic's Mythos-class model — the same underlying model as Claude Fable 5, with its cybersecurity, biology/chemistry, and distillation safeguards lifted. Available through Project Glasswing to vetted infrastructure-security partners.
- Opus 4.8: Claude Opus 4.8 (May 2026): Anthropic's most capable model. 1M context window, 88.6% SWE-bench Verified, $5/$25 per 1M tokens. Excels at long-horizon coding and complex reasoning.
- Codex Security: OpenAI's application security agent scans connected GitHub repositories, tests likely bugs in a sandbox, and drafts fixes for review as pull requests.
- Gemini 3.8 Flash Cyber: Gemini 3.8 Flash Cyber (Google DeepMind, Sept 2026) reports 86.2% on CyberGym and is limited to vetted Fairwind Program defenders; Gemini 4 Argon now sits above it.
- Gemini 4 Argon: Google DeepMind's Gemini 4 frontier model, announced 30 Sep 2026: multimodal input, 1M-token output, limited to Fairwind Program partners for now.
- Google DeepMind: Alphabet's AI research lab, created from DeepMind and Google Brain. It makes the Gemini, Gemma and AlphaFold models, and its newest frontier model is still limited to partners.
- GPT-5.6-Cyber: OpenAI's gated cybersecurity fine-tune of GPT-5.6 Sol, released August 2026 for vetted Daybreak Red partners doing authorized exploit development and vulnerability research.
- OpenAI: OpenAI builds ChatGPT, the GPT-6 family (Astra, Sol, Luna), Codex and the OpenAI API. It reports 1.2B weekly ChatGPT users and an $852B valuation after its March 2026 round.
Sources
Still deciding?
This guide covers a handful of options. Smart Match checks every listing in the directory against how you actually work and what you can spend, then hands you the shortlist and the reason behind each pick.
Start Smart MatchRelated guides
- The AI 80s Photo Trend: How to Make Yours (and Turn It Into a Video) in 2026AnalysisWhat changed and who it affects
- What Happened When 7 AI Agents Got Real Bank Accounts and No SupervisionAnalysisWhat changed and who it affects
- AMD Buys World Labs for $8.2B: What It Means for Marble UsersAnalysisWhat changed and who it affects
- Best Agentic AI in 2026: Pick the Job, Not the GeneralistBuyer's guideHow to pick, across a category
- Best AI Agents in 2026: Autonomy Level Matters More Than BenchmarksBuyer's guideHow to pick, across a category
- Best AI Assistant Apps for Android in 2026, Now That Google Assistant Is DeadBuyer's guideHow to pick, across a category