The most powerful AI model currently in deployment is not available to the public. It is not for sale. Access requires meeting security requirements, operating critical infrastructure, and passing a vetting process run by the company that built it. This is not a temporary measure. It is a design philosophy — and it is reshaping what artificial intelligence means as an economic and political object.
What Claude Mythos Preview Actually Is
Claude Mythos Preview is Anthropic’s frontier-class model, currently distributed exclusively through Project Glasswing — a structured programme for deploying advanced AI capabilities to critical infrastructure operators. As of June 2026, Anthropic has expanded the programme to approximately 150 new organisations across more than 15 countries. Each organisation must meet security requirements before gaining access. Most provide infrastructure on which, in Anthropic’s own estimate, a successful cyberattack could affect more than 100 million people.
The initial cohort of roughly 50 partners had already used the model to identify more than 10,000 high- or critical-severity security vulnerabilities in their codebases. The expansion adds power, water, healthcare, communications, and hardware sectors — industries conspicuously absent from the first round. This is not a product launch. It is an allocation decision made by a private company about who gets to use a capability that affects national security.
The previous article in this series, “US Treasury and Fed Convene Major Banks Over AI-Driven Cybersecurity Risks Linked to Anthropic Model,” documented how financial regulators and institutions are already treating Mythos-class AI as a systemic risk variable. Project Glasswing is the supply side of that same dynamic.
The Inversion of the Capability Logic
For most of the history of the technology industry, the competitive logic was straightforward: build something powerful, release it quickly, capture market share. The more capable the product, the faster it went to market.
Claude Mythos Preview inverts that logic entirely. As Anthropic has stated publicly, the model will not receive general release until the company develops safeguards robust enough to prevent its cyber capabilities from being misused — safeguards that, by their own admission, neither Anthropic nor any other AI developer has yet built.
This means the most capable AI in the world is withheld from market not as a competitive tactic, but as a safety calculation. At the frontier, the performance race gives way to a race to build capability controls that can contain what engineers have already built. Anthropic’s own timeline estimate sharpens the stakes: within 6 to 12 months, other AI companies are expected to reach Mythos-class capability levels, and they may release those models without equivalent safeguards. The window Project Glasswing occupies is narrow, deliberate, and unprecedented.
Access as the New Competitive Advantage
The distribution model for Mythos Preview reveals a structural shift in how AI creates value. The model itself is not sold. It is not licensed. It is allocated — to organisations that meet criteria Anthropic defines, for purposes Anthropic sanctions, under conditions Anthropic monitors.
Cybersecurity Dive has reported on the expansion and its framing: this is AI being treated not as software but as security infrastructure. The language Anthropic uses in its own communications reinforces this — “critical infrastructure,” “national security,” “catastrophic attack.” These are not product marketing terms. They are the vocabulary of regulated industries and government procurement.
What this creates, structurally, is an access gap. The organisations inside Project Glasswing gain a qualitatively different defensive capability than those outside it. Their ability to identify vulnerabilities, patch codebases, and anticipate attack vectors is materially superior to any organisation working with publicly available models. That gap compounds over time: the longer the programme runs, the more sophisticated the use patterns become, and the wider the defensive capability difference grows.
Business Insider has noted the controversy around Anthropic’s capability-limiting decisions — including routing certain queries to lower-performance models as a safeguard. The critique is coherent: if a company controls both the most powerful model and the criteria for accessing it, the distinction between safety and competitive gatekeeping becomes difficult to maintain from the outside.
When Safety and Monopoly Share a Structure
The tension at the centre of Project Glasswing is not unique to AI, but AI makes it unusually acute. The argument for restricted access is genuine: a model capable of finding thousands of critical vulnerabilities in weeks could, in the wrong hands, find and exploit them instead. The safeguards argument is not pretextual.
But it produces a structure indistinguishable from monopoly. A private company holds the most capable tool in a domain that affects national security. Access decisions, terms of use, and the ability to revoke — all of it sits with one company. Governments are participants in this structure, not its authors.
Anthropic’s Project Glasswing page frames the programme explicitly around the goal of giving defenders a permanent advantage over attackers. The aspiration is public-interest oriented. The mechanism is proprietary. The combination — genuine safety rationale, structural market power — is exactly what makes this moment worth watching carefully.
The Infrastructure Nobody Elected
The deeper issue is governance. Critical infrastructure has historically been subject to public oversight — regulated utilities, licensed operators, government procurement processes. The AI layer now sitting underneath that infrastructure follows different rules. It is governed by the company that built it, through access programmes the company designed, according to criteria the company sets.
This is not a criticism unique to Anthropic. It describes the condition of advanced AI development broadly. But Claude Mythos Preview and Project Glasswing make it concrete in a way that most AI deployments do not. The model is explicitly positioned as infrastructure. The access decisions are explicitly political — who gets in, who does not, which countries, which sectors, in what sequence.
The question this raises is not whether the technology is powerful. It clearly is. The question is what kind of institution should make these decisions — and whether the answer, right now, is a private AI company operating under self-imposed constraints.
That question does not have a clean answer yet. But the fact that it is now a real question marks a significant shift from where AI governance stood even eighteen months ago.
Key Sources
- Anthropic – Expanding Project Glasswing
- Anthropic – Project Glasswing
- Anthropic – Project Glasswing: An Initial Update
- Cybersecurity Dive – Anthropic Shares Mythos with 150 More Organizations
- Business Insider – What Smart People Are Saying About Anthropic’s New AI Limits
- TechCrunch – Anthropic Debuts Preview of Powerful New AI Model Mythos
- The Daily Telegraph – Anthropic Releases ‘Fable’ AI to Public as ‘Safe’ Claude Mythos
- New York Post – Anthropic Releases ‘Safe’ Version of Model It Called Too Risky
Subscribe to EuroLuminant for independent European journalism.



