In April 2026, Anthropic made a quiet announcement that sent shockwaves through the AI and cybersecurity world: a frontier AI model so powerful they were not prepared to release it to the public. Instead, they made it available exclusively to a handful of vetted organisations through a programme called Project Glasswing. Here is what it is, why it matters, and what it means for the future of AI safety.
What Is Project Glasswing?
Project Glasswing is Anthropic’s controlled-access programme for its Claude Mythos model — the most capable AI system the company has built. Rather than releasing Mythos to the general public, Anthropic restricted access to a small group of organisations working on critical infrastructure protection, software vulnerability research, and national security applications.
The name “Glasswing” is a reference to the glasswing butterfly, whose wings are almost entirely transparent — a symbol Anthropic appears to have chosen to represent the programme’s emphasis on transparency and oversight within a highly controlled environment.
Why Did Anthropic Restrict Claude Mythos?
Claude Mythos was designed with an unusual primary objective: finding software vulnerabilities. According to Anthropic, the model is exceptional at identifying security flaws in complex codebases — capabilities that are enormously valuable for defenders, but equally dangerous if misused by attackers. The company determined that the risk of releasing such a model publicly outweighed the benefits, at least in its unrestricted form.
This was an unusual move in a competitive industry where speed to market typically dominates decision-making. Anthropic’s decision drew praise from some security researchers and criticism from others who argued it created an uneven playing field — with Glasswing participants gaining significant advantages over those without access.
Project Glasswing vs Claude Fable 5: What’s the Difference?
When Anthropic launched Claude Fable 5 on 9 June 2026, many assumed Glasswing was being wound down. In reality, the two programmes run in parallel and serve different purposes:
| Feature | Claude Fable 5 | Claude Mythos 5 (via Glasswing) |
|---|---|---|
| Public access | Yes — API, Claude.ai, enterprise plans | No — invite-only, vetted organisations |
| Safety restrictions | Hard limits in cybersecurity, biology, chemistry | Fewer restrictions for approved use cases |
| Primary use case | General enterprise and developer use | Critical infrastructure, vulnerability research |
| Underlying model | Same as Mythos 5 | Same as Fable 5 |
| Data retention | 30 days (mandatory) | 30 days (mandatory) |
| Pricing | $10/M input, $50/M output | Custom enterprise agreements |
Crucially, Anthropic has confirmed that Fable 5 and Mythos 5 share the same underlying architecture. The difference is the safety guardrails applied at inference time. Fable 5 blocks responses in high-risk areas like cybersecurity exploit generation and biological weapon synthesis. Mythos 5, available through Glasswing, can operate with reduced restrictions for vetted defensive security researchers.
Who Has Access to Project Glasswing?
Anthropic has not published a full list of Glasswing participants. What is publicly known, based on reporting from outlets including CNBC and TechCrunch, is that access has been extended to organisations working in:
- Critical national infrastructure protection
- Government-adjacent cybersecurity operations
- Software vulnerability research and responsible disclosure
- Academic AI safety research
By early June 2026, Anthropic had expanded access from an initial handful of partners to hundreds of organisations across 15 countries, with a continued focus on entities managing critical infrastructure.
The Export Ban Complication
Just three days after the launch of Claude Fable 5, a US government export directive temporarily forced the model offline internationally. This affected both Fable 5’s public availability and Glasswing operations in certain regions. The incident highlighted a growing tension in AI governance: models powerful enough to be genuinely useful for national security are also powerful enough to be classified as export-controlled technology.
For businesses and organisations outside the US, particularly in regions covered by AI export restrictions, this creates real operational uncertainty. Access to frontier AI tools cannot be assumed to be permanent or unconditional.
What Does Project Glasswing Mean for Everyday Businesses?
For most businesses, Project Glasswing is background context rather than something directly actionable. You will not be applying for Glasswing access unless you are running a critical infrastructure organisation or a government-contracted security firm. But understanding Glasswing matters for two reasons:
- It signals how powerful AI has become: The fact that Anthropic felt the need to restrict access to a model tells you something important about the current capabilities of frontier AI in cybersecurity.
- It shapes the tools available to you: Claude Fable 5 exists specifically because Anthropic wanted to offer near-Mythos capability with appropriate safeguards. Understanding the lineage helps you evaluate what the model can and cannot do for your use case.
Bottom Line
Project Glasswing represents a new model of AI deployment — one where the most capable systems are not simply released to whoever can pay, but are governed by access controls, oversight requirements, and mandatory data retention. Whether this approach scales, or whether competitive pressure eventually forces a different model, remains to be seen. For now, it is Anthropic’s most concrete statement that not all AI capability should be universally available.

