Anthropic Scales Claude Mythos Across Critical Infrastructure in 15+ Countries

Global critical infrastructure network protected by Claude Mythos across more than 15 countries

FOLLOW-UP: AI BECOMES INFRASTRUCTURE

Anthropic is moving Claude Mythos from a limited security preview into the codebases behind essential services worldwide.

Project Glasswing is expanding to approximately 150 new organizations across more than 15 countries, covering power, water, healthcare, communications, hardware, and software relied upon by governments and major institutions.

This is a direct follow-up to our earlier analysis, AI Is No Longer Software: The Rise of Strategic Infrastructure. That article argued that frontier AI was moving beyond productivity software and becoming infrastructure that supports the infrastructure. Anthropic’s June 2 expansion of Project Glasswing makes that transition considerably harder to dismiss.

What changed?

Anthropic launched Project Glasswing with roughly 50 initial partners using Claude Mythos Preview to scan codebases for vulnerabilities. The company now says it is extending access to approximately 150 new organizations based in more than 15 countries.

The expansion deliberately reaches sectors that were not well represented in the initial cohort: power, water, healthcare, communications, and hardware. Many participants are vendors or nonprofits that maintain software used by other companies, public agencies, and governments.

The Scale Is the Story

Anthropic estimates that, for most participating organizations, a major attack on their codebase could affect more than 100 million people. Claude Mythos is no longer being positioned merely as a powerful coding model. It is being deployed as a defensive capability around systems with global and national-security consequences.

What Claude Mythos is being used for

Mythos Preview is designed to identify vulnerabilities at a scale that conventional security teams may struggle to match. Anthropic says Project Glasswing partners have already found more than 10,000 high- or critical-severity security flaws.

  • Scanning large first-party and open-source codebases for vulnerabilities
  • Helping security teams triage and verify findings
  • Writing patches and performing pre-release security checks
  • Supporting penetration testing and automated threat detection
  • Helping rebuild legacy code in memory-safe languages

The bottleneck is moving from discovery to remediation

Finding thousands of vulnerabilities is useful only if organizations can verify, disclose, prioritize, patch, test, and deploy the fixes. Anthropic acknowledges that this downstream work is becoming the new bottleneck.

That matters because critical-infrastructure environments often include old applications, tightly controlled change windows, long vendor chains, regulatory requirements, and systems that cannot be casually restarted or replaced. An AI model may identify the flaw quickly; safely fixing it in production can remain the harder problem. That same pattern shows up across recent RavenHawkTech vulnerability coverage, including Microsoft’s June 2026 Patch Tuesday volume, Redis RCE disclosure, and the reported FFmpeg zero-day wave.

Why the 15-country expansion matters

The expanded group includes organizations across Europe and the Indo-Pacific, alongside major technology, telecommunications, public-sector, and cybersecurity institutions. This is not simply international product distribution. Access to Mythos-class capabilities is currently controlled because safeguards capable of preventing misuse are not yet robust enough for general availability.

Strategic Access Is Becoming a Real Policy Question

When frontier cyber capabilities are selectively distributed to trusted organizations and allied countries, AI access begins to resemble other strategic technologies: advanced semiconductors, satellite systems, defense platforms, and secure communications infrastructure.

The defender-advantage race

Anthropic expects Mythos-class capabilities to become available from other AI developers within six to twelve months. The company’s stated objective is to help defenders adapt before cheap, fast, and highly capable cyber models become widely available without equivalent safeguards.

That creates a race with two connected goals:

  1. Find and remediate as many serious vulnerabilities as possible before similar capabilities become easier to misuse.
  2. Build the operational standards, verification processes, disclosure systems, and safeguards required for advanced cyber models to be used safely at scale.

The RavenHawkTech read

Our earlier article argued that AI was becoming strategic infrastructure because governments, security organizations, and critical-service operators would increasingly depend on it. Project Glasswing’s expansion is the evidence arriving faster than expected.

The question is no longer whether frontier AI will be used to protect essential systems. It already is. The harder questions now involve who receives access, how results are verified, who owns the remediation burden, what happens when the model is wrong, and how organizations avoid creating a new dependency while trying to secure the old ones.

For operators building practical defenses, this also belongs beside Why AI Security Is Becoming the New Cybersecurity Arms Race and the RavenHawkTech Cybersecurity guide.

Read the broader strategic analysis: AI Is No Longer Software: The Rise of Strategic Infrastructure.

Related Anthropic Coverage

As Anthropic expands Claude Mythos into critical infrastructure, the governance debate becomes more urgent. Read the companion analysis: Anthropic Wants a Global AI Brake Pedal—But Who Gets to Press It?

Sources

More RavenHawkTech Coverage

RavenHawkTech Category

Artificial Intelligence

Artificial intelligence strategy, model deployment, local AI, enterprise AI adoption, governance, infrastructure planning, workflows, tooling, and operational guidance.

RavenHawkTech Category

Infrastructure & Systems

Enterprise infrastructure, Windows Server, Linux administration, networking, storage, monitoring, messaging, and systems engineering tutorials and operational guidance.

RavenHawkTech Category

Cybersecurity

Cybersecurity operations, defensive security, identity, access control, security architecture, threat detection, hardening, compliance, risk management, and practical security guidance.