Anthropic’s announcement on 2 June that it was extending Project Glasswing to roughly 150 new organisations reads, on the surface, as good news for cyber defenders. Power, water, healthcare, communications and hardware firms across more than 15 countries gain access to a model that has already helped partners surface over 10,000 high- or critical-severity flaws. Read it again with a procurement eye, though, and something else is happening. A private American company is now running an accreditation regime that decides which critical infrastructure operators get the strongest defensive tooling in the world — and ten days later, the US government demonstrated that it holds the final say over that list. For UK organisations, the strategic question has quietly shifted from whether you can buy this capability to whether you qualify for it.
What the expansion actually announced
The substance is worth reading carefully, because Anthropic’s own framing is unusually candid about what it is building.
The first cohort was about 50 partners with access to Claude Mythos Preview. The new group is roughly three times that size and deliberately different in composition: sectors that were, in Anthropic’s words, “not well represented in our initial cohort” — power, water, healthcare, communications, hardware. Many of the new members are vendors, meaning organisations whose code sits inside other people’s systems, “including governments”. Anthropic estimates that for most partners, a successful attack “could affect more than 100 million people”.
Then the operative sentence: “Each one will need to meet our security requirements before they gain access.”
That is a vetting standard, set privately, published nowhere, applied to critical national infrastructure across at least 15 jurisdictions. Anthropic also flagged a forthcoming verification programme that “would grant Mythos-class capabilities to many more organisations for specific cyberdefence tasks” — a second tier below full membership, again with entry criteria the company controls.
| Number | What it is | Why it matters |
|---|---|---|
| ~50 → ~200 | Glasswing partners before and after the June expansion | The vetted tier is growing fast, but remains a fraction of exposed organisations |
| 10,000+ | High- or critical-severity flaws found by partners so far | The capability is not theoretical; it produces findings at industrial scale |
| 15+ | Countries represented in the new cohort | This is a transnational security arrangement without a treaty behind it |
| 100 million | People a successful attack on a typical partner could affect | Membership decisions have population-scale consequences |
| 6–12 months | Anthropic’s estimate before rivals field Mythos-class models, possibly unsafeguarded | The defensive head start has a stated expiry date |
Strategic Reality: Anthropic is not only supplying a tool. It is operating the register of who counts as a trusted defender of critical infrastructure — a function that in every previous era belonged to states.
Then Washington proved who holds the pen
The expansion post was published on 2 June. On 12 June, the US government applied export controls to both Fable 5 and Mythos 5, and Anthropic disabled access to comply with a directive citing national security authorities. The reported trigger was a jailbreak found by Amazon researchers, which coaxed Fable 5 into identifying software vulnerabilities and, in one instance, producing code demonstrating how a flaw could be exploited.
Access came back in stages. Government approval on 26 June allowed Mythos 5 to be restored to a set of US organisations, with Commerce Secretary Howard Lutnick determining in a letter that “appropriate safeguards” justified access for certain “trusted partners”. Fable 5 returned globally on 1 July.
The sequence matters more than any single step in it. Ten days after Anthropic told the world it was widening a defensive coalition across fifteen countries, a single US agency decision closed it. Whatever Anthropic’s security requirements say, they sit downstream of an export-control judgement made in Washington, and the restoration was explicitly framed around trusted partners rather than around the sectoral logic the Glasswing expansion had described.
Critical Context: A partner meeting every one of Anthropic’s published and unpublished criteria still lost access in June. Vendor vetting and state authorisation are two separate gates, and the second one is not negotiable in a contract.
Where this leaves British operators
BT became the first UK company to confirm Glasswing membership on 9 June, three days before the freeze. That single data point tells you most of what you need to know about Britain’s position: represented, but barely, and through a company large enough to be visible to Anthropic’s partnerships team in the first place.
Contrast that with financial services. Harriet Rees, the Treasury’s banking AI champion, described UK lenders’ inability to access Mythos as a “wake-up call” last week. British banks are systemically important by every domestic definition — the Bank of England stress-tests them, the FCA supervises them, the Financial Policy Committee worries about them publicly. None of that counts towards eligibility for a defensive capability allocated by a Californian company under US supervision.
Meanwhile the UK is building its own answer, but slowly. The NCSC has announced Cyber Shield, a programme to build national-scale AI-powered defensive capability, and the Government Cyber Coordination Centre — a joint NCSC and DSIT venture — is exploring how frontier models can be applied safely to cyber defence across government. The NCSC’s vulnerability-discovery guidance is sensible and well-pitched. What none of it does yet is give a UK water utility or NHS trust a route to the frontier capability that Anthropic is handing to their American and, in BT’s case, British counterparts.
| Stakeholder | What Glasswing accreditation changes | So what |
|---|---|---|
| UK CNI operators (energy, water, transport) | Frontier defensive tooling allocated by vendor vetting, not sector designation | Sector regulation confers no eligibility; get on partnership radar directly |
| UK financial services | Systemic importance recognised at home, not by Anthropic or Commerce | Escalate access through Treasury and trade channels, not procurement |
| Software vendors serving UK public bodies | Vendor status is explicitly favoured in the new cohort | Being upstream of many customers is now an eligibility argument worth making |
| UK government buyers | Suppliers may be tiered by a foreign private register | Ask suppliers about their access tier; it is now a resilience question |
| NCSC and DSIT | A parallel private accreditation regime is forming alongside national policy | Cyber Shield’s value depends partly on whether it can negotiate access, not just build capability |
Hidden Cost: The organisations most likely to miss out are mid-sized operators that are systemically important in a national sense but invisible in a global one. A regional water company serving three million people is not a rounding error in UK resilience, but it may well be one in a partnerships pipeline sized around 100-million-person blast radii.
The bottleneck Anthropic admits, and the one it does not
Anthropic is straightforward about the first constraint: “the bottleneck in cybersecurity is now verifying, disclosing, and patching the large numbers of vulnerabilities that Mythos-class models can surface.” That is the right diagnosis, and we have argued the same case for UK banks facing more findings than their change windows can absorb. The company’s response — Claude Security built on public frontier models like Claude Opus 4.8, internal tooling released to trusted security teams on request, discussions about scaling open-source review — is a reasonable set of answers to that problem.
The second bottleneck goes unmentioned, because Anthropic cannot fix it. Accreditation does not scale the way software does. Anthropic can serve a million API customers without meeting any of them; it cannot vet a million organisations against unpublished security requirements. Every expansion of Glasswing requires human judgement about who is trustworthy, and that judgement is the actual scarce resource. Anthropic says hundreds of thousands of organisations will need access to advanced cyber capability. The programme has reached roughly 200 in three months.
That gap is where the 6-to-12-month warning bites. If Anthropic is right that rival Mythos-class models arrive within a year, possibly without safeguards, then attackers face no accreditation queue at all. Defenders are being onboarded one vetted cohort at a time whilst the offensive side scales at the speed of a model release.
Reality Check: Vetting is a rate limit on defence that attackers do not share. That asymmetry is the strongest argument for building national capability rather than waiting for an invitation — and it is the argument UK policymakers should be making loudly.
What to do about it this quarter
The right response depends on how exposed you are, but none of it requires waiting for policy.
If you operate critical infrastructure or supply those who do, treat access tier as a resilience attribute and write it down. Establish, in plain terms, whether you have frontier-model vulnerability discovery available, through which route, and what happens if that route closes for a fortnight. June showed that a fortnight is a realistic scenario, not a tail risk.
If you are a vendor whose code sits inside other organisations’ systems, make that case actively. Anthropic explicitly prioritised vendors and open-source maintainers in this cohort and says future expansions will target essential infrastructure providers, critical open-source maintainers and safety testers. Being upstream of many customers is now an eligibility argument, and nobody will make it on your behalf.
If you cannot realistically reach the vetted tier, build the capacity that makes the tooling useful when it arrives. The NCSC’s position is that organisations should answer questions about purpose, process and patching capacity before granting any model access to source code or production environments. That work has independent value: an organisation that can absorb a thousand findings a month is more resilient than one that cannot, regardless of which model produced them.
Implementation Note: Remediation capacity is the one part of this you fully control and the one part that pays off under every scenario — accreditation granted, denied or revoked. Measure your current throughput in patched critical findings per month before arguing about model access.
Four problems that do not appear in the announcement
First, private accreditation creates a disclosure asymmetry. Partners find flaws in shared and open-source code, then disclose to maintainers who cannot themselves run the model. Anthropic acknowledges it is working on making these reports easier to triage, which is a polite way of saying that unaccredited maintainers are receiving findings they lack the tooling to verify independently. That is a dependency, not a gift.
Second, the register itself becomes a target. A list of the organisations whose compromise would affect more than 100 million people, compiled with detail about their codebases and known weaknesses, is one of the most valuable intelligence artefacts in existence. The programme’s security posture is now a systemic concern in its own right.
Third, eligibility criteria that nobody publishes cannot be appealed. If a UK operator is refused, there is no regulator to complain to, no published standard to demonstrate compliance against, and no British institution with standing to intervene. Our earlier analysis of Britain’s exposure when frontier access becomes a political instrument covered the geopolitical version of this; the accreditation version is quieter and harder to see.
Fourth, the defensive advantage may be temporary in a way the dependency is not. Anthropic hopes Glasswing enables “a permanent advantage for defenders”. If rival models arrive without safeguards within a year, that advantage narrows — but the organisational habits, tooling choices and reporting relationships built around one vendor’s programme will not unwind at the same pace.
The takeaway
Project Glasswing is a serious piece of work and the underlying instinct — put the strongest defensive capability in the hands of the people protecting critical systems — is the correct one. But the mechanism carries a consequence Anthropic does not dwell on. Deciding who defends critical national infrastructure has become a private function, exercised by a company in San Francisco, subject to veto by the US Commerce Department, and applied to British water, power and health systems with no UK institution in the room.
UK leaders should do three things before the next expansion. Find out your organisation’s actual access position and record it as a resilience fact rather than a procurement footnote. Build remediation throughput now, because it is the only variable in this that you own outright. And press the question that neither Anthropic nor Whitehall has answered: when the next cohort is chosen, who in Britain speaks for the operators who did not make the list?
Take Action: Ask your security leadership one question this week — if frontier vulnerability-discovery capability became available to us tomorrow, how many critical findings per month could we actually verify, patch and deploy? The honest number tells you whether access is your constraint or your alibi.
Source and attribution
This analysis draws on “Expanding Project Glasswing”, published by Anthropic on 2 June 2026, available at anthropic.com. Subsequent developments — the June export-control suspension and the phased restoration of access following US government approval on 26 June — are drawn from contemporaneous reporting by CNBC, Reuters and CyberScoop.
Editorial analysis and UK business framing by Resultsense. We make sense of AI in the UK — turning research, policy and announcements into what they mean for the people building and buying these systems. For more analysis, explore our insights or get in touch.