Anthropic is giving governments and big companies an AI that is unusually good at finding security holes in code, and Canada just got access. On Tuesday the company said it is expanding Project Glasswing, a program that lets approved partners turn that AI loose on their own code to find weak spots before attackers do.
The AI is Claude Mythos Preview, a frontier model Anthropic keeps behind a gate. It is strong at code, and it is agentic. That means it can run a multi-step job on its own, working through a codebase the way a human reviewer would rather than answering one question at a time. In practice a partner points it at a large codebase, lets it hunt on its own, and gets back the weak spots for a human team to triage.
What's new
It started small. In early April, Anthropic gave about 50 partners a preview of Mythos to run against their own systems. They have already turned up more than 10,000 high- or critical-severity flaws. Those are the serious ones, the bugs that let an attacker break in or take over a system, not cosmetic glitches. None of this is open to the public. The model stays in the partners' hands in a controlled setting, and now Anthropic is letting more groups in.
Canada is one of them. AI Minister Evan Solomon said the government has signed onto Project Glasswing, so Canadian systems can now use Mythos to test for vulnerabilities, according to Global News.
A major attack could hit 100 million people
Anthropic did not soften the stakes. "A successful attack on their codebase could be catastrophic," it wrote of its partners. "For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security."
That is why defenders get the tool first. The same AI that finds a flaw for a security team could help an attacker exploit it. Anthropic is betting that handing it to the people guarding critical software buys them a head start.
Claude Code Security is a separate Anthropic product. Glasswing is its own gated program, built around Mythos, for helping approved partners lock down critical software.
You cannot sign up for this. Glasswing is aimed at companies and governments running large, sensitive systems, not a tool you download. The part that touches you is simpler. Some of the software you use every day, from banking apps to government services, may soon be getting scanned by an AI hunting the same holes an attacker would.




