A few years ago, we were wondering whether artificial intelligence could write an email or generate a picture of a kitten. More recently came agents, autonomous tools, and automatic code execution. And now? Now we are looking at a situation where the world’s two largest AI companies are publicly admitting that their own models are so powerful that they are afraid to release them.
First, Anthropic
Let’s start with Anthropic. Their Claude Mythos Preview model first appeared "publicly" not thanks to a press release, but because someone left internal data accessible in an open database. Quite an embarrassment. But as soon as people saw what the model could do, the data leak fiasco quickly faded into the background.
In tests, Mythos managed to find thousands of critical security vulnerabilities in major operating systems, browsers, and key infrastructure. One specific example: in the open-source OpenBSD operating system, it uncovered a bug that had been there for 27 years. No one had noticed it. The model found it overnight.
And that is not even the most frightening part. Anthropic’s research team notes that even internal engineers without formal security training were able to assign the model a task in the evening and find working system exploits on their desks the next morning. In other words, executable code for attacking a system. The line between finding a vulnerability and weaponizing it is therefore practically disappearing.
Anthropic responded with Project Glasswing, a controlled-access program exclusively for vetted organizations. These include Amazon Web Services, Apple, Google, Microsoft, Nvidia, and approximately 40 other companies.
OpenAI: Wait, us too
Shortly after Project Glasswing was announced, OpenAI spoke up. Axios reported that they, too, are finalizing a cybersecurity product with advanced capabilities that will be made available only to selected partners. Is OpenAI merely trying to stay in the spotlight, or does it really have such a program up its sleeve? Probably both.
After all, OpenAI did not start from scratch. Back in February 2026, when it released GPT-5.3-Codex (its most capable cybersecurity tool to date), it launched the Trusted Access for Cyber program. It operates on the principle of verified access: companies and security professionals must prove who they are, what they do, and why they need access to tools that could cause considerable damage in the wrong hands.
An important clarification: the new cybersecurity product being discussed is not the upcoming flagship model code-named Spud. It is a separate security tool. OpenAI is therefore not restricting the release of its next major model, but packaging its most sensitive capabilities into a separate product with controlled access.
No one wants to be the one who gave hackers weapons
But why are both companies suddenly applying the brakes like this? "You can’t stop models from finding bugs in old code. That capability exists." That is what expert Rob T. Lee of the SANS Institute told Axios. Another expert adds that it is only a matter of weeks or months before other freely available models have similar capabilities. In other words: no one knows how to put the brilliant genie back in the bottle. So they can at least try to put it in the hands of the right people before the wrong ones find it.
Security expert Adam Meyers of CrowdStrike called Mythos’s capabilities "a wake-up call for the entire industry". And he is right. Water utilities, power plants, hospitals, banks, cloud platforms. All of them rely on software full of code written decades ago. And now there is a model that searches that code for weaknesses faster than entire teams of human specialists combined.
In the world of cybersecurity, there is a decades-old debate about responsible vulnerability disclosure: when you find a security flaw, do you give the vendor time to fix it and only then tell the public? Or do you disclose it immediately? Now the same logic is being applied to the release of AI models. Who gets access first? Under what conditions? How quickly? How can misuse be prevented?
Additional source: gizmodo.com



