Anthropic Launches AI Vulnerability Scanner with $104M Coalition — Amazon, Apple, Google, Microsoft, NVIDIA Back Project Glasswing
Anthropic launched Claude Code Security on April 11 in limited research preview, exclusively for Enterprise and Team accounts. The tool scans codebases for security vulnerabilities using AI reasoning rather than pattern matching, and surfaces suggested patches for human review.
The distinction from traditional static analysis tools is the mechanism: Claude Code Security understands code interactions, traces data flows across components, and ranks issues by severity based on the exploitability chain — not just the presence of a known pattern. It generates severity ratings that security teams can use to prioritise remediation.
Critically, all patches require human approval before deployment. Anthropic positioned the human-in-the-loop constraint as core to the product, not a limitation.
Project Glasswing: $104M Industry Coalition
The launch is part of Project Glasswing, an industry initiative Anthropic announced alongside Claude Code Security.
Coalition members:
- Amazon Web Services
- Apple
- Microsoft
- NVIDIA
- 40+ critical infrastructure organisations
Funding structure:
- $100 million in Anthropic Claude Mythos Preview usage credits for critical infrastructure maintainers
- $4 million in direct donations to open-source security projects
The $100M in compute credits is earmarked for expanding Claude Mythos Preview access to more than 40 critical infrastructure maintainers by Q3 2026. The reasoning is direct: Anthropic’s own research shows Claude Mythos Preview has already identified thousands of high-severity vulnerabilities across major operating systems and browsers. Project Glasswing is the defensive counterpart — using the same capability to find and patch vulnerabilities before adversaries can exploit them.
The Offensive-Defensive Framing
Anthropic’s announcement made an explicit acknowledgement that frontier AI models can now find vulnerabilities faster than human security researchers. The company framed Claude Code Security as a direct response: if AI will be used offensively, defenders need AI capabilities at scale.
This is a shift from Anthropic’s previous security positioning, which focused primarily on model safety and alignment. Project Glasswing extends the frame to infrastructure security and positions Claude Mythos Preview as a tool for defenders with access to critical systems.
The initiative arrives as the New York RAISE Act (effective January 2027) and the White House’s national AI legislative framework both increase compliance pressure on AI deployments touching critical infrastructure. Anthropic is getting ahead of that curve with an industry coalition rather than waiting for regulatory requirements.
Broader access beyond Enterprise and Team tiers is expected in subsequent rollout phases.