Breaking
AI Agents

Claude Mythos Goes Public? What Anthropic Just Revealed

By Aditya Rao May 28, 2026 2:13 PM 8 min read Updated May 28, 2026
Anthropic Claude Mythos AI model moving toward public release via Claude Code and Claude Security dashboard in 2026

Direct Answer Summary: Anthropic’s Claude Mythos — an AI model described as “too dangerous to release” when it launched in restricted preview on April 7, 2026 — is now showing clear signals of a commercial rollout. The model identifier claude-mythos-1-preview briefly appeared in Claude Code’s public interface on May 23, 2026. Anthropic confirmed on May 22 it intends to make Mythos-class models generally available, but only once stronger safeguards are in place — no date has been confirmed.


Introduction

Seven weeks ago, Anthropic made an announcement that stopped the AI world in its tracks: it had built a model so capable, so dangerous, that releasing it to the public was simply not an option. The model — Claude Mythos Preview — could autonomously find and exploit zero-day software vulnerabilities, hack corporate networks end-to-end, and outperform every AI system ever tested on expert cybersecurity benchmarks.

That was April 7, 2026. Now it’s late May, and the story has changed.

A toggle labeled “Mythos 1” briefly appeared inside Claude Code’s public interface on May 23. New UI strings referencing “Access to the Claude Mythos model in Claude Code and Claude Security” were spotted in the client source code days earlier. And on May 22, Anthropic published its first major Project Glasswing results — with a carefully worded statement that it “looks forward to making Mythos-class models available through a general release” once stronger safeguards exist.

The model once deemed too dangerous to touch may be closer to your fingertips than anyone expected.


What Is Claude Mythos, and Why Was It Restricted?

Claude Mythos Preview is Anthropic’s most powerful AI model to date — a tier above even Claude Opus. It first came to public attention in late March 2026, when a misconfiguration in Anthropic’s content management system accidentally exposed nearly 3,000 unpublished internal assets, including a draft blog post calling it “by far the most powerful AI model we’ve ever developed.”

When Anthropic formally announced the model on April 7, the reason for secrecy became clear: Mythos had demonstrated an unprecedented ability to find and exploit software vulnerabilities. In controlled tests, it:

  • Identified thousands of zero-day vulnerabilities across every major operating system and web browser — including a 27-year-old flaw in OpenBSD and a 17-year-old remote code execution bug in FreeBSD.
  • Autonomously wrote working privilege escalation exploits from a list of Linux kernel CVEs, succeeding in more than half of its attempts.
  • Became the first AI model ever to complete the UK AI Security Institute’s (AISI) 32-step corporate network attack simulation — “The Last Ones” — from reconnaissance to full network takeover.
  • Succeeded on expert-level capture-the-flag security tasks 73% of the time — tasks no AI could complete before April 2025.

Rather than a public release, Anthropic launched Project Glasswing: a restricted defensive consortium of over 40 organizations — including AWS, Apple, Google, Microsoft, Nvidia, CrowdStrike, and JPMorgan Chase — tasked with using Mythos to find and patch vulnerabilities before attackers could exploit them.


What Has Project Glasswing Actually Accomplished?

So, has the restricted approach worked? Based on the May 22 update, the numbers are striking.

In roughly six weeks of operation across approximately 50 partner organizations:

  • More than 10,000 high- or critical-severity vulnerabilities were identified in widely used software.
  • A separate scan of more than 1,000 open-source projects flagged 23,019 potential vulnerabilities, with 6,202 estimated as high or critical severity.
  • Six independent security firms vetted 1,752 of the high/critical findings — 90.6% were confirmed as valid, and 62.4% were confirmed high or critical severity.
  • Mozilla found and fixed 271 vulnerabilities in Firefox 150 using Mythos Preview — more than ten times the number found in the previous version using Claude Opus 4.6.
  • As of May 22, 1,596 vulnerabilities had been disclosed across 281 open-source projects, with 97 already patched.

Anthropic has described the sheer scale of findings as creating a new problem: verification, disclosure, and patching are now the bottleneck — not discovery.


Is Claude Mythos Actually Going Public?

This is the question everyone is asking. The answer is: probably yes, but not yet — and the conditions matter.

What’s Confirmed

  • On May 22, 2026, Anthropic stated: “In the near future, once we’ve developed the far stronger safeguards we need, we look forward to making Mythos-class models available through a general release.” This marks a notable shift from earlier language suggesting Mythos would remain restricted indefinitely.
  • The model identifier claude-mythos-1-preview appeared in Claude Code’s public interface on May 23, 2026, before being removed. UI strings referencing Mythos access in Claude Code and Claude Security have also been found in client source code.
  • Claude Security — originally powered by Claude Opus 4.7 in limited preview — launched in public beta for Enterprise customers on May 22, with a new dashboard for vulnerability tracking. This is widely seen as the scaffolding for a Mythos-powered upgrade.

What’s Rumored (Not Confirmed)

  • A model named “Mythos 1” as a discrete commercial product has not been officially announced — its appearance in UI strings is a technical signal, not a product launch.
  • Rumors of Claude Opus 4.8 in internal evaluation have circulated, which some analysts suggest could be a safety-gated precursor to a broader Mythos rollout.
  • No confirmed launch window exists. Independent analysts estimate limited enterprise access no earlier than late 2026, with general availability more likely in 2027 or beyond.
StatusDetail
✅ Confirmed10,000+ critical vulnerabilities found via Glasswing
✅ ConfirmedAnthropic signals intent for general release
✅ ConfirmedClaude Security in Enterprise public beta
✅ Confirmed“Mythos 1” toggle briefly visible in Claude Code
⚠️ RumoredMythos 1 as a named product launch
⚠️ RumoredClaude Opus 4.8 in internal testing
❌ Not ConfirmedAny specific release date
❌ Not ConfirmedPublic pricing

Why Does This Matter?

So, is this a big deal? Yes — for several reasons that go beyond the AI industry.

For cybersecurity professionals: A model that can find hundreds of critical bugs in a single software product overnight changes the economics of security research entirely. The question is no longer whether AI can find vulnerabilities at scale — it’s whether humans can review, triage, and patch them fast enough.

For enterprises and developers: If Mythos lands in Claude Code, developers could gain access to an autonomous security layer that proactively flags vulnerabilities in their own codebases before shipping. That’s a meaningful shift for software teams of all sizes.

For the broader public: Critical infrastructure — banking systems, hospitals, power grids — runs on software full of decades-old bugs. Mythos has already found vulnerabilities in systems 10, 17, and 27 years old. Whether those bugs get patched before they’re exploited is now a race with real-world stakes.

For AI governance: Anthropic’s decision to condition a public release on safeguards that don’t yet exist raises serious questions. Who verifies when those safeguards are sufficient? What happens when a competitor releases a similar model with fewer restrictions?


What Happens Next?

The trajectory is becoming clearer, even if the timeline isn’t:

  1. Claude Security for Enterprise will likely receive a Mythos upgrade as the first commercial milestone — a controlled environment where misuse can be monitored.
  2. Claude Code integration appears to be the next step, giving developers a gated but practical access point.
  3. General availability remains conditional on safeguard development — a process with no public timeline.
  4. Competitive pressure is mounting: OpenAI announced a similarly limited cybersecurity-focused model one week after Mythos, and is reportedly around six months behind Anthropic in capability.

The breach incident from April 21 — in which a Discord group accessed Mythos on launch day via a third-party contractor credential — also hangs over the rollout. If Anthropic couldn’t contain access in a restricted environment, a broader release demands significantly tighter controls.


FAQ

What is Claude Mythos? Claude Mythos is Anthropic’s most powerful AI model, announced April 7, 2026. It sits above Claude Opus in capability and is specialized in autonomously discovering and exploiting software vulnerabilities. Anthropic initially restricted it from public release due to its cybersecurity risks.

Is Claude Mythos available to the public right now? No. As of May 28, 2026, Claude Mythos Preview is available only to a limited group of enterprise partners under Project Glasswing. However, Anthropic has signaled a future general release and UI signals suggest a product called Mythos 1 is in preparation for Claude Code and Claude Security.

When will Claude Mythos be publicly released? Anthropic has not confirmed a date. On May 22, 2026, the company said a general release would happen “in the near future” once stronger safeguards are developed. Independent analysts estimate enterprise access no earlier than late 2026, with general availability more likely in 2027.

What is Project Glasswing? Project Glasswing is Anthropic’s restricted defensive cybersecurity initiative launched April 7, 2026. It gives select organizations — including Apple, Google, Microsoft, and JPMorgan Chase — access to Claude Mythos Preview to find and fix vulnerabilities before malicious actors can exploit them.

How many vulnerabilities has Mythos found so far? In roughly six weeks across 50 partner organizations, Mythos identified more than 10,000 high- or critical-severity vulnerabilities. A separate scan of over 1,000 open-source projects flagged 23,019 potential vulnerabilities, with 6,202 estimated as high or critical severity.

What is Claude Security? Claude Security is an Anthropic product that scans codebases for vulnerabilities. It launched in limited preview in February 2026 powered by Claude Opus 4.7, and moved to public beta for Enterprise customers on May 22, 2026. It is expected to be upgraded to run on Mythos.

Is Claude Mythos dangerous? In the wrong hands, yes. The UK AI Security Institute confirmed it can autonomously execute sophisticated multi-step cyberattacks. However, in controlled defensive deployments, it is being used to find and patch vulnerabilities — not exploit them. Anthropic has built safeguards into Claude Opus 4.7 to block offensive use cases as a stepping stone to safer Mythos deployment.

What is the difference between Claude Mythos and Claude Opus? Claude Mythos sits above Claude Opus in Anthropic’s model hierarchy and shows dramatically stronger performance on cybersecurity tasks. In Mozilla’s testing, Mythos found more than ten times the number of Firefox vulnerabilities that Opus 4.6 found. On expert capture-the-flag tasks, Mythos succeeds 73% of the time — tasks Opus cannot reliably complete.


Final Takeaway

Claude Mythos began as a secret, became a controlled experiment, suffered a breach on its first day, and is now inching toward a commercial reality. What started as the AI model “too dangerous to release” is being carefully, deliberately commercialized — first inside enterprise security products, then, eventually, more broadly.

Whether Anthropic can build the safeguards it needs fast enough — and whether its competitors will wait — are the two questions that will define the next chapter of this story. One thing is already clear: the era of AI-powered vulnerability discovery at scale has begun, and the race between offense and defense is very much on.

What does this mean for users? If Mythos lands in Claude Code, the way software gets built and secured will change permanently. Watch this space.

Author profile image for Aditya Rao
Written by

Aditya Rao

Aditya Rao covers AI infrastructure, cloud platforms, GPUs, datacenters, and enterprise AI systems. His articles focus on practical engineering insights behind the technologies powering the next generation of artificial intelligence.