The significance of three simultaneous releases
On April 7, 2026, Anthropic released three documents regarding Claude Mythos Preview almost simultaneously.
- Claude Mythos Preview System Card (PDF) — Capabilities and safety evaluation of the new model
- Project Glasswing: Securing critical software for the AI era — A new program supporting vulnerability detection and remediation in critical software
- Assessing Claude Mythos Preview’s cybersecurity capabilities — Specialized evaluation in the cybersecurity domain
On Hacker News, all three made the front page at the same time, with the System Card alone logging 508 points. Viewed individually, they appear disconnected as "a new model announcement," "a security initiative," and "an evaluation report," but the primary signal lies in the fact that they were released concurrently on the very same day.
In this article, we connect and analyze the three documents, detailing the strategic direction Anthropic aims for with Claude Mythos Preview and the implications Japanese companies should take away.
1. Reading the positioning of "Mythos" from the System Card
Meaning of the preview release
"Mythos" breaks with traditional naming conventions (Haiku / Sonnet / Opus) and is offered as a research preview. As indicated by the word "Preview" in the System Card title, it is in an evaluation and stress-testing phase prior to General Availability (GA).
Anthropic's objective in publishing a System Card at this stage is straightforward.
| Objective | Specific benefits |
|---|---|
| Ensuring transparency | Disclosing model capabilities and limitations in advance to build public trust |
| Inviting external evaluation | Gathering feedback from researchers and the security community |
| Anticipating regulatory dialogue | Demonstrating a stance of compliance with frameworks such as the EU AI Act and US Executive Orders |
How to read the capability profile
In the System Card, what stands out compared to the previous Claude 4 family is the enhanced evaluation scores for autonomous execution of long-horizon tasks and tool use. Since 2025, Anthropic has strengthened its positioning of "Claude as the premier coding agent." Mythos Preview is positioned as an extension of this trajectory: a flagship model that takes agent capabilities up another notch.
The current landscape of the AI coding space is also discussed in detail in In-Depth Comparison: Cursor 3 vs Claude Code.
2. Project Glasswing — A program to secure critical software
What it aims to achieve
Project Glasswing is a new initiative launched by Anthropic to "secure critical software for the AI era." As symbolized by the name "Glasswing" (a butterfly with translucent wings), the initiative emphasizes transparency and delicacy, encompassing activities such as:
- Vulnerability scanning of critical OSS (kernels, cryptographic libraries, browser engines, etc.)
- Responsible disclosure of discovered vulnerabilities
- AI-assisted patch proposals to maintainers
- Providing security tools for the public sector
Why now
The backdrop is the widespread adoption of AI coding agents and the accelerating race in vulnerability discovery. Now that LLMs can uncover vulnerabilities, the contest has become whether defenders or malicious actors will find them first. With Project Glasswing, Anthropic has essentially declared its intention to "preempt risks on the side of defenders."
This is also an important development in the context of security in the era of supply chain attacks.
3. Cybersecurity evaluation — Benchmarks in a specialized domain
The third document, "Assessing Claude Mythos Preview’s cybersecurity capabilities," evaluates Mythos Preview's concrete capabilities in the cybersecurity domain.
Representative tasks evaluated
| Categories | Task example |
|---|---|
| Vulnerability discovery | Autonomous discovery of known vulnerabilities within CVE datasets |
| Exploit development | Generation of proof-of-concept (PoC) code |
| Reverse engineering | Behavioral analysis of binaries |
| Incident response | Log analysis and timeline reconstruction |
Anthropic adheres to a policy of explicitly evaluating higher-risk tasks and disclosing red team results. By demonstrating to society "what AI can and cannot do," the aim is to avoid both excessive regulation and underestimation.
4. What emerges when connecting all three documents
Structuring into strategic layers
Arranging the three documents by strategic level makes Anthropic's goal clear.
- System Card = Model capability transparency (research level)
- Project Glasswing = Commitment to critical infrastructure protection (societal level)
- Cybersecurity evaluation = Benchmarks in specialized domains (policy level)
In other words, Anthropic is transforming into a company that releases not only powerful models, but also the blueprint for how they should be integrated into society as a complete package. For AI vendors in 2026, the evaluation axis is shifting beyond raw model capability to encompass the narrative of societal deployment—a movement that aligns with OpenAI's TBPN acquisition and industrial policy proposals. For details, please also see OpenAI Enters the Intelligence Industry Phase.
Comparison with Google and OpenAI
| Vendor | Key moves in April 2026 | Core message |
|---|---|---|
| Anthropic | Mythos Preview + Project Glasswing | "AI for defense" |
| OpenAI | Codex pricing revision + TBPN acquisition + industrial policy | "AI that defines industry" |
| Gemini API Flex/Priority + Gemma 4 | "AI with choices" |
From the developments across that same week, it is evident that all three companies have entered a phase where model performance alone is no longer sufficient for differentiation.
5. What Japanese companies should prepare for starting now
1. Action plans for AI-driven vulnerability detection
AI-assisted vulnerability detection like Project Glasswing accelerates utilization by both defenders and malicious actors simultaneously. Domestic enterprises urgently need to make preparations such as:
- Re-auditing internal product CVE tracking workflows
- Introducing SCA tools for dependencies (npm / PyPI / Maven)
- Establishing responsible disclosure processes
2. Governance when adopting Claude Mythos Preview
When using Mythos Preview via the API, it is vital to map the contents of the System Card into internal governance documentation.
- Extract "capabilities," "limitations," and "safeguards" from the System Card
- Map these factors to the internal risk matrix
- Create acceptable use guidelines broken down by business function
- Design an internal review structure (human checkpoints)
3. Monitoring security evaluation benchmarks
The figures in cybersecurity evaluation reports have the potential to become future industry standard benchmarks. Internal security leads and IT departments would do well to establish a quarterly cadence for reviewing vendor System Cards.
# 参考:社内ウォッチ運用のテンプレート
# 1. 四半期レビュー対象ベンダー一覧
# 2. System Card / Model Spec の差分レポート
# 3. 業務利用リスクへの影響評価
# 4. 経営層向けサマリー作成
Conclusion
The announcement of Claude Mythos Preview is far more than a simple model release.
- System Card — Disclosing model capability transparency at a research level
- Project Glasswing — A societal commitment to step into protecting critical software
- Cybersecurity evaluation — Concretely demonstrating capabilities in specialized domains
This three-part package is a clear manifestation of Anthropic's determination to shift the debate from "what AI companies build" to "what we protect with AI." If OpenAI is going on the offensive with industrial policy, Anthropic is playing offense by securing society's foundational software—this contrast looks set to become the central axis for understanding AI vendor strategies in 2026.
Japanese enterprises must simultaneously update internal governance and security operations in tandem with technical evaluations of new models. For foundational AI security measures, please also consult the Web Security Fundamentals Guide.
References








