The short version: Anthropic has expanded its restricted AI cybersecurity programme to 150+ organisations. The capability is not available to most small businesses directly, but the direction is clear — AI-grade security scanning is moving outward from the largest organisations.

What was announced

Anthropic expanded Project Glasswing, giving 150 additional organisations across 15 countries access to Claude Mythos — a restricted AI model built specifically for cybersecurity analysis and critical infrastructure defence. This is not a consumer product or a standard API. It is a purpose-restricted model offered under controlled access to organisations working in security-sensitive sectors.

Early participants in the programme used Claude Mythos to scan their infrastructure and identified more than 10,000 security vulnerabilities. Cloudflare was among the early partners involved in the expansion. The focus is on identifying vulnerabilities at scale, across complex infrastructure, without requiring a large dedicated security team to conduct the analysis manually.

The programme remains restricted — organisations apply for access rather than signing up freely — and it is primarily aimed at critical infrastructure operators, large networks, and enterprise-scale security challenges. However, the expansion to 150 organisations across 15 countries signals a deliberate move beyond the initial small group of research institutions that had access first.

What this means for data-holding small businesses

Most small businesses will not have direct access to Claude Mythos or Project Glasswing in the near term. But there is a relevant signal in the direction of travel: AI-grade security analysis is becoming more accessible, not less. The pattern with AI capability has been consistent — what starts as a restricted research tool reaches enterprise scale, then mid-market, then smaller operators, typically within two to three years.

For a small business that holds customer data — booking records, payment details, contact information, service history — the practical implication is not that you need to act on Project Glasswing today. It is that the bar for what "good security practice" looks like is rising, and businesses that have the basics in place now will be better positioned to adopt more capable security tools as they become available.

Under UK GDPR, businesses holding personal data have existing obligations to take appropriate technical and organisational measures to protect it. AI-assisted vulnerability scanning, when it reaches smaller operators, is likely to surface weaknesses in exactly the areas where many small businesses have the most exposure: weak or reused passwords, unpatched software, insecure CRM access, and email accounts without two-factor authentication.

Operator move for this week

If your business stores customer data — bookings, payment records, contact details — this week, check whether your website, CRM login, and email accounts use unique passwords and two-factor authentication. That is the minimum. When AI-grade scanning becomes available for smaller operators, having those basics solid means you can act on findings quickly rather than spending time on preventable issues first.