← Back to News
ANALYSIS

OT Vendors Press Anthropic for Glasswing Access as Critical Infrastructure Falls Behind

Operational technology vendors and the federal officials who oversee them are pushing Anthropic to expand Project Glasswing beyond cloud and finance. The pressure is real. The math on whether and how OT gets included in 2026 is more complicated than the trade-press summaries suggest.

By Michael Eakins min read
Project GlasswingClaude MythosAnthropicOperational TechnologyCritical InfrastructureCybersecurity

Executive Summary

Anthropic launched Project Glasswing in early April with a partner roster heavy on cloud, security, and finance and conspicuously empty of operational technology vendors. Three weeks later, OT industry representatives have made their displeasure public on background, federal officials at CISA and the Department of Energy's CESER program are quietly asking the same questions, and Anthropic has acknowledged the issue without committing to a timeline. This analysis pulls together what is actually being asked for, what Anthropic has signaled, and what the realistic paths to OT inclusion look like in the back half of 2026.

The News

The Glasswing partner list as published on Anthropic's research site is nine organizations: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, Microsoft, and Nvidia. Each has been granted access to Claude Mythos Preview — Anthropic's most capable model to date and the first frontier model to demonstrate autonomous discovery and exploitation of long-dormant zero-day vulnerabilities at meaningful scale. Mythos has reportedly identified thousands of zero-day vulnerabilities across the partner codebases, including a 17-year-old NFS bug in FreeBSD and a 27-year-old flaw in OpenBSD.

What is missing is the entire universe of operational technology: industrial automation vendors (Siemens, Schneider Electric, Honeywell, Rockwell, ABB, Emerson, Yokogawa), utilities, transportation operators, water authorities, healthcare device manufacturers, building automation, and small-to-medium ICS integrators. None of the Department of Energy's national labs — Idaho, Sandia, Pacific Northwest — that have historically led OT cybersecurity research are partners. None of the federally chartered ISACs (E-ISAC, WaterISAC, ONG-ISAC) have a formal Glasswing relationship.

Nextgov's reporting in early May, citing OT industry sources, captured the substance of the pushback in a single quote attributed to a senior automation-vendor figure: "the cloud guys getting an early look at the bug list while we wait for it to leak to the actors who don't ask permission." That is the operational complaint. The political complaint, voiced more carefully by federal officials, is that the country's most capable defensive cybersecurity tool is being made available to private commercial entities on a partner-selection logic that has no public accountability.

Deep Dive

Why the Asymmetry Exists

Four forces produced the Glasswing partner roster as it stands.

Commercial alignment. Glasswing partners are, with the partial exception of JPMorgan, top-decile Anthropic API customers. OT vendors are not. The partnership team at any frontier lab follows revenue and engineering relationships that already exist; it does not, by default, build new ones for sectors with no existing footprint.

Liability geometry. A Mythos finding that destabilizes AWS Lambda is a contained engineering incident. A Mythos finding that destabilizes a Siemens PLC is potentially a city-scale physical event. The risk-committee math at Anthropic is not symmetric between the two cases, even when the vendor consents.

Engineering reachability. Cloud partners can hand over source code, build environments, and target binaries within an afternoon. OT vendors typically cannot — their estates include acquired-company codebases, restricted RTOS licenses, hardware-dependent toolchains, and firmware whose original authors are no longer reachable. The on-ramp cost is real and falls on Anthropic's finite engineering capacity.

Information-handling maturity. A weaponizable zero-day in a widely deployed PLC is an extremely dangerous artifact even when shared in confidence. Anthropic's partner list, read carefully, is partly a list of organizations whose internal information security Anthropic is willing to vouch for. Most OT vendors, through no fault of their own, sit below the cloud-provider bar on that dimension.

What OT Vendors Are Asking For

The asks have firmed up significantly over the last three weeks. They sort into three buckets.

The technical ask is for a Glasswing engagement model that does not require shipping firmware images and source code over a public-internet API. The candidates being floated include an air-gapped on-premises deployment of Mythos, a vendor-controlled secure-compute enclave hosted at Anthropic, or a hybrid in which a smaller bootstrapped model runs at the vendor's site and only carefully-redacted artifacts escalate to the full Mythos. None of these match Anthropic's current product surface.

The governance ask is for Glasswing-OT findings to flow through the established CISA ICS-CERT coordinated disclosure process, with vendor-driven timelines that respect the physical-world patching reality. Cloud bugs can be patched in days. PLC firmware updates often require planned outages scheduled six to eighteen months in advance. The disclosure pipeline has to be designed around safe physical deployment, not around a 90-day soft deadline.

The economic ask is for pricing that reflects OT industry margins. Glasswing engagements with cloud partners are reportedly priced in the seven-to-eight-figure range. That is not an absorbable number for an industrial automation business unit. Either Anthropic prices an OT track differently — which it has not signaled it intends to do — or a federal cost-share program underwrites the difference.

OT vendor priority vs. Anthropic readiness on key Glasswing-OT asks (1-10 scale)

OT vendor priority vs. Anthropic readiness on key Glasswing-OT asks (1-10 scale)
askvendorPriorityanthropicReadiness
On-prem / enclave model93
CISA-aligned disclosure86
Federal cost-share pricing94
Pre-vetted OT-specific eval set75

What Anthropic Has Signaled

Anthropic's public posture, summarized across the research site update, the IBM Mixture of Experts podcast appearance, and public statements at recent industry events, comes to roughly this: yes, the OT exclusion is acknowledged; yes, the company is "evaluating expansion"; no, there is no timeline; and the constraints are real (engineering, legal, information-handling) rather than commercial. That last point is worth taking at face value — Anthropic has not, in any of its public materials, presented OT exclusion as a commercial prioritization decision. Whether that posture survives contact with the actual cost of building an OT-suitable Mythos deployment is the question on the table.

The internal signal that matters more than the public posture is who Anthropic has been hiring on the Glasswing side. The team has been adding senior cybersecurity researchers from the IT side, infrastructure security from cloud backgrounds, and a small number of researchers with explicit ICS/OT experience. The ICS/OT hiring is happening but is not, on the public record, at the scale that would imply a near-term major OT product launch.

The Federal Lever

There is a public-policy lever here that has not yet been pulled. CISA and CESER have both been public about the importance of AI-assisted vulnerability discovery in critical infrastructure. Neither has yet announced a program that would underwrite OT-vendor participation in a Glasswing-equivalent engagement. A federal cost-share program — even at 50% — would change the affordability arithmetic in ways that would meaningfully accelerate inclusion.

The window for this kind of program in fiscal 2026 is narrow. Federal procurement timelines being what they are, anything announced in May 2026 is probably not contracting until late Q3 or Q4. Anything not announced by July is probably slipping into FY2027. Whether a federal program emerges in the next two months is therefore one of the more consequential cybersecurity-policy questions of the year, and it has had remarkably little public discussion outside the trade press.

Data and Evidence

Project Glasswing launch partners by sector (n = 9)

Project Glasswing launch partners by sector (n = 9)
NameValue
Cloud / Hyperscaler3
Endpoint / Network Security2
Consumer Tech & Silicon3
Financial Services1

The historical IT-to-OT lag on every previous defensive technology adoption sits between three and six years. EDR, modern SBOM, ATT&CK for ICS, and supply-chain attestation all repeated the same pattern: the IT side adopted first, the OT side adopted three-to-six years later, and the gap was paid in incidents during the lag period. Repeating that pattern with Mythos-class capability would put broad OT availability somewhere in 2028–2029. The offensive analog of Mythos — a frontier-model-driven autonomous vulnerability discovery capability available to adversaries — is reachable now via open-weights models that have closed most of the closed-weights gap. The lag, if it follows historical norms, will be paid in OT incidents during 2027 and 2028.

Conclusion

Anthropic is not the villain of the Glasswing-OT gap. The gap is structural — driven by commercial, legal, engineering, and information-handling constraints that no single lab can be expected to solve alone — and the public response to it should be commensurately structural. That means federal cost-share programs, a productized on-prem or enclave deployment of Mythos, an OT-aligned disclosure pipeline through ICS-CERT, and procurement-side pressure from the operators of critical infrastructure on their vendors. None of those things will happen on Anthropic's timeline alone. All of them are tractable in the back half of 2026 if the relevant institutions decide to treat the gap as the structural cybersecurity issue it is.

The trade press is treating Glasswing-OT exclusion as a story about an AI lab making a curatorial decision. That framing is not wrong. It is also incomplete. The deeper story is that frontier AI labs are now operating, de facto, as a critical layer of cybersecurity infrastructure, and the partner-selection process by which that layer is allocated has no public accountability. That is the question worth raising while the policy window remains open.

Further Reading

Sources

  • Project Glasswing official page, anthropic.com/glasswing
  • Anthropic Research Preview, red.anthropic.com/2026/mythos-preview
  • Schneier on Security commentary, schneier.com (April 2026)
  • Nextgov, "OT providers feeling 'annoyance' at exclusion from Anthropic's Mythos rollout" (May 2026)
  • Fortune, "Anthropic giving some firms early access to Claude Mythos to bolster cybersecurity" (April 2026)
  • IBM Mixture of Experts podcast, "Claude Mythos, Project Glasswing and AI cybersecurity risks"