AI Just Broke the Rules of Cybersecurity. Most Organizations Are Not Ready.
- Kirk M. Anderson, MBA, CISSP, CISM, PMP

- May 25
- 5 min read

For two decades, cybersecurity operated at human scale. Attackers and defenders were constrained by human expertise, human labor, and human time. AI may have just ended that era.
5 min read · May 2026

What happened
Anthropic recently published initial results from Project Glasswing, a cybersecurity initiative it formed with 11 founding partners: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. More than 40 additional organizations that build or maintain critical software infrastructure joined as participants. The initiative uses an unreleased model called Claude Mythos Preview to scan critical systems for previously unknown security flaws.
In roughly one month of partner use, the model helped surface more than 10,000 high- or critical-severity vulnerabilities across cloud platforms, browsers, operating systems, and enterprise software. Partners reported finding bugs at more than ten times their previous rate. Cloudflare identified 2,000 vulnerabilities in its own systems, with 400 rated high or critical. Mozilla found and fixed 271 vulnerabilities in Firefox 150 during Mythos testing, a dramatic increase compared to prior testing cycles. A financial services partner used the model to detect and stop a fraudulent $1.5 million wire transfer in real time.
Separately, Anthropic used Mythos Preview to scan more than 1,000 widely used open-source projects, the kind of shared infrastructure that underpins much of the internet. That scan identified an estimated 23,019 potential vulnerabilities. Of the high- and critical-severity findings that external security firms have reviewed so far, roughly 90 percent have been confirmed as genuine flaws, with more than 1,000 already rated high or critical severity. The review and patching process is ongoing; Anthropic expects the confirmed count to grow substantially as that work continues.
"Progress on software security used to be limited by how quickly we could find new vulnerabilities. Now it's limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found by AI."
Anthropic, Project Glasswing update, May 2026
The most revealing detail in Anthropic's own report is not the volume of findings. It is the admission that follows: even at what the company describes as a relatively slow pace of disclosures, the AI is adding to an already-overloaded security ecosystem. Some open-source maintainers have asked Anthropic to slow down reporting because they cannot develop and deploy fixes quickly enough to keep up. That is the real shift. The bottleneck in cybersecurity is no longer finding problems. It is fixing them.
Executives should not treat this as another AI trend story. This is a reassessment of the enterprise threat surface itself.
Business impact
Revenue risk
Every major platform your business relies on, from your cloud provider to your SaaS tools to the open-source components inside your own software, likely contains vulnerabilities that no human team has yet discovered. As AI-assisted discovery compresses the timeline from "flaw exists" to "flaw is known," the window before potential exploitation shrinks with it. Ransomware incidents, supply chain compromises, and service outages become more probable not because attackers have become more sophisticated, but because the attack surface is now being mapped at a speed and scale that simply did not exist before.
Operational risk
Most security teams are already managing a remediation backlog. A tenfold increase in critical findings does not arrive with a corresponding increase in the engineers needed to safely test, approve, and deploy fixes. The math breaks. More alerts, more urgent patches, and more emergency change requests land against the same headcount and existing change-management processes. Palo Alto Networks released more than five times its usual number of patches in a recent update cycle as a direct result of Glasswing.
Microsoft has signaled that patch volumes will keep growing. For organizations without the engineering depth of those two companies, that trajectory represents a genuine operational stress test. Alert fatigue, delayed patches, and burned-out security staff are not abstract concerns. They are the preconditions for exactly the incidents organizations are trying to prevent.
Governance and reputation risk
Regulators, cyber insurers, and enterprise procurement teams increasingly require organizations to demonstrate software supply chain awareness, not just perimeter security. A Software Bill of Materials (SBOM), continuous dependency monitoring, and documented patch velocity are becoming baseline expectations in regulated industries and large enterprise contracts. Organizations that cannot provide that level of visibility will face higher insurance premiums and regulatory scrutiny, and will increasingly appear operationally unprepared to the customers and partners whose trust their business depends on.
Executive action required
The specific questions your leadership team should be asking right now:
Do we have a complete, continuously updated inventory of every open-source component our critical systems depend on, and do we maintain a Software Bill of Materials?
What is our current remediation backlog, and what is our average time from a critical finding to a deployed patch?
Which vendors or third-party integrations represent the highest concentration of software supply chain risk?
If our security team received ten times its current volume of critical findings tomorrow, would operations absorb it, or would the queue grow faster than it could be cleared?
Are we measuring cybersecurity operationally, tracking patch velocity, backlog growth, and mean time to remediate, or only by perimeter and detection metrics?
Does our board understand the difference between detection investment and remediation capacity? A dashboard full of findings that no one has capacity to act on is not security. It is a documented record of unmanaged exposure.
How urgent is this?
Project Glasswing is live and operational now. Vulnerabilities are being found now. Open-source maintainers are already asking Anthropic to slow disclosures because they cannot patch fast enough. The question is not whether AI has changed the speed of cybersecurity. It already has. The question is whether your organization can operationally adapt before the gap between discovery speed and remediation capacity becomes a material business risk.
There is also a capability gap executives need to understand. The founding consortium of Project Glasswing includes Microsoft, Google, Apple, Amazon, JPMorganChase, and Palo Alto Networks. These organizations are hardening their systems right now, using tools that are not yet available to the broader market. Hospitals, municipalities, mid-market businesses, and public-sector entities face the same accelerating threat landscape without equivalent access to defensive tools. Anthropic committed $100 million in model usage credits and $4 million in direct donations to open-source security organizations specifically because this gap is real and consequential. Closing it at the organizational level requires deliberate investment decisions, not deferred ones.
Budget implications

The framing that matters for boards: these are no longer optimization investments. They are resilience investments. Anthropic's own commitment of $100 million toward defensive security work reflects the scale of what is being asked of the industry. Building organizational capacity before an incident costs a fraction of what responding to one costs, and the runway between those two scenarios is getting shorter.
Cybersecurity is no longer constrained by human discovery speed. But most organizations are still governed, staffed, funded, and operationalized as if it is. That gap may become one of the defining business risks of the AI era.



Comments