Back to all posts

Project Glasswing and the dangers of private diplomacy

The New Yorker published a profile of Sam Altman last week, echoing much of what Karen Hao laid out in Empire of AI: his reputation as a self-interested sociopath, his talent for telling investors exactly what they want to hear, and his duplicitous stance on OpenAI’s core mission.

So what? The personality of Big Tech leaders is a distraction. Whether Altman is a megalomaniac or a visionary is irrelevant, or at least it should be. We know the current system rewards shark-like behavior. No surprise there.

Sadly, this piece is still important.

The real cause for concern is exemplified by Anthropic’s recent decision regarding their latest frontier model. Anthropic chose to withhold the release of Mythos after it discovered critical, previously hidden vulnerabilities in major operating systems and browsers. They reasoned that if the model was able to find these vulnerabilities, it would be able to find more and exploit them, and, put in the wrong hands, could threaten critical public and private systems. So instead of a public launch, they initiated Project Glasswing, granting access to an exclusive evaluation version to a select consortium of tech companies to patch their software infrastructure.

“Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Given the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely. The fallout—for economies, public safety, and national security—could be severe. Project Glasswing is an urgent attempt to put these capabilities to work for defensive purposes.”

There’s a lot of chatter debating whether Anthropic’s caution is genuine or a clever marketing ploy. The truth likely sits in a mix of motivations:

  • They are building hype. By the time Mythos is "safe" enough for release, the demand will be astronomical and tokens will fly off the shelf like Labubus.
  • It reinforces their image as the "safety-first" alternative to other labs.
  • They might have gone over the EU AI act threshold in training compute that classifies Mythos as a General Purpose AI model with systemic risks (10^25 floating point operations (FLOPs)). With the rule entering into force in August, Anthropic may be performing "goodwill" to avoid future friction with European regulators.
  • They’re genuinely concerned about the risks that their latest model poses, and they’re putting their AI Safety mission in action.

The fact that we have to guess their motivation is the problem. If this discovery had happened at Meta, who refused to sign the EU’s voluntary Code of Practice, calling it “overreach”, or at xAI where safety is treated as "woke", would that model already be in the wild?

Some will argue that initiatives like “Project Glasswing” prove that AI doesn’t need government oversight, and that “responsible” labs can manage their own risks through private governance. But it only highlights the absurdity of our current position. In this scenario, a private company is acting as a self-appointed Head of the Security Council for the global software infrastructure. Who determines when the consortium has done enough testing and the risk is low enough to release the model? Who is consulted, and who is left outside the room? It’s all at Anthropic’s discretion.

In a sensible world, profiles like The New Yorker’s wouldn’t be printed. We wouldn’t need to pay attention to a CEO's temperament and principles. Public interest would not hinge on any tech leader’s conscience or their company’s marketing strategy. We wouldn’t be counting on benevolent leaders to gatekeep high-risk technology.

The Mythos delay shouldn't be seen as a victory for self-regulation but as a warning of how much power we’ve already ceded. We need AI sovereignty: public, transparent and state-backed infrastructure that serves the public interest, not a corporate board's "Responsible Scaling Policy".


Sources