Tuesday, August 4, 2026

Anthropic representatives discuss AI Safety

See All Articles

The Glasswing Moment: When AI Cybersecurity Became a Geopolitical Flashpoint

In a revealing exchange with the European Parliament’s IMCO committee, Andrew Greenberg, the technical co‑lead of Anthropic’s Project Glasswing, laid bare the extraordinary promise and peril of frontier AI models in cybersecurity. What was intended as an “exchange of views” quickly turned into a tense reckoning with dependency, trust, and the sudden fragility of transatlantic technology alliances. The transcript of that session, now circulating widely, exposes a raw nerve in Europe’s digital sovereignty – and it deserves a careful, critical unpacking.

Mythos Preview: The Dual‑Use Genie Out of the Bottle

Greenberg presented a startling picture of a model that Anthropic did not specifically train for cyber offence but which, by virtue of its coding and reasoning prowess, unearthed thousands of previously unknown vulnerabilities. “In testing, it found thousands of previously unknown vulnerabilities, including in every major operating system and web browser,” he told the committee. The list includes a 27‑year‑old flaw in OpenBSD, one of the world’s most security‑hardened operating systems, and several Linux kernel bugs that the model chained together to seize control of the machine. The company’s Red Team blog details the critical bugs, and the message was unequivocal: releasing such a model broadly would be irresponsible.

Instead, Anthropic launched Project Glasswing – a company‑level partnership with cyber defenders to get ahead of AI‑driven offensive threats. Over 150 organizations in more than 15 countries were given gated access. The results, even within the first month, are staggering. Mozilla found and fixed 271 vulnerabilities in a single Firefox release – ten times what it found in the previous one. A table of publicly known highlights underscores the scale:

Software Vulnerability Age Severity Outcome
OpenBSD 27 years Critical Flaw identified
Linux kernel Multiple, chained High Full machine control achieved
Firefox (single release) Unknown 271 high/critical Fixed (10× previous rate)
Across Glasswing partners 10,000+ high/critical Found in first month

“Finding vulnerabilities is no longer the bottleneck,” Greenberg observed. “Fixing them and incorporating AI capabilities across defensive security programs is.” The bottleneck has shifted to triage, remediation, incident response, and configuration scanning – a systemic challenge that no single actor can solve alone.

The Export Control Shock and Its Aftermath

Then came the geopolitical tremor. On 12 June, the U.S. government applied export controls to Anthropic’s newest models – Fable 5 and Mythos 5 – forcing the company to suspend access for all foreign nationals. The controls were lifted on 30 June, and access was restored the following day. Greenberg described subsequent collaboration with U.S. agencies “to review and test our safeguards” and to increase their robustness on the Fable class. Notably, he clarified that the Mythos class – the models with the most worrying dual‑use cyber potential – were not the subject of that safeguard reinforcement; they have “limited safeguards” by design. No specific change was made to them before or after the restrictions.

The episode revealed an uncomfortable truth: a company legally bound to weigh public interest could be compelled overnight to withdraw a critical defensive tool from allies. For European lawmakers, the move was not merely a bureaucratic hiccup but a vivid demonstration of dependence. MEP Dirk Houtink (EPP) captured the mood, describing how the White House intervention had turned a noble technological mission “into a geopolitical tool and an economic tool,” shattering illusions of a solid transatlantic tech partnership.

Europe’s Anxiety: Can We Trust the Model, or Its Maker?

The committee’s questions were sharp and impatient. Would Anthropic even be buildable in the EU, given Europe’s regulatory thicket and energy constraints? Greenberg sidestepped, insisting the real issue was not one company but a global cybersecurity moment: “We expect our competitors to have models of similar capabilities quite soon … some of whom will be providing open weights or won’t be providing them with adequate safeguards.” In other words, fixating on Anthropic misses the point – an approaching wave of less scrupulous models threatens to flood the zone.

MEP Köstl‑Schaldemosen (S&D) raised a more fundamental worry: dependency. If Europe uses Anthropic’s services, it feeds data and growth back to a U.S. entity while remaining at the mercy of Washington’s political whims. Why not develop sovereign EU systems instead? Greenberg offered no real answer, only that the goal should be to up‑level cyber defence globally, using a diverse set of models, not to rely on “one special or magic model.”

The Greens’ Kim van Sparentaak did not hide her alarm: “What is Entropiq exactly doing to ensure people and businesses are safe, not only in the U.S. … but also in Europe?” She demanded to know whether the model could be weaponized for geopolitical gain. The phrasing – “Entropiq” (a misspelling that inadvertently underscored the alienness of the company from a European vantage) – encapsulated the trust chasm.

A Window Measured in Months

Perhaps the most chilling forecast was temporal. “Within three to six months, we expect many other AI companies will have models of this class, and some may release them without safeguards. The window in which defenders hold the advantage is measured in months,” Greenberg warned. The same capability that makes these models dangerous, he stressed, also makes them the most powerful defensive tool ever created – if wielded properly, technology favours defenders long‑term. But that optimism hinges on a global, coordinated response that is nowhere yet in evidence.

The company is working to avoid future circus‑style rollouts. Greenberg admitted that the staged, guarded release was “a long road” born of the need to build protections progressively and watch for misuse. The promise is that future models will be delivered to cyber defenders in a more targeted, predictable fashion. But given the geopolitical electricity that now courses through every AI deployment, that assurance will need far more than good intentions to be believed.

Criticisms

  • The United States government is criticized for abruptly imposing export controls on AI models without prior consultation with allies, thereby weaponising a defensive technology and undermining transatlantic trust.
  • Anthropic is faulted for its insufficient foresight in addressing the geopolitical dimensions of its dual‑use models, leaving European customers exposed to sudden access revocations.
  • The European Union’s regulatory framework is questioned for its potential to stifle indigenous AI development, reinforcing dependency on non‑European providers and slowing the emergence of sovereign alternatives.
  • The White House’s decision to lift controls after internal safeguards review is seen as opaque, with no public clarity on what changes were made to justify restored access, fuelling suspicion of secret concessions.
  • Member states are criticised for a reactive posture, failing to invest coherently in the AI‑enabled cyber defence infrastructure that Greenberg’s testimony makes urgently necessary.

Greenberg ended with a plea for “coordinated, highly collaborative action across many organizations.” It was a message that, in the tension‑filled room, sounded both noble and hollow. The power to act rests not with one technical co‑lead in New York, but with governments that have yet to prove they can match the speed and scale of the threat. The glass may be half‑full, but the window is closing fast.

No comments:

Post a Comment