India Gets Claude Mythos Keys: CERT-In, Banks — IT Firms Out
Quick summary
Anthropic expanded Project Glasswing to 150 orgs in 15+ countries. India's cyber, telecom, and finance sectors got preview access; big IT vendors did not.
Read next
- White House Blocked Anthropic Mythos Rollout: 1,726 CVEs, 6-Month Warning
- Anthropic Mythos: Glasswing Adds 150 Orgs in 15+ Countries
India did not get a public Mythos download link on June 4 — a handful of Indian cyber, telecom, banking, and finance organizations received controlled preview access to Claude Mythos under Anthropic's expanded Project Glasswing, while major IT services vendors were left off the list, government officials told Economic Times and The Hindu BusinessLine.
"Gets keys" in headline terms means gated API access with security reviews, not keys on GitHub.
What Anthropic Announced
On June 2, 2026, Anthropic posted that ~150 additional organizations in more than 15 countries joined Project Glasswing, extending Claude Mythos Preview beyond the initial ~50 partners (clouds, banks, hardware majors) from April 2026.
Anthropic's public note stresses partners defend critical infrastructure — power, water, health, communications, finance, national security — where a major attack could affect 100M+ people.
The company does not publish org names or country lists, but confirmed to Indian outlets that India is included.
What India Actually Received
Economic Times (June 3–4 reporting) cited senior officials:
- Single-digit count of Indian orgs so far (public + private)
- Sectors: cybersecurity, telecom, banking, finance
- No major Indian IT outsourcing giants on the early list
- Government pushing to widen access; CERT-In (national cyber agency) likely in the preview pipeline
- MeitY engaged ~two months with US counterparts to secure access so Indian critical infrastructure is not stuck patching blind while US peers use Mythos-class tooling
India Today and News9 echoed the same framing: tight controls, infrastructure defenders first, RBI already analyzing Mythos alongside global regulators after April's launch spooked finance ministries.
Why IT Services Were Excluded (For Now)
Mythos is not a coding copilot. It is an offensive-security-capable frontier model Anthropic and the White House already fought over expanding (White House blocked wider Mythos rollout after 1,726 confirmed CVEs).
Letting every global IT body shop touch Mythos preview would multiply misuse and credential theft risk. Sectoral filtering — banks and CERT teams first — matches Glasswing's defensive patching mission, not TCS/Infosys contract velocity.
Developers at outsourcers still patch the same FFmpeg, OpenSSL, Linux bugs Mythos finds — they just do it without Mythos in the loop until access broadens.
Technical Implications for Indian Dev and SecOps Teams
If you run critical infra in India:
- Expect dual-speed patching — partners with Mythos may get earlier flaw reports routed via Glasswing; you still owe your own scanning
- Do not wait for Mythos — April Mythos runs already surfaced 10,000+ high/critical issues industry-wide; see developer patch action list
- Supply-chain audits — banks with preview access may demand faster SBOM proof from vendors still excluded
- Data residency — preview terms likely restrict cross-border prompt data; architecture reviews should assume no Mythos prompts leave approved environments
Finance angle: April launch triggered RBI and Finance Ministry warnings to tighten defenses — preview access is acknowledgment that regulators want parity, not relaxation.
How This Fits Global AI Security Politics
Glasswing is Anthropic's attempt to coordinate defensive patching faster than adversaries copy Mythos-class capability — Amodei's 6–12 month adversary window still applies in India as much as the US.
India sitting inside the tent beats reading about 1,726 CVEs in press releases after US banks patch first. Excluding IT majors signals capacity-constrained rollout, not a snub.
Cross-read Uber token caps vs engineers for how even AI buyers hit budget walls — Glasswing is the opposite problem (too much capability, tightly rationed).
Tooling: track model costs on LLM API Pricing; Mythos itself is not a public API product.
Key Takeaways
- June 2, 2026: Anthropic added ~150 orgs, 15+ countries to Project Glasswing / Mythos Preview
- India: single-digit early orgs in cyber, telecom, banking, finance — not big IT firms
- CERT-In and wider govt access in negotiation; MeitY pursued access for ~two months
- "Keys" = vetted preview credentials, not open weights or public endpoints
- Developers: patch cadence pressure rises; excluded vendors must still match Glasswing-disclosed flaw velocity
- Watch: IT sector inclusion, RBI guidance, White House view on India expansion, adversary replication timeline
Sources
FAQ
Frequently Asked Questions
Did India get public access to Claude Mythos?
No. Anthropic expanded controlled Mythos Preview access under Project Glasswing to a small number of Indian public and private organizations in cybersecurity, telecom, banking, and finance. It is not a public API or downloadable model.
Which Indian organizations got Mythos access?
Anthropic does not publish names. Indian officials told media the count is in the single digits, focused on critical infrastructure sectors, with CERT-In likely among future public-sector recipients.
Why were Indian IT companies excluded?
Early Glasswing expansion prioritizes critical infrastructure defenders and regulated finance under strict security requirements. Large IT services firms were not on the first Indian list, likely due to proliferation risk and limited preview capacity.
What is Project Glasswing?
Project Glasswing is Anthropic's program to give vetted organizations access to Claude Mythos Preview so they can find and patch severe vulnerabilities faster. It expanded by roughly 150 organizations in June 2026.
What should developers do without Mythos access?
Maintain normal enterprise patching for open-source dependencies, monitor advisories from projects Mythos already scanned, and pressure vendors for SBOM transparency. Mythos accelerates discovery industry-wide even for teams without direct access.
Free Weekly Briefing
The AI & Dev Briefing
One honest email a week — what actually matters in AI and software engineering. No noise, no sponsored content. Read by developers across 30+ countries.
No spam. Unsubscribe anytime.
More on Cybersecurity
All posts →White House Blocked Anthropic Mythos Rollout: 1,726 CVEs, 6-Month Warning
The White House blocked Anthropic from expanding Mythos access to 120 organizations after the AI found 1,726 confirmed CVEs. Dario Amodei warns of a 6-12 month window before adversaries match it.
Anthropic Mythos: Glasswing Adds 150 Orgs in 15+ Countries
June 2, 2026: Anthropic expanded Project Glasswing — Claude Mythos Preview to ~150 new orgs across 15+ countries. Power, water, health, comms. 10,000+ critical flaws found since April.
MuddyWater Pre-Planted Backdoors in US Banks, Airports, and Defence Firms Before Iran Conflict
Iranian APT MuddyWater (Seedworm) planted Python backdoors inside US financial institutions, airports, and defence contractors before Operation Epic Fury. CISA and Unit 42 confirmed. Here is what security teams need to do now.
Volt Typhoon and Salt Typhoon: China's Pre-Positioned Hackers Are Inside US Power Grids and Telecoms
FBI and CISA confirmed Chinese state hackers Volt Typhoon and Salt Typhoon have been dormant inside US power grids, water systems, and telecoms for years. Here is what happened, why it matters, and what infrastructure teams must do now.
Written by
Software Engineer based in Delhi, India. Writes about AI models, semiconductor supply chains, and tech geopolitics — covering the intersection of infrastructure and global events. 803+ posts cited by ChatGPT, Perplexity, and Gemini. Read in 164 countries.
