Anthropic says it limited Claude Mythos Preview to a gated security program because the model can find and exploit software vulnerabilities at a level that requires controlled access. Public evidence also shows that Anthropic was managing major compute expansion and that Mythos carried a high usage price. No public primary source proves how Anthropic weighted those factors internally.
Last checked July 26, 2026. This article separates Anthropic’s statements, partner observations, third-party reporting, and inference.
Evidence summary
- What changed: Anthropic launched Project Glasswing with named launch partners and extended Claude Mythos Preview access to more than 40 additional organizations working on critical software.
- Current access and cost: Anthropic lists Mythos as a gated research preview for Glasswing participants at $25 per million input tokens and $125 per million output tokens. It committed up to $100 million in usage credits.
- Official source: Anthropic’s alignment risk update says Mythos is not generally available, is more capable and more agentic than prior models, and received an overall alignment-risk assessment of “very low, but higher than for previous models.”
- Company and partner claims: Anthropic and participating security organizations report stronger vulnerability-finding performance. These statements support the security rationale but are not independent proof of Anthropic’s internal release decision.
- Third-party and indirect evidence: Compute procurement, capacity management, and reporting about operating cost show that capacity mattered to Anthropic in 2026. They do not establish that compute scarcity caused the Mythos access restriction.
- Kingy-tested: Not tested. Kingy did not receive Mythos access or reproduce its security evaluations.
- Not yet verified: Anthropic has not published an internal decision record assigning weight to safety, cost, capacity, product readiness, or commercial strategy.
What Is Claude Mythos Preview?
Before examining the motives behind its restricted release, it helps to understand what Mythos actually is — or at least, what has been publicly confirmed.
Anthropic’s developer documentation describes Mythos Preview as an invitation-only model with no self-serve sign-up pathway. It is available through multiple channels — Anthropic’s direct API, Amazon Bedrock, Google Vertex AI, and Microsoft Azure Foundry — but only to vetted participants in the Glasswing program. Microsoft’s technical documentation describes it as supporting a 1 million token context window with a maximum output of 128,000 tokens, making it one of the longest-context models publicly documented.
Pricing during the Glasswing preview is listed at $25 per million input tokens and $125 per million output tokens — substantially higher than Claude’s standard tiers — with Anthropic committing up to $100 million in credits for program participants, a signal of how seriously the company is treating the initiative as a strategic investment rather than a commercial product launch.
What makes Mythos unusual isn’t just its context window or price point. It’s the specific capabilities that Anthropic’s own Frontier Red Team write-up documented: unlike prior models that could reproduce known vulnerabilities from training data, Mythos was tested against real, previously undisclosed software flaws — zero-days, in security parlance — that cannot be “memorized” from training sets. The model found them anyway. The scale and autonomy of that capability, Anthropic argues, is what makes broad release genuinely dangerous.
Partners and platform providers echoed the company’s framing. The AWS Security Blog described Anthropic as “taking a deliberately cautious approach to release.” The Microsoft MSRC blog framed early access as a mechanism to “identify and mitigate risk.” These are organizations with significant cybersecurity credibility, and their consistent amplification of the security rationale carries weight.
The Security Case: Evidence and Argument
The strongest evidence for security as the primary driver of restricted access comes directly from Anthropic itself, which makes it either the most credible source or the most interested party — depending on your prior.
The Glasswing announcement states explicitly: “Without the necessary safeguards, these powerful cyber capabilities could be used to exploit critical software.” The Frontier Red Team research makes the case in technical terms, arguing that restricted initial release is designed to “buy time for defenders” before equivalent capabilities proliferate through other channels — whether from other AI labs, state actors, or eventual model leakage.
The Alignment Risk Update for Claude Mythos Preview, a redacted public PDF published on April 10, 2026, goes further. It describes Mythos as “more capable and more agentic than prior models,” documents concerning observed behaviors in the service of task success, and explicitly confirms that the model is in a “limited-release research preview” and “not available for general access.” That document — an internal risk assessment voluntarily made public — represents a remarkable degree of transparency about the company’s concerns, and its existence is hard to dismiss as merely marketing.
Axios reporting from the launch period quoted Anthropic’s frontier red team head describing the model’s autonomy and vulnerability-finding capacity in stark terms, framing the decision to withhold broader release as a direct consequence of what the red team observed. Anthropic’s leadership, per the same reporting, publicly discussed the decision to hold back until adequate safeguards existed.
The existence of Project Glasswing as a consortium structure is itself a piece of evidence. Building a 40-organization vetted research program, committing $100 million in compute credits, and coordinating simultaneous partner announcements from AWS, Microsoft, Google Cloud, and Cisco is not the work of a company that simply ran out of server capacity. It reflects institutional investment in a particular access model — one designed around defensive use cases and accountability structures. You don’t build that infrastructure if the real problem is just cost.
That said, the security case has critics. The Guardian’s investigation into Anthropic’s communications strategy raised the pointed question of whether the company is benefiting from the marketing appeal of “too powerful to release” — a narrative that simultaneously positions Mythos as uniquely dangerous and Anthropic as uniquely responsible. That critique does not refute the security evidence; it mainly asks whether security is the only driver, or whether it is also strategically convenient.
The Compute Constraint Case: A Parallel Story
While Anthropic was announcing Glasswing, a separate set of events was unfolding that told a very different story about the company’s operational reality.
On April 6, 2026 — the day before the Glasswing launch — Anthropic announced a major compute expansion partnership with Google and Broadcom, described as involving multiple gigawatts of TPU capacity. The language in the announcement was telling: the capacity was needed, the company said, “to power our frontier Claude models and help us serve extraordinary demand.” Reuters’ contemporaneous reporting put the figure at approximately 3.5 gigawatts. The critical detail: this capacity was expected to come online starting in 2027, not 2026.
Four days later, on April 10, Reuters reported that Anthropic had struck a separate deal with CoreWeave to bring additional computing capacity online “later this year.” The CoreWeave deal looked like exactly what it was: a company filling a near-term gap while waiting for long-cycle infrastructure to materialize. And on April 9, Reuters also reported that Anthropic was exploring designing its own AI chips — a move explicitly tied to “a broader shortage of AI chips” and estimated to cost roughly $500 million.
These three stories, arriving within days of each other, painted a picture of a company under acute compute pressure across multiple time horizons: burning money to lease capacity now, negotiating for large-scale capacity years away, and beginning to consider the capital-intensive option of owning its own chip supply chain.
That picture was reinforced by what was happening with Anthropic’s existing products during the same period. On April 6, The Register reported that Anthropic had moved to restrict third-party agentic harnesses — tools that allowed users to run Claude continuously through automated pipelines. The company’s spokesperson stated that these harnesses “put an outsized strain on our systems” and that “capacity is something we manage thoughtfully.” Axios framed the same policy change as a cost-control measure, noting that agentic usage can run continuously and consume orders of magnitude more tokens than ordinary chat interactions. Anthropic’s public status page showed repeated elevated error rates and outage incidents in the same timeframe, consistent with heavy operational load.
Anthropic’s own hiring signals are worth examining here. A job listing for a Staff/Senior Software Engineer on the Compute Capacity team describes “one of the largest and fastest-growing accelerator fleets” spanning “multiple accelerator families and clouds,” with a mandate to ensure every chip is “accounted for” and “efficiently allocated.” A separate role focused on securing and delivering compute capacity and a data center capacity delivery position that emphasized activating leased and partnered capacity “on the fastest possible schedule” together suggest that compute efficiency and capacity delivery are organizational priorities, not merely engineering concerns.
Taken together, this evidence establishes one thing clearly: compute is a binding constraint at Anthropic in the spring of 2026. What it does not establish — at least not in primary sources — is a direct causal link from compute scarcity to the specific decision to restrict Mythos access.
The Leaked Draft: A Bridging Datapoint
The closest thing to a smoking gun connecting the two stories appeared not in an official document but in a leak.
On March 26, 2026, Fortune reported that an internal draft page — apparently associated with the Mythos/”Capybara” model — had surfaced, describing the model as “by far the most powerful” Claude to date while simultaneously noting that it was “expensive to run” and “not yet ready for general release.” Anthropic’s spokesperson, responding to the Fortune inquiry, confirmed a deliberate release approach with a small early-access cohort, but did not directly address the cost characterization.
That draft language matters because it’s the only publicly available document — even as a leak — that places cost and readiness in the same sentence as the decision to restrict access. The “expensive to run” framing is not a security argument. It is an economics argument, and its presence in what appears to have been an internal product description suggests that Mythos’s cost profile was at least part of the internal conversation about how to deploy it.
A week later, on April 1, the LA Times reported a separate source-code leak involving Claude Code, describing it as the second security incident in days and referencing the earlier Mythos/Capybara internal drafts. Whether coincidental or not, the pattern of internal documentation surfacing before the official launch added texture to the picture of a company managing a difficult rollout across multiple dimensions.
What It Actually Costs to Run Mythos at Scale
To evaluate the compute constraint hypothesis seriously, it helps to understand the economics of running a model with Mythos’s documented specifications.
Modern large language model serving involves two distinct computational phases. Prefill processes the full prompt and builds a key-value cache of intermediate activations. Decode then generates tokens autoregressively, reusing the cached values at each step. Both phases are computationally intensive, but the economics of the KV cache are particularly consequential for long-context models.
KV cache memory footprint scales linearly with context length, and also grows with batch size and model configuration. This means that a model supporting a 1 million token context window faces dramatically different memory requirements than one supporting 128,000 tokens. NVIDIA’s own documentation on KV cache management illustrates the issue concretely: for a 70-billion parameter model, a 128,000-token context at batch size 1 can require roughly 40 gigabytes of memory for the KV cache alone. Scaling to 1 million tokens implies approximately eight times that — hundreds of gigabytes — before counting model weights, activations, and other overhead.
For a single inference request, this is manageable. For thousands of concurrent agentic sessions, each potentially involving multi-step autonomous workflows across a million-token context, the numbers become very large very quickly. Serving this kind of workload economically would require aggressive KV cache optimization strategies, highly efficient serving engines utilizing continuous batching and paged attention mechanisms, and careful product-level constraints — rate limits, access gates, and workflow restrictions — to prevent any individual session from consuming a disproportionate share of the fleet’s memory.
In other words: the technical architecture of Mythos, as publicly documented, is precisely the kind of model that would create massive infrastructure strain if released without access controls. The invitation-only, defensive-workflow-focused structure of Glasswing is, from a systems engineering perspective, a sensible way to manage that strain — regardless of whether security or cost is the primary motivation.
Why the Compute Gap Won’t Close Quickly
The compute expansion deals announced in the same week as Glasswing are themselves evidence that Anthropic cannot simply flip a switch and serve Mythos broadly.
The 3.5-gigawatt TPU capacity secured through the Google and Broadcom partnership is not expected to come online until 2027. That is not an unusual timeline for large-scale infrastructure procurement — it reflects the physical reality of building data centers, procuring specialized hardware, and bringing complex systems into production. But it means that for the foreseeable future, Anthropic is operating with the compute it has today, not the compute it will have in 18 months.
That constraint is not unique to Anthropic. TechRadar reported in April 2026 that nearly half of US data centers planned for 2026 had been canceled or delayed, with transformer lead times and power infrastructure bottlenecks cited as the primary causes. The “power wall” — the difficulty of securing sufficient electrical grid capacity for large-scale AI facilities — has become a structural constraint across the industry. Network World reported that demand for AI compute is so intense that AWS customers have attempted to purchase the hyperscaler’s entire available capacity, and that even Amazon faces periods of insufficient supply.
In this environment, Anthropic securing the CoreWeave deal for near-term capacity and the Google/Broadcom deal for future capacity simultaneously is not a sign of excess — it is a sign of urgency. Companies do not pursue two parallel procurement strategies at different time horizons unless they are genuinely capacity-constrained. The explicit internal admission, through the third-party agent controversy, that capacity is “managed thoughtfully” fits the same pattern.
Incentives and the Narrative Gap
The question of why Anthropic would emphasize security over compute in its public communications is, on its own, not very complicated.
“We cannot serve it” is a product weakness. “We won’t release it because it’s dangerous” is a principled choice. Both statements might be equally true, but only one of them positions Anthropic as a responsible steward of frontier technology. In a landscape where the dominant public concern about AI is safety and misuse, framing a restricted release as a safety decision is not just accurate — it is strategically advantageous.
There is also a competitive dimension. The Verge reported on April 13, 2026 that an internal OpenAI memo — apparently authored by the company’s Chief Revenue Officer — explicitly accused Anthropic of failing to acquire enough compute, framed Anthropic’s restricted release story as one driven by “fear” and “restriction,” and asserted that OpenAI “has the compute” to serve its models broadly. That memo is a competitor document and should be treated as strategic messaging, not objective analysis.
But its existence confirms that the compute framing is being actively weaponized in the competitive space between these companies. For Anthropic, admitting compute insufficiency would hand OpenAI an argument they are apparently eager to deploy.
Anthropic’s incentive structure thus points strongly toward leading with security, even if compute is also a genuine constraint. The security narrative provides a defensible rationale, invites partnership with governments and critical infrastructure owners, mitigates reputational risk, and counters the competitive attack on compute acquisition — all simultaneously.
The Guardian’s investigation into Anthropic’s communications described it bluntly as a “bid to win the AI publicity war,” noting that the “too powerful for the public” framing benefits from its very ambiguity: it simultaneously generates hype, establishes Anthropic as a responsible actor, and provides cover for access restrictions that might otherwise be read as capacity management. This critique does not prove that security is not the real driver.
It simply establishes that security is also very useful as a public narrative, which means we should weight Anthropic’s public statements accordingly — as important evidence, but not as dispositive proof.
What the evidence supports
The security rationale has the strongest direct support. Anthropic published a gated-release design, a system card, an alignment-risk update, named launch partners, and a defined defensive-security program. Participating organizations also described their own security work with the model.
The compute and cost case is real but indirect. Anthropic was expanding capacity, managing heavy workloads, and charging a high public preview price. Those facts make cost and capacity plausible constraints. They do not show that either was the decisive reason for limiting access.
The defensible conclusion is narrower than the original headline: Anthropic documented security reasons for the restricted release, while public operating signals suggest cost and capacity may also have influenced rollout design. The available evidence cannot assign a percentage to each factor or establish a hidden “real reason.”
Kingy AI records
- Open the Claude product record
- See the later Claude Fable 5 and Mythos-class launch record
- Read Kingy’s Claude Mythos Preview system-card summary
Publishing
The Kingy Brief
Source-checked AI launch and product intelligence. See the public archive for the latest edition and cadence.
