AWS Claude Mythos Preview | Bedrock Application and Glasswing Eligibility

Article Summary by AI Chatpowered by Claude

For security professionals looking to try Claude Mythos Preview on AWS, this article outlines the access conditions via Amazon Bedrock, the organizations targeted by Project Glasswing, and the realistic hurdles involved in applying. Access is not generally available — it operates on an allow-list basis, is restricted to defensive security use cases, and is only offered in the US East region. This article is structured to help you determine eligibility as quickly as possible.

結論powered by Claude

For security professionals looking to try Claude Mythos Preview on AWS, this article outlines the access conditions via Amazon Bedrock, the types of organizations targeted by Project Glasswing, and the realistic hurdles involved in applying.

The key points are that access is not generally available — it operates on an allow-list basis — and that use cases are restricted to defensive security.

Taking into account the additional constraint that the model is only available in the US East region, this article is structured to help you determine your organization's eligibility as quickly as possible.

目次 (9)

What Is Claude Mythos Preview?

Claude Mythos Preview is Anthropic's latest-class model, made available in limited preview via Amazon Bedrock on April 7, 2026. Anthropic describes it as surpassing previous Claude models in cybersecurity, large-scale codebase comprehension, and complex reasoning — capable of identifying and demonstrating high-severity software vulnerabilities with minimal human guidance. It has already been used to discover numerous vulnerabilities in major operating systems and web browsers, and is positioned as a model designed to strengthen the capabilities of defenders.

The fundamental difference from conventional Claude Sonnet and Opus models is that Mythos Preview is not intended for general chat use. Organizations considering adoption need to first ask: "Does our organization bear responsibility for defensive security?"

Why It Is Bundled with Project Glasswing

Claude Mythos Preview is not offered as a standalone model. It is provided as part of Project Glasswing, a program that Anthropic launched together with AWS and major platform providers. Glasswing is designed to direct AI — whose code analysis capabilities are beginning to surpass those of top human experts — toward ensuring an advantage for defenders. Anthropic cites protecting internet infrastructure as a core motivation.

The initial partners number 11 in total; Anthropic's public disclosures name five explicitly: AWS, Apple, Google, Microsoft, and Cisco. The remaining six are not disclosed in official announcements (see Anthropic Project Glasswing for details). In addition, more than 40 organizations and open-source maintainers responsible for critical software are included. Access to Mythos Preview is tied to Glasswing membership — it cannot be activated through Bedrock's self-service model catalog.

Application Requirements and Eligible Organizations

AWS's official What's New announcement states that access is limited to "organizations on the initial allow-list," and eligible companies are contacted directly by their AWS account teams. On the Anthropic side, there is also an application channel for open-source maintainers through the Claude for Open Source program.

The realistic barriers to applying come down to three points:

  1. The organization must be responsible for maintaining critical internet infrastructure, major operating systems or browsers, or large-scale open-source software.
  2. The use case must be restricted to defensive security (local vulnerability detection, black-box testing of binaries, endpoint protection, and penetration testing of the organization's own systems).
  3. The organization must have passed individual review via an AWS account team or through Anthropic.

General development use cases, analysis of third-party products, and offensive security applications are out of scope. There is currently no announced timeline for general availability (GA).

Sources: AWS Official What's New / Anthropic Project Glasswing

How It Is Offered on Amazon Bedrock

The available region is US East (Virginia / us-east-1) only. There are currently no announcements for availability in the Tokyo, Osaka, or European regions. Organizations based in Japan that wish to use the model will need to separately design governance around cross-region inference and data transfer.

Unlike standard Bedrock models, Mythos Preview is not an invokeModel target that can be activated automatically from the model catalog. It is a gated research preview that only accepts requests after access has been granted by an AWS account team. Organizations planning to adopt it should have the following three items ready to expedite conversations with their account team: the target AWS account ID, the intended region, and the anticipated workload.

Anticipated Use Cases

The use cases envisioned by Glasswing are clearly oriented toward the defensive side. Specifically, they include the following areas:

  1. Vulnerability scanning and PoC generation for the organization's own products and infrastructure
  2. Black-box testing of binaries prior to release
  3. Strengthening detection logic in endpoint protection products
  4. Automating triage and initial analysis for existing security teams
  5. Vulnerability auditing of their own projects by open-source maintainers

Anthropic states that the model has "reached a level where it can discover high-severity vulnerabilities with practical accuracy," positioning it as a tool that can significantly reduce the upfront effort required from security teams. However, validating the results and implementing fixes remain the responsibility of human engineers.

Pricing and the Current State of Public Information

The AWS Official What's New announcement does not specify pricing for Mythos Preview. It appears that pricing details are communicated individually to allow-listed organizations by their AWS account teams. Pricing has not been publicly disclosed at this time.

For budget planning purposes, it is prudent to include two caveats: (1) the initial access may come with complimentary credits or a special credit pool, and (2) the pricing structure may be revised when the model reaches general availability.

Choosing Between Mythos Preview and Existing Claude Models

Mythos Preview is not a replacement for general-purpose Claude. A realistic division of use cases for internal deployment might look like the following:

  • General operations, code generation, chat: Claude Sonnet / Opus (standard Bedrock offering)
  • Vulnerability detection for the organization's own products and defensive security research: Claude Mythos Preview (via Glasswing)
  • Large-scale codebase refactoring and architectural support: Claude Opus 4.x with Extended Thinking

Even if an organization gains access to Mythos Preview, repurposing it for everyday development may constitute a violation of the terms of use. It is essential to incorporate the Glasswing terms — which explicitly limit usage to defensive security — into your organization's internal guidelines.

Sources: Anthropic and Amazon expand collaboration / AWS Weekly Roundup 2026-04-13

Pre-Application Checklist

Before deciding whether to apply, confirm the following seven points internally:

  1. Does your organization qualify as a Glasswing target (critical infrastructure, major OSS, or defensive security responsibility)?
  2. Will legal and compliance teams allow the use case to be restricted to defensive security?
  3. Do your information governance requirements permit data residency in us-east-1?
  4. Is there a clear line of communication with your AWS account team?
  5. Does your organization have the resources to remediate discovered vulnerabilities? (Discovering vulnerabilities and leaving them unaddressed is itself a risk.)
  6. Can the billing pathway be kept separate from existing Claude (Sonnet / Opus) contracts?
  7. Can your organization accept the risk of pricing changes and potential discontinuation when GA is announced?

If the answer to any of these is "No," it is premature to apply at this time. Exploring alternatives — such as supplementing defensive security workflows with the standard Claude models available on Bedrock — would likely yield better return on investment.

Summary

Claude Mythos Preview is a cybersecurity-specialized model offered exclusively through Bedrock under the Project Glasswing framework. It comes with three layers of restriction: available only in us-east-1, access controlled by an allow-list, and usage limited to defensive security. It is not a model available to every organization that wants to use Claude on AWS. Organizations responsible for critical infrastructure or major open-source software have good reason to pursue an application through their AWS account team; for all others, using standard Claude Sonnet or Opus via Bedrock is the more practical path. Waiting for an official GA announcement and confirmed pricing is also a fully rational choice.

Sources:

参考になったら ♡
Clauder Navi 編集部
@clauder_navi

Anthropic の Claude / Claude Code を中心に、日本のエンジニア向けに最新動向と実務 を毎日発信。 運営方針 は メディアについて をご覧ください。