Anthropic's Claude Mythos cybersecurity model, distributed under the Project Glasswing program, now spans roughly 200 partner organizations, but the absence of major UK lenders on that list points to a different trust gap.
A frontier AI cybersecurity model can spot a flaw in a bank's code in minutes. It will not save the bank that still cannot tell a customer what happened within the hour. That is the practical question the UK's largest lenders are now sitting on, even as Anthropic's Claude Mythos, the model in question, rolls out to roughly 200 partner organizations under the name Project Glasswing.
Anthropic launched the program in early April 2026 with about 50 partners, then expanded to roughly 150 more organizations in more than 15 countries on June 2, per the company's expansion announcement and CNBC's coverage. The current partner roster spans cloud, hardware, telecom and finance, and includes Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. The single US bank on that list, JPMorganChase, has direct access. Major UK banks do not.
UK lenders are "notably absent" from the Glasswing list, according to TechRadar Pro, and several are reported to be using a rival cyber-focused model from OpenAI instead. The OpenAI product is not named in the public reporting, so the substitution story is best treated as plausible but unverified at the model level. What is verifiable is that Bank of England Governor Andrew Bailey has been raising cybersecurity concerns about Anthropic's new model in public since April. Reuters reported on April 14, 2026 that Bailey sees "major cybersecurity risks" in the new model, and the same concern has resurfaced in UK business press coverage through July. The governor's standing position on bank cyber risk is set out in his letter to the Daily Mail.
The argument the TechRadar Pro piece pushes, written by a Smart Communications employee in a personal capacity, is that access to a frontier AI cybersecurity model is not the same as customer trust. Trust, the column argues, depends on whether a bank communicates quickly and plainly when something goes wrong. TechRadar Pro asserts that "over a third of Brits" are now distrustful of their financial providers. The column does not cite the underlying survey, so the number is best read as the outlet's claim rather than a verified fact. The shape of the number fits a trend UK regulators have flagged for years, but a reader should treat it as the column's framing until the survey surfaces.
Anthropic says Glasswing partners have used Mythos to surface more than 10,000 high- or critical-severity flaws in their own code, per the Glasswing expansion page. That 10,000-flaw count measures what the model can do inside a software pipeline. It does not measure what a bank's customers experience when an actual incident hits.
That gap is the story. A bank that flags a problem at 9:00 a.m. and tells its customers at 5:00 p.m. has, in customer terms, the same cyber posture as a bank that did not flag the problem at all. A bank that flags at 9:00 a.m. and texts at 9:04 is operating in a different category, and the model used to do the flagging is downstream of that. Customer trust in financial services is increasingly set by the time between "we know" and "you know," and that interval has nothing to do with which frontier model a bank has access to.
The strongest counterargument is that detection matters on its own. A bank running Claude Mythos across its codebase will surface more flaws and patch them faster than a bank that is not, which is the practical reason the Glasswing partner list is a useful proxy for which institutions are taking frontier tooling seriously. Access is necessary. The case the column makes is that access is not sufficient.
The milestones worth watching are the next Glasswing partner update from Anthropic, the next public statement from the Bank of England on frontier AI risk in financial services, and any UK lender disclosure that names the cyber-focused model it is actually running. The practical question for a UK reader is short: when your bank has a problem, how long before it tells you?