Why Epic joined Anthropic’s Project Glasswing

Advertisement

Epic used its Users Group Meeting executive address this week to confirm publicly for the first time that it’s participating in Project Glasswing, Anthropic’s effort to test its most capable — and still unreleased — AI model against critical software before that capability spreads to attackers.

Anthropic launched Project Glasswing in April after deciding not to publicly release Claude Mythos, an AI model capable of autonomously finding and exploiting decades-old cybersecurity vulnerabilities.

The program initially included about 50 partners, mostly major tech and cybersecurity firms, before expanding in June to roughly 150 more organizations spanning industries including healthcare. Anthropic has not disclosed the identities of most participants, citing security concerns, though it has said organizations are free to share their own involvement.

Epic’s revelation came during a security-focused portion of its Aug. 18 keynote, which also touched on new AI tools, smaller-organization product tiers and rural health expansions. Epic Chief Security Officer Stirling Martin told UGM attendees in Verona, Wis., that the AI arms race in cybersecurity accelerated this year as tools such as Anthropic’s Claude Code grew capable of reasoning across large codebases and surfacing security flaws that had gone undetected for years.

“In April, Anthropic announced a program called Glasswing and Mythos, an AI model so capable that they’ve limited access to a small number of critical providers,” Mr. Martin said. “We’ve not talked publicly about it before. I’m happy to share that we’ve been a participant in [Glasswing] and heavy users of Mythos.”

Epic has since pointed the models at its own codebase, which spans several hundred million lines, and said the AI surfaced issues its own expert developers had missed.

“In each successive model, the AI gets better and better at finding potential vulnerabilities, and at stringing unrelated issues together into a novel attack path,” Mr. Martin said. “These are not obvious issues, but the nuanced interplay between unrelated parts of the software.”

That means Epic customers should brace for more frequent, and less predictable, security updates, he said.

“Your teams should continue to expect to see a higher than usual number of urgent security fixes from us as we do,” Mr. Martin said. “We’re moving fast because speed is the whole game now, and these tools have given us a head start.”

Mr. Martin also put the burden back on health systems’ other software vendors, telling the audience of IT executives that the same forces are pushing patch volumes up across the industry.

“So here’s a question worth asking,” he said. “If one of your vendors isn’t shipping more updates than they used to, why not? In this new world, the status quo is not a good sign.”

He added: “The old goal of patching within 30 days — that’s no longer good enough.”

Seth Howard, Epic’s executive vice president of research and development, referenced his company’s work with Anthropic later in the session, telling attendees AI has become embedded across the company’s own operations, not just its cybersecurity work.

“This morning, you heard about how we use Mythos and other models to improve security,” Mr. Howard said, adding that Epic’s own engineers now lean on AI coding tools — including Anthropic’s Claude Code and OpenAI’s Codex — to build product faster.

Health system CIOs have been pushing to be included in Project Glasswing, arguing that healthcare’s mix of legacy systems, long patching cycles and thin margins makes it especially exposed to AI-accelerated attacks.

Speaking with Becker’s on the sidelines of UGM, Sha Edathumparampil, chief digital and information officer of Coral Gables, Fla.-based Baptist Health South Florida, said Epic’s AI roadmap overall impressed him, but singled out the security update as one of three things that stood out from this year’s conference.

“The third piece I’m excited about is all the focus on cybersecurity,” he said. He pointed to Epic’s improved patching frequency and said the company has begun giving hospitals that host their own Epic systems specific guidance to help them accelerate their own patching schedules.

Epic’s disclosure is a rare instance of a health IT vendor or healthcare-focused company confirming its own participation in Glasswing — a level of specificity Anthropic itself has largely avoided providing on participants’ behalf.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Innovation

Advertisement