Delinea has joined Project Glasswing, Anthropic’s programme that puts unreleased frontier AI to work on critical software. The identity-security company is testing Claude Mythos 5.1 against its own vaulting, secrets-handling and session-brokering code. Announced 17 September from San Francisco, the news reached Indian inboxes on 22 September bearing a Bangalore dateline. Both datelines describe the same modest fact: a PAM vendor pointing a powerful model at its own code.
The context around that fact is less modest. Project Glasswing has become the most consequential defensive-AI programme in the industry, and Delinea has the most to prove among its security-vendor members.
Why the Project Glasswing News Arrived Now
Four threads explain the timing.
A vendor onboarding wave
Delinea is not an outlier; it is a pattern. Sophos joined Glasswing in July, testing Claude Mythos 5 on its own code. Tanium announced its participation on 14 September. Delinea followed on the 17th.
Anthropic spent June expanding Glasswing from roughly 50 to about 200 organisations across more than 15 countries, adding power, water, healthcare and hardware players. Security vendors are simply the newest cohort — and each joins with a press release in hand.
The biggest PAM asset left standing
Palo Alto Networks closed its $25 billion acquisition of CyberArk in February 2026, the largest pure identity-security deal on record. That transaction removed the PAM category leader from the independent market and re-rated every remaining asset upward. Analysts now describe TPG-backed Delinea, with ARR above $400 million, as a prime IPO or strategic-sale candidate for late 2026. A frontier-AI security badge reads well in both an IPO prospectus and a sales deck.
The StrongDM integration is live
Delinea closed its acquisition of StrongDM in March, adding just-in-time runtime authorisation aimed at developers and AI agents. The company now pitches itself as the platform that governs “what AI agents, humans and machines can do once they have access”. Testing Mythos on the code that brokers that access is the logical next beat of the same story.
A five-day-old announcement, re-datelined
The original release carries a San Francisco dateline of 17 September. The Indian distribution arrived five days later with a Bangalore dateline. Localisation is standard PR practice. It also shows how a global announcement is resold market by market — in this case to Indian media, in a country Glasswing’s June expansion reportedly reached.
The Competitive Picture Behind Project Glasswing Membership
Glasswing’s own launch partners included Anthropic’s fiercest rivals: AWS, Apple, Google, Microsoft, NVIDIA. Palo Alto Networks — which now owns Delinea’s chief competitor, CyberArk — is a founding member too. So Delinea’s badge arrives in a cohort where its biggest threat sits at the same table.
The frontier labs are also courting security vendors in parallel. Sophos joined Glasswing in July and OpenAI’s Daybreak Cyber Partner Program in June. Delinea’s release mentions only Anthropic, but multi-lab participation is becoming the norm. For the labs, security vendors supply credibility and findings; for the vendors, early model access is a differentiator sales teams can quote. Neither side discloses commercial terms.
What the Data Shows About Project Glasswing and Delinea
The programme’s numbers and the gaps both deserve attention.
What Glasswing has actually found
Anthropic says the first cohort found more than 10,000 high- or critical-severity vulnerabilities in roughly two months of scanning. Named examples include a 27-year-old OpenBSD flaw, a 16-year-old FFmpeg bug and a FreeBSD remote-code-execution issue tracked as CVE-2026-4747. Mythos-class models found flaws in every major operating system and browser. One caveat matters: the 10,000 figure is self-reported by Anthropic and its partners, with no independent audit.
What Delinea has actually found
Nothing, so far as any public record shows. The release describes scope — vaulting logic, key management, session brokering, just-in-time authorisation paths — and process, but zero findings, zero metrics and zero timeline. That is normal for a programme that just started. It also means the announcement’s substance is a promise, not a result.
The market backdrop
Gartner pegs global identity-and-access-management spending at $24.3 billion for 2026, up about 15%. Machine identities outnumber human ones by more than 80 to 1, and AI-agent identity has become the fastest-growing slice of the market. Private AI-agent identity platforms command 15 to 30 times revenue in funding rounds — the highest ceiling in identity. Delinea’s Glasswing positioning sits directly on that premium.
What’s New vs. What’s Repackaged
New: Delinea’s membership, and the specific admission that authorization logic — not just memory safety — is now frontier-model territory. Repackaged: nearly everything else. Coordinated disclosure commitments and a security-advisories channel are standard practice. Feeding findings back into secure-coding standards and pre-merge checks is what mature SDLCs already do.
Even the CISO’s elegant framing — treat the model like a privileged identity, scoped, temporary and logged — is Delinea’s own product pitch turned inward. It is good marketing precisely because it reuses the company’s one true differentiator.
The Question the Press Release Doesn’t Answer
What has Mythos found in Delinea’s code — and when will anyone know? The release promises disclosure through existing channels but cites nothing yet. Nor does it say how admission to Glasswing works: Anthropic has published no criteria, no roster and no audit standard, so “member” is an unverifiable claim. And a sharper question sits underneath: does the badge change what buyers should expect from Delinea’s products, or only from its press releases? Until findings appear, the honest answer is the latter.
What the Project Glasswing Membership Means for You
If you run identity and access management, this news does not change your shortlist. But ask Delinea — and every PAM vendor — how they use frontier models internally, and whether findings surface in advisories you can subscribe to. That is the test of substance.
If you are a security vendor watching from outside, note that Glasswing membership is becoming table stakes among large vendors. Anthropic plans a Cyber Verification Program to widen access. Start preparing your disclosure pipeline now; a flood of AI-found vulnerabilities is already straining the 90-day norm.
If you follow identity-sector M&A or IPOs, this is positioning. Delinea carries TPG ownership, an IPO window, a fresh StrongDM integration and now a frontier-AI badge. The CyberArk sale made every remaining independent PAM asset strategic. Watch Delinea’s next filing or term sheet for what the badge was really for.

Editor’s Note
This article draws on Delinea‘s press release of 17 September 2026 and its Indian distribution of 22 September, Anthropic’s Glasswing announcements of April and June 2026, Sophos and Tanium’s Glasswing participation announcements, Palo Alto Networks’ CyberArk acquisition releases, and identity-sector market analysis from Gartner-cited estimates and Windsor Drake Research. Glasswing findings figures are self-reported and unaudited. Nothing here is investment advice.

