Advanced Cyber Tools Are Becoming Available to Companies Without Big Security Teams

Anthropic’s Project Glasswing showed that frontier AI models can be used defensively to scan large codebases and identify software vulnerabilities at a scale that would be difficult for traditional security teams to match. The initiative brought together major technology and infrastructure partners, gave defenders early access to Claude Mythos Preview, and focused on finding and fixing weaknesses in critical software before attackers can exploit them.
For ordinary businesses, the point is not that every company will run a frontier security model internally. The point is that expectations are changing. If AI can help security teams inspect code, trace vulnerable patterns, generate structured findings, and accelerate triage, then software vendors can no longer treat deep code review as a luxury reserved for large enterprises. Even a mid-sized retailer, importer, clinic, manufacturer, or services company depends on software that can carry serious risk.
The new cybersecurity question for business owners is not whether they write code. It is whether the code they depend on has been checked, fixed, and verified.
Why This Matters to Non-Software Companies
A company may not think of itself as a software company, but its operations usually tell a different story. Sales may depend on an ecommerce site. Customer experience may depend on an app. Finance and inventory may depend on an ERP system. Suppliers may connect through a portal. Customers may use loyalty accounts. Partners may connect through APIs. A custom system built years ago by an external developer may still sit quietly at the center of the business.
The Vendor Accountability Shift
Project Glasswing also changes how business owners should speak with software vendors. A vendor can no longer rely on a vague statement that “security is important to us.” If AI-assisted vulnerability discovery is becoming part of the modern defensive toolkit, then customers should ask whether the vendor uses code scanning, dependency analysis, remediation workflows, and human review to turn findings into real fixes.

That last point is critical. AI can produce a large number of findings, but not every finding is equally important, exploitable, or correctly classified. The business should not accept a raw AI report as proof of security. It should ask for evidence that findings were reviewed, prioritized, remediated, tested, and closed. Discovery is useful only when it becomes verified risk reduction.
If a vulnerability is found in the software your business depends on, do you know who must fix it, how fast, and how they prove the fix worked?
What Businesses Should Demand from Software Vendors
The practical response is to make software security part of vendor management. A business does not need to become a cyber research lab, but it does need better questions, stronger contracts, and evidence that its vendors are using modern security practices. If a supplier builds, hosts, customizes, or integrates business-critical software, security review should be part of the service, not a favor requested after an incident.
For business owners, the goal is not to demand perfect security. Perfect security does not exist. The goal is to make security visible, contractual, and reviewable. A vendor should be able to explain what was scanned, what was found, what was fixed, what remains open, and who accepted the residual risk. If the answer is only “our AI tool checked it,” the answer is not enough.
DNLA Playbook for Vendor Cyber Accountability
- Inventory critical software. List every ecommerce site, app, ERP customization, supplier portal, loyalty system, API, and custom-built workflow the business depends on.
- Classify vendor risk. Prioritize systems that touch payments, customer data, employee data, financial records, supplier access, or operational continuity.
- Ask for scanning evidence. Require proof of code scanning, dependency review, and remediation activity, not only a policy statement.
- Define response times. Put vulnerability response commitments into contracts or service-level agreements.
- Demand third-party visibility. Ask vendors to report major libraries, components, plugins, and external services used in the solution.
- Require human review of AI findings. AI can accelerate discovery, but qualified professionals must validate severity, exploitability, fixes, and closure.
DNLA Take
Project Glasswing is a signal that advanced defensive AI is moving from research novelty toward practical security operations. That matters far beyond technology companies. Ordinary businesses rely on software every day, even when they do not write code themselves. The ecommerce site, app, ERP system, supplier interface, loyalty platform, API, and custom workflow all carry risk. As AI makes vulnerability discovery faster, business owners should raise expectations for their vendors: scan the code, fix the weaknesses, document third-party components, commit to response times, and prove that AI-generated findings were checked by humans. In the next phase of cybersecurity, trust will not come from a vendor saying “we are secure.” It will come from evidence that the software was inspected, remediated, and verified.
Want the same rigor applied to your own AI system?
That's what a QAi Health Check is for.