🛡️ On the afternoon of May 15, 2026, the head of Anthropic's global policy team walked into a meeting with Japanese government officials in Tokyo. Hours earlier, Michael Sellitto had told Nikkei the company is "considering" joining a Japanese corporate alliance on cyber defense — the first concrete sign that the framework Tokyo has been quietly building around Anthropic's most capability-restricted AI model to date is close to taking shape.
The trigger is Claude Mythos Preview, a frontier model Anthropic unveiled on April 7 that the company has declined to release publicly because its zero-day-discovery abilities are deemed too useful to attackers. The Japanese answer to the threat is being shaped, almost line for line, after the US precedent: a closed industry consortium that concentrates the AI's defensive value while keeping it out of malicious hands. But beneath the borrowed architecture sits a much older question — whether Japan's distinctive, deliberately light-touch approach to AI governance can hold up when the underlying technology suddenly has national-security weight.
What was actually agreed today
According to Nikkei's Rei Nakafuji, Sellitto — Anthropic's Head of Global Affairs — confirmed in a Tokyo interview that the US AI lab is weighing participation in the consortium proposed by Japan's ruling Liberal Democratic Party. He was scheduled to meet government officials that same afternoon. Anthropic has been looking for partners willing to share the burden of containing Mythos's offensive potential, and the LDP framework is now the most developed non-US venue for that work.
The Japanese consortium is openly modeled on Project Glasswing, Anthropic's own coalition announced on April 7 alongside Mythos itself. Glasswing's twelve launch organizations — Anthropic itself plus Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks — share gated access to Mythos Preview for defensive work, with Anthropic committing up to $100 million in usage credits and another $4 million in donations to open-source security groups. More than 40 additional critical-infrastructure operators have been added since.
What Japan is building looks similar in shape but starts from a different place. None of Glasswing's eleven external launch partners is Japanese. Tokyo is now trying to plug that gap from the demand side.
How Japan got here in eight weeks
The pace has been unusual by Japanese policy standards.
On April 7, Anthropic announced Mythos Preview and Project Glasswing on the same day. Mythos had identified thousands of zero-day vulnerabilities across every major operating system and web browser, including a 27-year-old flaw in OpenBSD that no human reviewer had spotted.
On April 20, the LDP's National Cybersecurity Strategy Headquarters convened a joint session with several related party committees. Representatives from both Anthropic and OpenAI attended. The party put together an emergency proposal calling on the government to upgrade cyber defenses against AI-driven attacks, with explicit reference to financial-sector infrastructure.
On April 26, the same LDP body held a hearing with Anthropic specifically — discussing AI-led autonomous attacks and how to respond. Headquarters chief Masaaki Taira, a former digital minister, told members the goal was to fold the conclusions into Japan's three national security documents and the government's growth strategy.
On May 1, the Ministry of Economy, Trade and Industry summoned executives from 24 critical-infrastructure operators across electricity, gas, oil, chemicals, and credit cards. Economy Minister Akazawa demanded emergency cybersecurity audits within a month.
On May 12, Prime Minister Sanae Takaichi ordered Cybersecurity Minister Hisashi Matsumoto to draft countermeasures during a ministerial gathering. The same day, US Treasury Secretary Scott Bessent — visiting Tokyo — met executives from the three Japanese megabanks. Mythos access was reportedly on the agenda.
On May 14, Taira's LDP headquarters handed Takaichi the finished recommendations. Hours later, the Financial Services Agency convened the inaugural meeting of a 36-organization public-private working group that includes the Bank of Japan, the Tokyo Stock Exchange, Mitsubishi UFJ, Sumitomo Mitsui, Mizuho, Rakuten Bank, and Anthropic's Japan subsidiary.
And today, May 15, Sellitto's interview confirmed Anthropic's interest in joining the consortium itself — not just as an external technology supplier, but as a participant. A separate inter-ministerial meeting on Mythos has been scheduled for May 18.
If the three megabanks complete the access process by month's end as Reuters reported on May 13, they will be the first Japanese companies anywhere to operationally deploy Mythos.
What this says about Japan's AI rulebook
The interesting part is not the speed. It's the legal context.
Japan passed its first comprehensive AI statute — the AI Promotion Act (人工知能関連技術の研究開発及び活用の推進に関する法律) — on May 28, 2025, and brought it fully into force on September 1 the same year. The law does several things that look familiar: it establishes a cabinet-level AI Strategy Headquarters chaired by the prime minister, requires the government to publish a national AI Basic Plan, and lays out broad obligations for developers and users to respect human rights, fairness, and transparency.
What it deliberately does not do is impose penalties. There are no fines. There is no licensing regime. If a company misuses AI in a way that harms public interests, the government can investigate, issue guidance, and — as a last resort — publicly name the offender. That is the entire enforcement toolkit. Smart Governance, the Tokyo think tank where former METI digital policy chief Hiroki Habuka now sits, has described this as Japan's deliberate bet on an "agile" model: write the framework first, fill in details as the technology evolves, avoid locking in rules that the next generation of systems will make absurd.
Compare that to the two ends of the spectrum.
The European Union's AI Act, in full force since August 2024 and applying in phased waves through 2027, takes the opposite stance. It bans certain AI uses outright (social scoring, real-time biometric surveillance in most public contexts), categorizes "high-risk" systems by sector, demands conformity assessments before market entry, and backs the whole structure with fines that can reach 7% of global annual turnover for the most serious violations. The general-purpose-AI obligations that took effect in 2025 force frontier model providers to publish training data summaries, conduct systemic-risk evaluations, and notify the European AI Office of serious incidents. It is, by design, the world's most explicit AI hard law.
The United States under the second Trump administration has gone the other direction. The January 2025 executive order "Removing Barriers to American Leadership in Artificial Intelligence" revoked Biden's earlier AI safety executive order and shifted federal policy toward acceleration. In December 2025, Trump signed a further order designed to preempt state-level AI regulation, particularly California and Colorado's emerging rules. There is no federal AI law. Self-regulation, industry consortia like Glasswing, and procurement leverage are the main governance instruments.
Japan sits in between, but not at the midpoint. Tokyo's approach is closer to Washington in its instinct against penalty-backed regulation, closer to Brussels in its willingness to legislate a national framework at all. Critics call this "soft law plus aspiration." Defenders call it "cooperative governance" — the state, industry, and academic experts working out norms together without the threat of fines hanging over the conversation.
The Mythos case is testing the model in public. Nothing in the AI Promotion Act compels Anthropic to share Mythos with Japanese institutions. Nothing compels Mitsubishi UFJ, SMBC, or Mizuho to participate. Whether the consortium gets built depends entirely on whether the actors involved choose to cooperate — which is exactly what the law was designed to make work.
So far, it appears to be working. But "working" in this case means three megabanks racing to acquire access to a model whose offensive capabilities the developer itself does not fully understand, with Anthropic considering whether to staff a Tokyo-based defensive cyber alliance, all under a legal regime that has no enforcement teeth. That is either an elegant solution or a fragile one. The next six months will say which.
The catch nobody is talking about openly
There is a quieter conversation running underneath the press releases.
When the LDP held its April 20 joint meeting, the party noted publicly that no Japanese company was among Project Glasswing's launch partners. Tokyo was, in effect, watching a defensive AI capability accumulate at the world's largest US tech firms while Japanese critical infrastructure remained outside the loop. Nikkei reported in late April that Japan was "falling behind" the US and UK on Mythos-driven cyber defense.
That framing matters. The LDP consortium is being marketed as a sovereign response — a way to ensure Japanese institutions are not last in line for a technology that could decide whether the next major cyberattack on Japanese banks succeeds or fails. The fact that Anthropic, an American company, is being invited inside as a participant rather than just a supplier is itself a compromise: full sovereignty would mean a Japanese model, which does not exist.
There is also a competition dimension. The University of Chicago's ProMarket published a piece on April 22 questioning whether Project Glasswing — 40-plus companies sharing technical data and "best practices" in a closed circle — could run afoul of US antitrust law. The argument was that information-sharing protocols among dominant firms can suppress competition from outsiders even without explicit price-fixing. The same critique, in principle, applies to a Japanese version. Tokyo has not publicly addressed it.
And there is the practical problem of personnel. Japan's AI Safety Institute (AISI), housed inside IPA, runs on a small staff relative to its mandate. The talent pool for AI security research in Japan is thin. A consortium of 36 organizations can be announced in a press release; staffing it with people who can actually evaluate Mythos-class capabilities is a different matter. The same constraint that has slowed Japanese cyber defense for years has not gone away just because the political urgency has.
What changes from here
The next inflection points are visible on a calendar.
May 18: Cybersecurity Minister Matsumoto's inter-ministerial meeting on Mythos.
Late May: Megabank access to Mythos goes live, contingent on Anthropic's approvals.
Mid-2026: G7 finance ministers and central bank governors are expected to meet in Paris. Japan's Finance Minister Satsuki Katayama has said she will push for AI-misuse risks to be a primary agenda item, with international coordination on safeguards.
Within 2026: Full enforcement of Japan's Active Cyber Defense Law begins. The 2025 statute lets the government take pre-emptive action against threats — including, in extreme cases, neutralizing attacker infrastructure abroad. The consortium that Anthropic is now weighing joining will sit at the intersection of that law and the AI Promotion Act.
The bigger question is whether the world is converging or diverging on AI governance. Brussels remains committed to its rules. Washington has stepped back. Tokyo is trying to thread the needle: get the security benefits of consortium-style cooperation while maintaining the regulatory restraint that Japanese policymakers believe is necessary to attract frontier AI development. Anthropic, with its Tokyo office opened in November 2025 and a President in Hidetoshi Tojo (formerly Snowflake Japan), is the first frontier lab to take that bet seriously enough to staff for it.
If the Mythos consortium works in Japan, Tokyo will have a credible answer to the question Europe and the US have been arguing about for three years: can you govern frontier AI through cooperation rather than command? If it doesn't work — if a bank gets hit despite Mythos access, or if the no-penalty AI Promotion Act fails to prevent a downstream misuse incident — the case for the EU model gets a lot stronger globally.
For now, the calendar is what we have. So is Sellitto, somewhere in central Tokyo this Friday afternoon, in a meeting that nobody has yet released a readout of.
How does your country approach the question of who gets access to dual-use AI — something that could be a powerful defensive tool or a devastating weapon depending on whose hands it ends up in? Is regulation by hard law, by industry consortium, or by something in between the right answer? We'd genuinely like to hear how this debate is unfolding where you live.
References
- Nikkei Asia (May 15, 2026): https://asia.nikkei.com/business/technology/anthropic-weighs-taking-part-in-japan-cyber-defense-alliance
- Nikkei (May 15, 2026): https://www.nikkei.com/article/DGXZQOUC1250L0S6A510C2000000/
- Reuters via Yahoo Finance (May 13, 2026): https://finance.yahoo.com/news/japans-megabanks-set-access-anthropics-040945338.html
- Anthropic, Project Glasswing announcement: https://www.anthropic.com/glasswing
- ITmedia (May 12, 2026): https://www.itmedia.co.jp/aiplus/articles/2605/12/news102.html
- SBBit / FinTech Journal: https://www.sbbit.jp/article/fj/184851
- Smart Governance, "Japan's Agile AI Strategy": https://smart-governance.co.jp/resource/insight-habuka-hiroki-20250805
- ProMarket / Stigler Center: https://www.promarket.org/2026/04/22/the-antitrust-risks-of-anthropics-project-glasswing-and-the-ai-avengers/
- Nippon.com on Active Cyber Defense Law: https://www.nippon.com/ja/in-depth/d01147/
Global Discussion
4 comments