The parties also intend to exchange information, best practices and governance frameworks. That can help connect technical testing with operational decisions: which risks should be tested, what thresholds should apply, who can access a model and what should happen when a serious weakness is found.
This is a broader approach than benchmarking model capability alone. A model can perform impressively on a benchmark and still be unsuitable for a public-service or infrastructure setting if its access permissions, monitoring, disclosure procedures or human-oversight arrangements are inadequate.
The MOU’s third focus is exploring policy approaches for trusted access to frontier models. The underlying idea is controlled availability: highly capable systems should be accessible for legitimate testing and useful work, but not exposed without safeguards appropriate to their capabilities and risks.
The agreement therefore points toward a layered model of AI safety: test the system, share what is learned, restrict access where necessary and use governance rules to define accountability.
Anthropic’s Claude Mythos Preview provides a useful example of the dual-use problem facing frontier AI. Anthropic says that it and approximately 50 Project Glasswing partners used the restricted model to identify more than 10,000 high- or critical-severity vulnerabilities in systemically important software. It also reported that Mythos could identify and exploit vulnerabilities, including zero-days, in major operating systems and browsers.
That capability could support defensive security by helping researchers find flaws before criminals do. The same capability could also shorten the path from vulnerability discovery to exploitation if it were broadly released or poorly controlled. This is why Anthropic kept Mythos behind restricted access through Project Glasswing rather than making it publicly available.
However, the available evidence does not establish that Claude Mythos specifically caused or prompted the June 12 Singapore–Microsoft MOU. Mythos is better treated as an example of the rapidly changing risk environment that makes structured evaluation, controlled access and governance frameworks increasingly important.
Project Glasswing’s limited-access model is itself a risk-management measure. Anthropic gave a defined group of partners access for defensive work rather than releasing the model broadly. That approach limits exposure while allowing security teams to study what the system can do.
Restricted access is not a complete safety system: it depends on vetting, monitoring, secure handling and responsible disclosure. But it demonstrates the principle behind the MOU’s trusted-access work—access should reflect capability and risk, rather than treating every frontier model as an ordinary public software release.
Finding a flaw is only the first step. Singapore’s Cyber Security Agency has advised organizations to patch critical and high-severity vulnerabilities, enable multi-factor authentication across interfaces and gateways, and review unnecessary access rights. Those measures reduce the opportunity for attackers to exploit weaknesses while organizations investigate and fix them.
The available evidence also argues against presenting the roughly 10,000 Mythos findings as broadly remediated. One later assessment reported 1,596 disclosures to maintainers but only 97 fixes. That does not mean the project produced no defensive benefit, but it does mean claims that “many” of the findings were fixed should be treated cautiously.
The lesson is operational as much as technical: AI safety requires a process for identifying risks, disclosing them responsibly, prioritizing repairs and reducing exposure while remediation is incomplete.
Microsoft brings experience in frontier-model development, enterprise infrastructure and the operational side of evaluating and controlling access to AI systems. The MOU’s stated scope, however, is broader than a single Microsoft model: it concerns approaches to safety testing and trusted access for frontier models generally.
The supplied evidence does not substantiate several more specific claims as formal parts of this agreement, including claims about Microsoft’s MAI model, Azure AI Foundry access to OpenAI and Anthropic models, or comparable arrangements with the UK AI Security Institute and the US Centre for AI Standards and Innovation. Those details should not be presented as commitments made under the Singapore–Microsoft MOU.
Taken together, the agreement’s components form a practical safety chain:
That is the significance of the MOU. It does not make frontier AI safe by itself, and it does not resolve the risks illustrated by Claude Mythos. Instead, it links technical evaluation with access governance and cybersecurity practice—an approach intended to make advanced AI more safe, secure, reliable and accountable before capability is mistaken for readiness.