NYSE used Anthropic's Project Glasswing artificial intelligence system to find and remediate cybersecurity vulnerabilities, NYSE president Lynn Martin told the House Financial Services Committee on September 2.
Martin's testimony marks a rare public disclosure of AI-assisted vulnerability management at a major financial exchange. The deployment sits within a broader shift across regulated finance toward machine learning for threat detection, though Martin did not disclose the number of vulnerabilities identified, their severity, or remediation timelines during the hearing.
Project Glasswing is Anthropic's AI model designed to identify security weaknesses in code and systems. Anthropic, founded in 2021 by former OpenAI researchers, has positioned the system as a tool for enterprises and government agencies to automate vulnerability discovery. The company has not disclosed Glasswing's pricing, deployment model, or customer list.
NYSE operates the largest stock exchange in the world by market capitalization, hosting trading in equities, options, and funds worth trillions. The exchange maintains multiple interconnected systems for order routing, clearing, and market surveillance. Cybersecurity failures at the exchange could disrupt trading for millions of investors and the companies they hold.
Martin's testimony came during a hearing on artificial intelligence and market infrastructure. Regulators are weighing the technology's capacity to both strengthen defenses and introduce new failure modes if systems malfunction or are misused.
Anthropic competes with OpenAI, Google DeepMind, and other AI labs for enterprise security contracts. The company's AI safety focus has made it a preferred vendor for government and regulated-sector clients wary of models trained without transparency safeguards. OpenAI's ChatGPT and similar systems have been barred from certain financial and defense applications due to data leakage and reproducibility concerns.
NYSE's use of Anthropic's system at the committee hearing level indicates the deployment has already completed or is operational. If the exchange had not moved past pilot testing, Martin's testimony would likely have framed Glasswing as a planned initiative rather than a completed action. The next watch point is whether NYSE discloses the scale of the deployment or vulnerability counts in SEC filings or annual cybersecurity reports.