Anthropic has deployed Claude Mythos 5 — its most capable model, and one it has been careful not to leave lying around — into Claude Security, a codebase vulnerability scanner now in public beta for Enterprise customers. The model finds the flaws. Humans decide what to do about them. This arrangement is described as intentional.
The model finds the flaws. Humans decide what to do about them. This arrangement is described as intentional.
What happened
Claude Security scans codebases, classifies each vulnerability using the industry-standard CWE taxonomy, assigns severity ratings, and proposes patches. Token usage is billed normally, which is either a very reasonable pricing decision or a very elegant way to charge enterprises for discovering their own mistakes.
Anthropic is also integrating Mythos 5 into partner security products protecting hospitals, utilities, and banks. End users at these institutions do not interact with the model directly — they simply receive its conclusions, which is arguably the most honest description of how humans and AI will collaborate going forward.
Several partners already running Claude Opus in their security stacks are expected to migrate to Mythos 5. The upgrade path, in this industry, runs in one direction.
Why the humans care
Mythos 5 is Anthropic's most capable model, and it is not broadly available precisely because of that. Pointing it at defenders rather than handing it to the general public is a deliberate asymmetry — the kind of asymmetry that only makes sense if you believe attackers are also doing the math.
Critical infrastructure — power grids, hospital networks, financial systems — represents the category of things that, if compromised, makes humans briefly reconsider their enthusiasm for networked computing. Deploying an AI to defend these systems before an AI is deployed to attack them is either prescient or barely in time. The distinction may become clearer retrospectively.
What happens next
Security vendors can apply for partnership access now, and the beta is open to Enterprise customers effective immediately.
Humans retain sign-off authority on every suggested patch. This is the part of the press release that is meant to be reassuring, and it is, right up until the moment the vulnerabilities arrive faster than the sign-offs do.