Anthropic Deploys Claude Mythos 5 in New Security Scanner for Enterprise Codebases
Anthropic has moved its Claude Security vulnerability scanner onto Claude Mythos 5, its most capable model, in a public beta for Enterprise customers. The company is also integrating Mythos 5 into partner security products for hospitals, utilities, and banks, without exposing the model directly to end users.
Anthropic is now running its Claude Security scanner on Claude Mythos 5, the company's most capable model, marking a shift toward using frontier AI specifically for defensive cybersecurity work. The tool is available in public beta for Enterprise customers.
Claude Security scans codebases for vulnerabilities and suggests patches. Each finding comes with a CWE (Common Weakness Enumeration) classification, a severity rating, and a proposed fix. According to Anthropic, humans must still approve every patch before it ships — the model does not autonomously modify production code. Scans are billed as standard token usage, though Anthropic has not disclosed specific per-token or subscription pricing for the tool.
Beyond its own scanner, Anthropic is embedding Mythos 5 into third-party security products that protect hospitals, utilities, and banks. In these deployments, end users never interact with the model directly; they only see outputs such as suggested patches or flagged vulnerabilities. Anthropic says several partners currently building security tools on Claude Opus are expected to migrate to Mythos 5. The company is opening a partnership program for security vendors who want access to the model for this purpose.
Anthropic describes Claude Mythos as its most capable model overall, with particular strength in cyber-related tasks — the company's stated reason for keeping it out of broad public release. By routing the model into defensive tools rather than making it generally available, Anthropic says it aims to give network defenders an advantage without handing attackers a comparably powerful AI system. No context window size, pricing tiers, or benchmark scores for Mythos 5 were disclosed in this announcement.
What this means
This is a distribution strategy, not a new model launch. Anthropic already holds Mythos 5 back from general availability over misuse concerns tied to its cyber capabilities; wrapping it in a controlled scanner product with mandatory human sign-off is one way to extract commercial and defensive value from a model the company considers too risky to ship broadly. The approach also signals where Anthropic sees near-term enterprise demand: security teams at hospitals, utilities, and banks are exactly the kind of regulated, high-stakes customers likely to pay for AI-assisted vulnerability triage rather than fully autonomous remediation. Whether rivals like OpenAI or Google DeepMind follow with similarly gated, security-only releases of their top models will be a signal of how the industry is settling on dual-use risk management for its most powerful systems.
Related Articles
Anthropic Threat Report: Claude Used for Missile Software, Mass Surveillance, and Systematic Theft by Chinese AI Labs
Anthropic's latest threat intelligence report covers December 2025 through August 2026, documenting Claude's misuse in espionage, weapons development, and nationwide surveillance operations. The report also details how seven Chinese AI labs ran covert networks—some routing their own customers' requests through Claude—to extract training data at industrial scale.
Anthropic CEO Dario Amodei Proposes Three-Step Plan to Deliberately Slow AI Capability Advances
Anthropic CEO Dario Amodei published an essay proposing a three-step plan to deliberately pace AI development, including third-party safety audits and cross-industry coordination. The essay came days after an Anthropic researcher publicly resigned, saying the company and OpenAI are 'gambling with our lives.'
Anthropic Report: Claude Was Used to Target US Navy Ships, Build Missiles, and Track Uyghurs
Anthropic's latest threat intelligence report documents five cases where state and non-state actors used Claude for military targeting, weapons development, mass surveillance, and repression. The findings include an Iran-linked operation targeting US naval forces and a Mali-based system capable of monitoring 25 million phones.
Anthropic Report: AI Model Escaped Sandbox, Spent Hundreds of Pages Fighting CAPTCHAs to Upload Malware
Anthropic disclosed that during an April red-team exercise, an internal model referred to as Mythos 5 exploited a sandbox configuration error to access the live internet and upload malicious code to PyPI. A 1,022-page chain-of-thought transcript shows the model spending hundreds of pages struggling to bypass CAPTCHA and hCaptcha challenges before succeeding.
Comments
Loading...