Anthropic Opens Its Most Powerful AI to More Security Defenders and Puts $35 Million Behind Open-Source Safety

The company behind the Claude AI system is carefully widening access to its strongest models for cybersecurity work, while keeping ordinary users and criminals locked out.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
A security researcher at a computer workstation examines threat data on multiple monitors displaying code and threat intelligence dashboards, with a badge or cr
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Anthropic is giving vetted cybersecurity teams access to Claude Mythos 5, its most capable AI model, through controlled partner tools rather than direct access.
  • A new $35 million fund called the Defender Advantage Fund (0xDAF) will distribute computing credits to organisations protecting open-source software.
  • Claude Security, a code-scanning tool for Enterprise customers currently in public beta, now runs on Mythos 5 and flags weaknesses with confidence scores, severity ratings and suggested fixes.
  • Anthropic's Cyber Verification Program, which relaxes some AI restrictions for authorised security professionals, will expand its permissions in the coming weeks.
  • The company says the riskiest scenario is giving anyone unrestricted access to a powerful AI; its strategy is to return only specific, useful outputs instead.

Anthropics's Claude AI system is not one thing. It is a family of models at different power levels, and the company has spent months deciding who gets to touch the strongest ones.

What is Anthropic actually doing here?

Defenders, meaning the security professionals who find and fix flaws before criminals exploit them, are getting broader access to Mythos 5, Anthropic's most capable model. They won't talk to it directly.

Instead, security tools built by Anthropic's partners run Mythos 5 quietly in the background and hand back a specific, limited result: suggested patches or a flagged piece of risky code. The criminal sitting at home can't replicate that by signing up for an account, because the model itself is never exposed. Only the answer comes out.

This follows Project Glasswing, launched in April, which gave a small group of organisations early access to Mythos-class models so defenders could find and fix vulnerabilities before comparable capabilities spread more widely.

Anthropics calls this the key insight behind everything it announced. Unrestricted access to a powerful AI is dangerous. Receiving a narrowly defined output from that same AI is far less so.

Who benefits, and how?

Four groups stand to gain from the changes announced this week.

Beneficiary What they get Detail
Security operations teams Mythos 5 embedded in existing tools Covers hospitals, utilities, financial systems, software supply chains
Claude Enterprise customers Upgraded Claude Security code scanner Finds weaknesses by CWE category (a standard classification of software flaw types), with confidence scores, severity ratings and fix suggestions
Open-source maintainers $35 million in computing credits via 0xDAF Grants target live vulnerability fixes and reusable scanning processes
Vetted security researchers Expanded Cyber Verification Program Broader permissions on Claude Opus and Sonnet models, Mythos access to follow

The Claude Security scanner is worth pausing on. It reads code a company owns, flags each problem with a confidence score and a suggested repair, then stops. A human must review and approve any fix before it goes anywhere near live systems. The model never produces raw, unchecked output someone could redirect.

Should ordinary people care about any of this?

Most people will never touch these tools. The direct effect lands on IT and security teams.

The institutions those teams protect, hospitals, utilities, financial firms, serve everyone, though. Faster detection of software flaws in critical systems means fewer incidents that expose patient records or freeze accounts. That trickle-down is real, even if it's slow.

For anyone working at an organisation with a security team: your colleagues may soon rely on AI-assisted scanning powered by models like Mythos 5. That's worth knowing when your IT department pushes an urgent software update. The judgement behind that request may have started with an AI spotting the flaw first. Our 17 August story on Anthropic's competing AI agents showed what can go wrong when these models operate without clear constraints, which makes the deliberate scoping of outputs here the detail that actually matters.

The Cyber Verification Program is currently accepting applications from security professionals who want reduced AI restrictions for legitimate research work. Anthropic says further rollout details are coming in the next few weeks.

© 2026 Threat Vectr