Release2026-08-21

Anthropic has turned on code scanning with its strongest cybersecurity model, Mythos 5, inside Claude Security and in partner defensive products, giving users the findings and suggested fixes rather than access to the model itself. Scans return flaws tagged by category, severity and confidence, and every fix must be approved by a person before it is applied. The company is also putting $35mn of usage credits into a fund for open-source security work, three weeks before EU vulnerability reporting duties begin.

What changed

Mythos 5 was held back from broad access, with security teams unable to use it for code scanning.

What it unlocks

Enterprise customers can scan a code repository with Anthropic's strongest security model and get ranked findings with suggested fixes, billed as normal usage.

  • $35mn in credits for open-source security
  • CRA reporting starts 11 September
  • 10,000 critical flaws found in a month

What you need to act on it

  • Anthropic enterprise account
  • human review and approval of every patch
  • access via Claude Security or a partner product rather than the model itself

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.