Three Labs, Same Instinct, Two Weeks: Anthropic Widens Access to Its Most Capable Cyber Model | Vulnerabilities.ai™ Research
← Research
August 22, 2026 · AI-Discovered Vulnerabilities
AI-Discovered Vulnerability Response

Three Labs, Same Instinct, Two Weeks: Anthropic Widens Access to Its Most Capable Cyber Model

Reads alongside our briefs on OpenAI's Daybreak restructuring and CrowdStrike's QuiltWorks SMB expansion.

On August 21, Anthropic announced a significant expansion of who gets to use Claude Mythos 5's cybersecurity capabilities — moving well beyond the small, hand-selected cohort Project Glasswing launched with in April. It's the third time in under two weeks that a major AI or security vendor has made essentially this same move: give more defenders access to frontier-level cyber capability, while trying to keep that capability away from attackers. OpenAI restructured Daybreak into two access tiers on August 10. CrowdStrike extended Project QuiltWorks down-market to SMBs on August 13. Now Anthropic is doing its version.

What Anthropic actually announced

Four concrete changes. First, Claude Security — Anthropic's code-scanning product — now runs on Mythos 5 for Claude Enterprise customers in public beta, scanning codebases for vulnerabilities and returning findings with CWE categorization, confidence and severity ratings, and a suggested fix for human review. Critically, the user never interacts with Mythos directly; they receive only the scan output, with every suggested patch requiring human approval before implementation — the same "output-only access" design philosophy Anthropic used with Fable 5's dual-use-blocked general release.

Second, Anthropic is launching the Defender Advantage Fund (0xDAF), committing $35 million in Claude credits to organizations helping open-source maintainers patch live vulnerabilities, automate scanning and patching, and build more fundamentally attack-resistant systems. This builds on the $4 million in direct donations and infrastructure support Glasswing already provided to open-source security organizations, including Akrites and Gold Eagle.

Third, the Cyber Verification Program — which currently gives vetted defenders reduced safeguards on Opus and Sonnet — is expanding to include Mythos-class access, extending the same "trusted access" model that already governs Daybreak Red and QuiltWorks to Anthropic's most capable model specifically.

Fourth, Anthropic is working with cybersecurity technology and services partners to integrate Mythos 5 directly into the security products defenders already use — building on prior work putting Opus into partners' cyber tools — rather than requiring defenders to adopt a new, separate interface.

Why the "output-only access" design is worth taking seriously as its own approach

Anthropic's framing is explicit about the tradeoff it's managing: direct model access is the riskiest configuration, since a malicious actor with a prompt box can try to steer a capable model toward harmful uses, while a user who can only receive a specific, bounded artifact — a patch, a scan finding, a security alert — represents much lower risk regardless of how capable the underlying model is. This is a meaningfully different access philosophy than either OpenAI's Daybreak Red (direct, tiered-vetting model access) or CrowdStrike's QuiltWorks (full-stack product bundling). Anthropic is betting that capability can be made broadly useful without being broadly accessible, by controlling the interface rather than primarily the audience.

Why three separate companies making this move in two weeks is the real story

None of these three moves happened in coordination, as far as any public account indicates — but the shared instinct is too consistent to ignore. Each is responding to the same underlying pressure this site has tracked all month: AI-discovered and AI-exploited vulnerabilities are accelerating faster than most defenders' access to comparable AI-assisted defense, and the labs and vendors sitting on the most capable models are each concluding, independently, that keeping that capability narrowly held is no longer defensible given the shape of the threat. Whether output-gating, tiered vetting, or full-stack bundling turns out to be the more durable access model — or whether some combination becomes standard — is the open question these three moves leave for the industry to answer over the coming months.

Sources
Verified Anthropic, "Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders," claude.com/blog, August 21, 2026.
Verified Anthropic, "Claude Fable 5 · Claude Mythos 5," anthropic.com/news, referenced for background on the output-gating precedent.
This brief synthesizes and cross-verifies publicly available primary and secondary sources, listed above. It is independent analysis, not first-party research.