Blog

Claude Mythos 5 Now Powers Claude Security: What It Means for AU Cyber Defence Teams

August 2026 · 6 min read · Technical

A shield with a terracotta seal at its centre, flanked by lines of code being scanned
← Back to all posts

Anthropic has started rolling its most capable model, Claude Mythos 5, into Claude Security rather than releasing it broadly to anyone with an API key. Customers on Claude Enterprise plans can now run Mythos 5 inside Claude Security to scan codebases for vulnerabilities and suggest patches. That tier of capability was previously reserved for a small group of vetted defenders under Anthropic's Project Glasswing.

The announcement will get read as a product update. It is more useful read as a statement about how frontier capability gets distributed, because that is the part an Australian business actually has to make a decision about.

What changed, in three lines

  • Claude Mythos 5 is now live inside Claude Security for Claude Enterprise customers, for codebase scanning and patch suggestions rather than open-ended prompting.

  • A new $35 million Defender Advantage Fund will pay for open-source vulnerability patching and scanning automation.

  • The Cyber Verification Program, which today gives vetted defenders reduced safeguards on Opus and Sonnet, is expanding toward Mythos-class access over time.

The access model is the actual news

Anthropic's reasoning is worth restating plainly, because it is the logic a security buyer should be applying too. Direct model access is the riskiest way to hand out frontier capability. Give someone an unrestricted channel to the most capable model available and a determined actor can spend as long as they like steering it toward offensive use. Give them a specific output instead, a patch suggestion or a vulnerability alert scoped to a codebase they already own, and the same capability carries far less risk of being turned around.

That is a design decision, not a marketing one, and vendors are landing on different sides of it. A vendor that hands every paying customer direct, unrestricted access to its most capable model has made one set of trade-offs. A vendor that gates frontier capability behind outputs, verification programs and partner integrations has made another. For a business building a security program on top of one of them, the second is usually the safer foundation, because the thing you are relying on is harder for someone else to repurpose against you.

Three questions worth asking any AI security vendor

If your team is assessing an AI tool for anything security-adjacent, code scanning, incident triage, log analysis, vulnerability patching, the useful diligence is not benchmark scores. It is these:

  • What tier of model am I actually getting? Vendors routinely market a frontier model and serve a smaller, cheaper one for most requests. Get it in writing.

  • What gates access to anything more capable, and who decides? A verification program, a partner tier and a sales conversation are three very different gates with three different failure modes.

  • What happens when that gate changes? Capability that arrives via a program can leave via one too. Ask what notice you get and what your fallback is.

A fourth question matters specifically in Australia: where does the analysis run, and what leaves the country. If the tool is scanning a codebase that contains customer records, the Privacy Act obligations sit with you regardless of which vendor's model did the scanning. Sydney and Melbourne businesses in regulated sectors should be asking this before procurement, not during an incident.

What this does not mean

Two things worth not concluding from this announcement. First, gated access is not the same as safe. A well-governed vendor with a poor integration into your workflow will still leave gaps, and the model tier is only one input into whether a security program works. Second, this is not an argument that open-weight models have no place in a security stack. Plenty of AU teams run smaller open models locally for log triage and pattern matching precisely because nothing leaves their own infrastructure, and that is a defensible call for the right workload.

  • Gated frontier access reduces one specific risk, capability being repurposed offensively. It does nothing about misconfiguration, alert fatigue or a team too small to action what the tool finds.

  • The $35 million fund is aimed at open-source maintainers, not at your business. Useful for the ecosystem, not a line item in your security budget.

  • Access tiers change. Any architecture that only works if you keep a particular model tier is a fragile architecture.

The businesses that get the most out of a tool like Claude Security tend to be the ones that scoped the workflow first and the model second: who reads the findings, what the remediation path looks like, what gets auto-patched versus escalated, and how the audit trail holds up if a regulator asks. The model tier is a real input to that, but it is not the design.

Automata AI works through this kind of vendor diligence with Sydney and Australian mid-market businesses as part of scoping a Claude Security or Claude Code rollout, including the access-model questions above and the Privacy Act implications of what gets scanned. If you are partway through a procurement and want a second read on it, book a session.

Ready to move from AI pilot to production?

We help mid-market Australian businesses deploy AI automations that actually reach production and deliver measurable ROI.