Anthropic said on 21 August that customers on Claude Enterprise plans can now run Claude Mythos 5 — the model it has kept behind its tightest cyber gating — inside Claude Security, scanning their codebases for vulnerabilities and suggesting patches. Alongside it the company announced a $35 million Defender Advantage Fund and an expanded Cyber Verification Program. In April, the same model class went out to a small group under Project Glasswing; the allowlist has now become a plan tier.

What actually shipped

Claude Security is in public beta, restricted to Claude Enterprise — not Pro, Max or Team. An Enterprise admin enables it in the admin console; from there a user selects a repository and receives findings with severity ratings and suggested patches for human review. Partner integrations are described as early stage, with defenders seeing patches and alerts rather than the model itself.

What the common framing gets wrong

Headlines read as though Anthropic handed its most dangerous model to customers. It did not. What shipped is a product surface: a scan that returns a report. There is no prompt box, so a customer cannot steer Mythos 5 at anything — and that constraint is the safety story, not an afterthought. Direct Mythos-class access under the Cyber Verification Program is still gated; the capabilities being loosened now land on Opus- and Sonnet-class models, with Mythos "to follow". The second misreading is the fund. $35m in Claude credits is not $35m disbursed: it is inference capacity valued at list price, redeemable only against Anthropic's own models, with the pilot cohort and eligibility rules not yet published.

The cheapest-sounding sentence describes a meter

Anthropic's page says scans are billed "as standard token usage under your existing plan, with no separate add-on." That phrasing reads as generosity and means the opposite of free: a full-codebase scan draws down the token budget the customer already bought, run on the most expensive model in the lineup. There is no published per-scan price because there is no per-scan price — there is a token meter.

Why the shape matters more than the announcement

This is a template for shipping dual-use capability. Rather than deciding who may hold a model, the vendor decides what the output can be, and the interface does the gatekeeping. It is a weaker guarantee than an allowlist and a stronger one than an API key, and it is now attached to a commercial plan rather than to a vetting process.