Anthropic has brought its most capable AI model, Claude Mythos 5, to all enterprise customers through its Claude Security tool, reversing a policy that previously restricted the model to about 150 partners because of safety concerns. The company announced Friday it's now making Mythos 5 available in public beta for any Claude Enterprise user wanting to scan code for security flaws, alongside a $35 million fund to identify and fix vulnerabilities in open source projects. Mythos 5 performed so well in high-risk domains that Anthropic chose not to release it publicly in June, instead launching Fable 5, essentially the same model but with stricter safety controls.

The upgrade also includes partnerships with other cybersecurity firms to integrate Mythos 5 into their products, according to the announcement. Anthropic's new Defender Advantage Fund (0xDAF) will distribute $35 million in credits specifically for finding and patching weaknesses in open source software. Organizations approved through Anthropic's existing Cyber Verification Program—which already allows vetted defenders to run dual-use cybersecurity work on Opus and Sonnet with fewer restrictions—will soon receive safeguarded access to Claude Mythos as well. The company charges $10 per million input tokens and $50 per million output tokens for Mythos 5 usage.

Anthropic argues it can now safely deploy Mythos 5 because users interact with the model through controlled outputs rather than direct access. "The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses," the company writes. "But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower." Anthropic maintains that Claude Security "uses Mythos 5 to scan code you own" and that the company and its partners "have abuse prevention measures in place to verify the model stays within its intended scope," according to the announcement.

The shift from restricted to broadly available reflects Anthropic's confidence in a mediated deployment strategy—users receive findings and patches instead of querying the model freely, which the company believes creates sufficient guardrails. Because Anthropic controls the tools and infrastructure, it asserts it can maintain safety while expanding access beyond the original Project Glasswing cohort of 150 partners who first tested Mythos 5. Enterprise admins can now enable Claude Security for their teams, allowing developers and security staff to point the model at their repositories and receive suggested fixes when vulnerabilities surface. However, the announcement notes that ownership becomes "a bit of a slippery category" when codebases include open source libraries, since a developer cloning a widely used library into a company repository and scanning it with Mythos 5 would uncover the same vulnerabilities an attacker might exploit—vulnerabilities that exist everywhere that library is deployed.

Anthropic's broad release of Mythos 5 through controlled channels represents a calculated bet that restricting output types rather than model access can manage dual-use risks in AI cybersecurity tools. The approach attempts to thread a needle that has vexed the industry: extracting maximum defensive value from highly capable models while preventing those same capabilities from aiding attackers. For enterprise security teams weighing the adoption of AI-assisted vulnerability scanning, the tradeoff is straightforward—access to frontier model performance at premium token pricing, bounded by guardrails that may prove permeable as scanning practices evolve.