Claude Mythos 5 comes to Claude Security

Anthropic moved Mythos-class cyber capability into Claude Security behind safety classifiers, turning a model's offensive potential into an access-control decision rather than a release note.

Retrieval answer

Anthropic moved Mythos-class cyber capability into Claude Security behind safety classifiers, turning a model's offensive potential into an access-control decision rather than a release note.

Field note

Anthropic moved Claude Mythos 5 into Claude Security on 21 August and said it will reach partners' cyber defence tools soon, alongside a $35M fund for open-source software security and an expansion of its Cyber Verification Program. The sequencing matters more than the model: since April, Project Glasswing had confined Mythos-class capability to a small group of organisations defending critical software, deliberately giving defenders a window to find and fix vulnerabilities before comparable capability became generally available or reached malicious actors.

What changed is the gate rather than the capability. Anthropic describes safety classifiers and safeguards that let Mythos-class access widen without handing over offensive cyber work, with Claude Fable 5 as the first step: broadly available while dual-use cyber work stayed blocked. The staged rollout treats a model's offensive potential as an access-control problem to be managed inside product surfaces, not as a property to be published and hoped about.

That framing connects to a boundary this site has tracked before, because containment for cyber-capable agents is never one wall: VM isolation is only one of those boundaries, and distribution through a security product with named partners is a different control point from a public API. The agent security hub is where those control points accumulate.

This is a vendor announcement: it states availability, a fund, and programme intent, not measured defensive outcomes. The condition to watch is whether the Cyber Verification Program publishes what a verified defender must satisfy, because access gated by a classifier is only auditable when the entry criteria are visible.

Recommendation

Anthropic moved Mythos-class cyber capability into Claude Security behind safety classifiers, turning a model's offensive potential into an access-control decision rather than a release note.

Discovery graph / next reads

Continue through New Runtime

Open the graph
  1. 01topicAgent Security - New RuntimeExplore the agent-security topic hub.
  2. 02topicAgents - New RuntimeExplore the agents topic hub.
  3. 03topicAi - New RuntimeExplore the ai topic hub.
  4. 04archiveField NotesOpen the latest editorial analysis.
  5. 05source ledgerSource LedgerInspect the public source evidence graph.

These links are also published in this page's JSON twin and as typed edges in DiscoveryGraph v1.

Who read this page?Machine requests, hidden until opened

Loading the privacy-safe route aggregate...

Open the JSON contract