TL;DR

Anthropic has extended its most capable model to enterprise security scanning and, shortly, to partners’ defensive products, alongside $35m in credits for open-source security work. The access design is the substance: users receive outputs such as patches and alerts without being able to prompt the model directly. It arrives days after OpenAI’s policy chief warned of persistent automated attacks.

Access without the model

The company’s stated problem is that capability useful for defence is equally useful for attack, and the risk concentrates where someone can steer a model freely. Its answer is to sever the two. Customers on enterprise plans can now run codebase scans on the frontier model, receiving each finding with a weakness classification, confidence and severity ratings, and a proposed fix. What they cannot do is ask that same model to build an exploit.

Partner integrations follow the identical pattern. A vendor’s remediation tool might return a list of suggested patches generated by the model, while the person using it never reaches a prompt. Every patch still requires human review before it lands.

This is a meaningful design position rather than marketing. Restricting what a model can be asked, rather than which model you may use, is a different control surface from the usual capability gating — and one that could generalise well beyond security.

The fund and the vetting

The $35m Defender Advantage Fund provides credits to organisations hardening open-source projects, aimed at patching live vulnerabilities, making scanning and patching repeatable, and funding structural fixes that close whole categories of attack. It follows $4m in direct donations under the earlier Glasswing programme. Separately, the vetting scheme that grants approved security teams reduced safeguards is being widened, with frontier-class access to follow.

Looking forward

The timing is doing work. Chris Lehane argued this week that defenders will need superior models to withstand model-driven attacks — a claim that conveniently sells models. Anthropic has shipped something closer to an answer: capability delivered as results rather than as access.

For UK organisations the practical question is where this lands. Most will meet it through an existing security vendor rather than directly, which puts it squarely inside the third-party AI visibility problem raised in UK pensions guidance today and by the NCSC last week. A scan that produces patches nobody at the organisation can trace to a model, running under a supplier’s contract, is a capability gain and a governance gap in the same purchase.

Open-source maintainers are the clearer beneficiaries. Britain’s public sector runs extensively on projects staffed by volunteers, and funded patching there is worth more than most enterprise deployments.