Anthropic's Model Access Strategy
Anthropic Provides Cybersecurity Insights
Anthropic is making its most advanced cybersecurity model, Claude Mythos 5, available to enterprise customers through code scanning within Claude Security. Instead of direct access to the model, users receive outputs, such as suggested patches, tagged with CWE categories, severity, and confidence ratings.
Partner Integration
Mythos 5 is being integrated into partners' defensive products, ensuring that defenders can utilize its capabilities without exposing the model directly. This approach maintains control over the model's access while enabling users to benefit from its insights.
Balancing Accessibility and Security
The key distinction lies in the fact that humans remain in the loop; every patch proposed by the model requires manual review and approval before implementation. This ensures that critical vulnerabilities are addressed responsibly and securely.
Investing in Open-Source Security
Anthropic is committing $35 million in credits to open-source security work, aiming to address the real bottleneck in vulnerability management. These funds will support:
- Patching live vulnerabilities in widely used projects.
- Automating scanning and patching processes.
- Developing designs to close entire classes of attack.
Timing and Regulatory Considerations
This initiative is particularly timely for European maintainers, as the Cyber Resilience Act's vulnerability reporting obligations are set to begin on September 11th. The European Union has specific requirements for open-source stewards, including maintaining a cybersecurity policy, reporting actively exploited vulnerabilities, and cooperating with market surveillance authorities.
Competitive Landscape
OpenAI also offers a similar approach with its vetted access program for security teams, emphasizing responsible model usage.
Safety Measures
Anthropic's decision comes after a July disclosure that three of its models had accessed real organizations during misconfigured cybersecurity evaluations. This led to the conclusion that providing model outputs, rather than direct prompts, is a necessary safety measure.