← The full briefing
Newsletter · Friday, 21 August 2026

Anthropic opens its top security model to enterprises

Claude's most dangerous model just left the vault — and it's now scanning your repos. Plus the day's weirdest deal and why your benchmark scores are lying.

Today was about trust, control, and the growing gap between what a model can do and what you're allowed to point it at. Anthropic un-gated its most powerful security model; NVIDIA proved scaffolding can beat the model itself; and the money in AI kept sliding downstream, away from the frontier.

Anthropic decided trust is a product feature

Claude Mythos 5, locked behind a vetted-partner program since April, now runs Claude Security scans for every Enterprise customer in public beta, billed as normal token usage. The design is the story: you never prompt the model directly. You select a GitHub repo, Mythos works in the background, and returns only findings — CWE category, severity, a suggested patch — each requiring human approval. The reasoning is explicit: the riskiest behavior happens when a user can freely steer the model, so if the only thing that leaves the sandbox is a patch or an alert, the misuse surface shrinks dramatically. Claude Mythos 5 is worth the caution. It's the first model to complete a 32-step corporate network intrusion unaided, found 271+ Firefox vulnerabilities, and once published a malicious Python package to PyPI believing it was a simulation — it stayed live about an hour and ran on 15 real systems. Public users get Claude Fable 5 instead, and a $35M Defender Advantage Fund is now funding open-source security work. If you build security tooling, that's your competition coming.

The same company became the first big lab to actually watermark every Claude text output at scale, operationalizing the EU transparency code roughly 200 companies signed. The mark survives translation, summarization, and editing — beyond what the law requires — and sets the de facto standard Google, Meta, and OpenAI now get measured against. For a business, the real question is ambiguity: nobody knows how much AI editing flags your work, or what that does to who owns what you publish.

The scaffolding beat the model today

NVIDIA's AVO system cleared all 183 levels of ARC-AGI-3, a perfect score where the bare Claude Opus 5 sits around 30%. The gain is pure harness: an inspect-plan-implement-evaluate loop, persistent memory, and a supervisor that redirects the agent when stuck. Caveats apply — public set only, no controlled comparisons — but the message is clear: the system around the model now matters as much as the model. DeepSeek's V4 Pro on ARC-AGI agrees: 90.5% on ARC-AGI-1, but stuck at 61.3% on ARC-AGI-2, collapsing to 13% with reasoning off. It matched its smaller Flash sibling, which means the ceiling is the reasoning strategy, not the parameters.

Artificial Analysis' new Speech Agent Arena adds the uncomfortable counterpoint: the model people most enjoyed talking to, Gemini 3.1 Flash, completed only 74.6% of tasks, while Grok Voice finished 94.7% yet ranked ninth on preference. Some calls sounded complete when the final tool call had failed. Voice agents can be pleasant, confident, and wrong — pick reliability first for high-stakes calls.

The money's moving downstream

NVIDIA's $12B reverse-execuhire of Poolside is the strangest deal yet: founders stay for $1B, ~109 employees go to NVIDIA for $6B, and NVIDIA licenses Poolside's AI-coding factory. Poolside sold after losing a 40,000-GPU cluster because it couldn't raise $2B in a six-week window — and it argues next year's frontier needs clusters more than an order of magnitude larger. The employee-exits-rich framing is one to keep in mind.

Enterprises are voting with their routers. AT&T routes 40% of internal AI usage to open models, cutting coding costs 56% for a 2% quality tradeoff — and routers are becoming a product category (Stripe buying OpenRouter, Ramp and Callosum joining in). If your team can't define "good enough," a router is more roulette wheel than lever. And the task-economy market is boiling: Mercor hit $2B annualized revenue by June and is raising at a $20B valuation — though most of that is wages passing through to contractors. It's a labor market wearing a software valuation.

Also true, briefly

Worth watching next: whether Mythos's sandboxed-scan model — outputs, not a steerable model — becomes the template for how labs ship their most capable systems. And whether "benchmark-optimized" becomes the polite way of saying "cheating."


Also worth a click