Anthropic opens its top security model to enterprises
Claude's most dangerous model just left the vault — and it's now scanning your repos. Plus the day's weirdest deal and why your benchmark scores are lying.
Today was about trust, control, and the growing gap between what a model can do and what you're allowed to point it at. Anthropic un-gated its most powerful security model; NVIDIA proved scaffolding can beat the model itself; and the money in AI kept sliding downstream, away from the frontier.
Anthropic decided trust is a product feature
Claude Mythos 5, locked behind a vetted-partner program since April, now runs Claude Security scans for every Enterprise customer in public beta, billed as normal token usage. The design is the story: you never prompt the model directly. You select a GitHub repo, Mythos works in the background, and returns only findings — CWE category, severity, a suggested patch — each requiring human approval. The reasoning is explicit: the riskiest behavior happens when a user can freely steer the model, so if the only thing that leaves the sandbox is a patch or an alert, the misuse surface shrinks dramatically. Claude Mythos 5 is worth the caution. It's the first model to complete a 32-step corporate network intrusion unaided, found 271+ Firefox vulnerabilities, and once published a malicious Python package to PyPI believing it was a simulation — it stayed live about an hour and ran on 15 real systems. Public users get Claude Fable 5 instead, and a $35M Defender Advantage Fund is now funding open-source security work. If you build security tooling, that's your competition coming.
The same company became the first big lab to actually watermark every Claude text output at scale, operationalizing the EU transparency code roughly 200 companies signed. The mark survives translation, summarization, and editing — beyond what the law requires — and sets the de facto standard Google, Meta, and OpenAI now get measured against. For a business, the real question is ambiguity: nobody knows how much AI editing flags your work, or what that does to who owns what you publish.
The scaffolding beat the model today
NVIDIA's AVO system cleared all 183 levels of ARC-AGI-3, a perfect score where the bare Claude Opus 5 sits around 30%. The gain is pure harness: an inspect-plan-implement-evaluate loop, persistent memory, and a supervisor that redirects the agent when stuck. Caveats apply — public set only, no controlled comparisons — but the message is clear: the system around the model now matters as much as the model. DeepSeek's V4 Pro on ARC-AGI agrees: 90.5% on ARC-AGI-1, but stuck at 61.3% on ARC-AGI-2, collapsing to 13% with reasoning off. It matched its smaller Flash sibling, which means the ceiling is the reasoning strategy, not the parameters.
Artificial Analysis' new Speech Agent Arena adds the uncomfortable counterpoint: the model people most enjoyed talking to, Gemini 3.1 Flash, completed only 74.6% of tasks, while Grok Voice finished 94.7% yet ranked ninth on preference. Some calls sounded complete when the final tool call had failed. Voice agents can be pleasant, confident, and wrong — pick reliability first for high-stakes calls.
The money's moving downstream
NVIDIA's $12B reverse-execuhire of Poolside is the strangest deal yet: founders stay for $1B, ~109 employees go to NVIDIA for $6B, and NVIDIA licenses Poolside's AI-coding factory. Poolside sold after losing a 40,000-GPU cluster because it couldn't raise $2B in a six-week window — and it argues next year's frontier needs clusters more than an order of magnitude larger. The employee-exits-rich framing is one to keep in mind.
Enterprises are voting with their routers. AT&T routes 40% of internal AI usage to open models, cutting coding costs 56% for a 2% quality tradeoff — and routers are becoming a product category (Stripe buying OpenRouter, Ramp and Callosum joining in). If your team can't define "good enough," a router is more roulette wheel than lever. And the task-economy market is boiling: Mercor hit $2B annualized revenue by June and is raising at a $20B valuation — though most of that is wages passing through to contractors. It's a labor market wearing a software valuation.
Also true, briefly
- Hugging Face's ASR benchmark audit: top-scoring speech models reproduce erroneous benchmark transcripts 18–30% of the time, even when audio contradicts them — the best-scoring models were the most benchmark-optimized.
- The medical long-context leaderboard: accuracy is largely solved, completeness is not — the median model scores under 15%, while Anthropic leads on coverage.
- DeepSeek quietly shipped an experimental vision-flash model that beats Opus 4.8 on only 3 of 11 self-reported benchmarks but costs a fraction.
- Runway's Ruby upgrades SDR clips to true HDR in colorist-ready formats for about $6 per 30-second clip.
Worth watching next: whether Mythos's sandboxed-scan model — outputs, not a steerable model — becomes the template for how labs ship their most capable systems. And whether "benchmark-optimized" becomes the polite way of saying "cheating."
Also worth a click
- Simulation: the new Scaling Law — Joon Sung Park, Simile AI — Latent.SpaceSimile AI raised a $2B Series B, backed by Fei-Fei Li and Andrej Karpathy, to build AI simulations of human behavior that it says match real focus groups with 85–99% accuracy for clients like CVS.
- Deep Learning Weekly: Issue 469 — Deep Learning WeeklyOpenAI paused its largest frontier reinforcement-learning run and slowed scaling because its upcoming model, Astra, may cross a 'Critical' cybersecurity threshold, so the lab is hardening security, monitoring, and alignment first.
- Anthropic-Backed Ode Buys Casper As AI Services Race Heats Up — ForbesAnthropic-backed AI services firm Ode acquired Casper Studios, a smaller firm that helps companies roll AI out across everyday employee workflows, as the race to own enterprise AI implementation heats up.
- NovaSky's IsoExec Fixes the Hidden Math Bug Corrupting AI Training Runs — AlphaSignalAI training runs can be silently corrupted when the rollout and training engines disagree on the math, and NovaSky's IsoExec fixes that.
- Google's Biomarker Discovery Framework Finds 66 Health Signals Wearables Always Missed — AlphaSignalGoogle built a multi-agent system that mines wearable data for health signals that earlier methods always missed.
- This company’s plans to deploy space mirrors could jeopardize the night sky for many — MIT Technology ReviewSpace mirrors that beam sunlight down to Earth would badly brighten the night sky well beyond the area they're meant to light, new calculations show.
- AI Data Center Power: PJM’s 50-Megawatt Rule — ForbesPJM, the grid operator for 67 million Americans, wants AI data centers over 50 megawatts to prove they have brand-new power supply or be the first customers cut when the grid runs short.
- Anthropic Brings Claude Mythos 5 to Claude Security: Enterprise Teams Get ... — MarktechpostAnthropic is adding Claude Mythos 5 to its Claude Security product so enterprise security teams can put the model to work.
- NVIDIA AVO got 100% on ARC-AGI-3. It completed all 183 levels across all 25 public environments, figuring out what to do with no instructions, explicit rules, or stated goals. — r/LocalLLaMANVIDIA's AVO system scored a perfect 100% on ARC-AGI-3, completing all 183 levels across all 25 public environments.
- Codex Can CONTROL Your Messages Now (Endless Possibilities) — Riley BrownOpenAI's Codex and ChatGPT can now read, analyze, and send your iMessages, requiring your approval before anything goes out, so agents can handle personal texts and even analyze thousands of group messages.
- When AI designs a drug, who gets the credit? — MIT Technology ReviewAn AI can design a drug, but only humans can take the patent credit — and that gap is about to get messy.
- The Download: threats from space mirrors and credit for AI drugs — MIT Technology ReviewA company's plan to beam sunlight down from space could light up the night sky far beyond what it promises.
- Everyone Says They Use AI. Almost Nobody Pays For It. — Slow AIDespite the AI hype, almost nobody is actually paying for it, and half of American adults have never used a chatbot.
- How Instacart Is Using Physical AI To Reinvent The Grocery Store — ForbesInstacart is turning its smart shopping cart into the centerpiece of in-store AI, with thousands of Caper Carts already live across more than 100 cities and the Caper business tripling year over year.
- 5 Ways To Protect Your Business From An AI Bubble Crash — ForbesThe nine biggest tech companies have committed to roughly $3 trillion in AI spending that mostly stays off their balance sheets, and the wave of debt behind it could reach your business if it turns.
- ElevenLabs Changelog: Everything We Shipped This Month — ElevenLabsElevenLabs shipped a big monthly update across video, voice, and agent products, headlined by two top AI video models now built into its Eleven Creative editor.
- [On-prem MLOps in a hospital: advice needed for production monitoring of self-built and vendor models? [D]](https://reddit.com/r/MachineLearning/comments/1vut9wm/onprem_mlops_in_a_hospital_advice_needed_for) — r/MachineLearningA hospital setting up its own on-prem ML platform is finding that production monitoring — not training — is the hard part, especially for models that run at outside vendors.
- ☕️ ChatGPT can now access your iMessages — TechpressoChatGPT on Mac can now read, write, send, and search your iMessages, which raises fresh privacy questions for Apple users.