# Anthropic Opens Its Best Model to Defenders and Backs Open Source Security With $35M
When AI companies talk about safety, the word usually means "making sure the model doesn't say bad things." Anthropic's latest moves are something different: extending access to Mythos 5 — the company's most capable model — to security researchers and incident responders, while simultaneously dropping $35 million into a fund specifically for open source security infrastructure. That's not PR. That's a bet that the defensive side of the AI arms race needs real resources.
## What Defenders Are Actually Getting
The expanded access program shifts Mythos 5 from a product available to paying enterprise customers into something closer to a utility for the security community. The details matter here: "more defenders" is deliberately broad language, covering researchers, threat intelligence teams, red teams, and incident response shops that previously hit rate limits or couldn't justify enterprise contract overhead.
In practice, that means access to a model that can reason through complex attack chains, draft incident timelines, synthesize threat actor TTPs from messy log data, and help analysts working at 2 AM figure out whether that anomalous network behavior is a misconfiguration or an active intrusion. None of those tasks are impossible without AI, but they're faster with it — and in security, speed is often the margin between containment and catastrophe.
## Where $35 Million Goes
The open source fund is the more structurally interesting piece. Open source security infrastructure is chronically underfunded relative to its importance. The Log4Shell crisis exposed exactly this problem: a single maintainer effectively supporting a library embedded in tens of thousands of enterprise products, with no sustainable funding model. The lesson should have been obvious. Three years later, the ecosystem still depends on volunteers maintaining critical components for free.
Thirty-five million dollars won't fix that entirely. But deployed strategically — grants to maintainers of high-dependency libraries, funding for security audits of foundational tools, support for the researchers who find vulnerabilities and responsibly disclose them rather than sell them — it can meaningfully move the needle.
The question is governance: who decides where the money goes, and what accountability mechanisms exist? Anthropic hasn't published a grant-making process yet. That matters. Funds like this have a tendency to drift toward projects with good optics rather than genuine risk reduction.
## The Dual-Use Problem Doesn't Go Away
There's an obvious tension in any AI company expanding security access: the same model capabilities that help defenders analyze malware samples also lower the barrier for offensive operations. Mythos 5 presumably includes the same guardrails as Anthropic's production models, but guardrails have always been more speed bump than wall against a determined adversary.
Security researchers have spent years demonstrating that safety layers on large language models are permeable under specific prompt conditions. Anthropic knows this — they've published their own research on it. So expanded access to a more capable model is a two-sided door, even with good intentions behind the policy.
The counter-argument, and it's a reasonable one, is that sophisticated threat actors already have access to capable AI through other channels. Restricting access from legitimate defenders while adversaries proceed unconstrained is the worst of both worlds. Anthropic seems to be making that calculus explicitly.
## The Timing Signal
This announcement follows a period of intense scrutiny on AI companies' claims about security. Several major vendors faced embarrassing disclosures in the past year about models being used to assist in social engineering campaigns and automated vulnerability scanning at scale. The pressure on Anthropic to demonstrate that their technology is net-positive for security — not just neutral — has been building.
The $35M fund is also notable for what it signals to the market. Google, Microsoft, and Amazon have each made public commitments to open source security in various forms. Anthropic, as the youngest major AI lab, is planting a flag that says it belongs in that conversation — not as a disruptor, but as infrastructure.
---
## HackWire Analysis
The Mythos 5 defender access program is worth watching closely, but not for the reasons most coverage will emphasize. The model capability angle is almost beside the point. What matters is the precedent: if this works — if expanded AI access demonstrably accelerates security operations and threat detection — it establishes a template for how AI labs should position themselves relative to the security community. Not as vendors, but as utility providers.
The $35M open source fund comparison point that keeps coming to mind is Alpha-Omega, the joint Microsoft-Google initiative that launched in 2022 to fund security work on the most critical open source projects. Alpha-Omega moved slowly and faced criticism for prioritizing high-profile projects over genuinely at-risk ones. Anthropic has an opportunity to do this differently, but only if the fund's governance is transparent and its criteria are risk-driven rather than reputational.
The missing story in most AI-security announcements is the measurement problem: how do you actually assess whether expanded AI access improves security outcomes? Incident response time? Vulnerability detection rates? False positive reduction in alerts? Anthropic should commit to publishing outcome data from the defender access program, not just access statistics. That accountability would distinguish this from a marketing initiative.
For defenders evaluating whether to integrate Mythos 5 into their workflows: the legitimate question is not "can it help?" — it can — but "what does responsible deployment look like?" That means access controls, audit logging of queries, and clear policies on what types of investigations can be AI-assisted. The organizations that will benefit most are those treating this as a workflow redesign, not a search engine upgrade.
The open source fund, if well-governed, could be genuinely important. The security community should push Anthropic to publish grant criteria and selection processes within the next quarter. Silence on governance is where good intentions go to die.
— HackWire Editorial
---
## Related Coverage