Anthropic's most capable model, Claude Mythos 5, now drives Claude Security scans for Enterprise this week. The model itself stays out of reach: customers get patches, but no way to talk to Mythos 5 directly.
Anthropic has shipped its newest frontier model, Claude Mythos 5, into Claude Security, its code-scanning product, for Enterprise customers in public beta this week. The model itself is not reachable by prompt.
What comes back to the customer is a set of suggested patches and alerts. The actual patching happens in Claude Code on the web, using whatever models the organization already has, not Mythos 5. The model stays behind the wall. Anthropic's blog post makes the non-feature explicit: there is no way to prompt the model to write an exploit. Customers get the model's findings. They do not get the model.
Anthropic is choosing to keep a frontier model out of reach even as it ships that model's capabilities to paying customers. Other vendors shipping frontier models into security-sensitive products now face the same question: is capability without direct access the right distribution, and what does it cost in transparency and debuggability?
Two other launches in the same week follow the same shape. DeepSeek shipped deepseek-v4-flash-vision-exp on August 21, an experimental multimodal model that matches V4-Flash on text (agents, reasoning, world knowledge) and adds vision at the same per-token rate. The capability lands; the model stays on a fixed-price Flash tier with peak and off-peak pricing. Quoting a single price for V4-Flash is incomplete; the pricing page splits it: $0.22 per million input tokens off-peak, $0.44 peak; $0.66 output off-peak, $1.32 peak. Peak and off-peak windows follow a schedule DeepSeek publishes on its pricing page. A budget built on one number is off by 2x.
xAI's Grok Bot, launched in beta on August 11, expanded this week to all SuperGrok Plus, SuperGrok Heavy, Cursor Pro+, Cursor Ultra, and Cursor Teams plans. The bots run in a cloud computer with browser and terminal access, work across apps, and are designed for parallel multi-bot workflows (Sales Prospector, Website Builder, Inbox Manager). The orchestration surface sits behind paid plans, not a free tier, and the underlying model stays inside xAI's cloud computer.
Across all three: the capability is real, the model is gated. Anthropic's gating is the most explicit; DeepSeek's is the pricing clock; xAI's is the paywall. Each moves the boundary between what the model can do and what the customer can ask it to do in a different direction.
A security team that wants to ask why a patch was suggested or push back on a false positive has to route the question through the partner-tool flow. The model that produced the finding is unreachable to the person investigating it. For defenders, that asymmetry is the price of the safety framing; for the rest of the industry, it sets the template for how frontier AI in security-sensitive contexts gets shipped: capability first, prompt never.
The Claude Security deployment is the one worth watching. The strongest counter is that it is a beta; the lock-in could loosen, the model might eventually become promptable, or the partner-tool flow might narrow. The product page is explicit for now, though: users cannot prompt Mythos 5 to write an exploit. The non-feature is on the record.
The next test is what happens when a real vulnerability surfaces in Claude Security's output. If the suggested patches are good and arrive in a usable form, the defender-only pattern holds. If customers need Mythos 5 directly to interpret the results, the wall comes down. For now, the model is shipped, the prompt is not, and the customer is downstream of the partner tool.