Google Opens CodeMender to Outside Security Teams, Taking Aim at Anthropic's Mythos
Google's selective API rollout for CodeMender puts it in direct competition with Anthropic's Mythos on AI-driven vulnerability discovery.
10. Google Opens CodeMender to Outside Security Teams, Taking Aim at Anthropic's Mythos
Google announced at I/O 2026 that CodeMender, an AI agent for code security first debuted in October 2025, is now available via API to select groups of external security experts. Previously limited to internal use, the tool is designed to identify and remediate vulnerabilities in production codebases. The expanded access marks Google's first meaningful external rollout of a dedicated security-focused coding agent, and the company is actively marketing it as an enterprise-grade offering.
The timing is not coincidental. Anthropic's Mythos has been quietly gaining traction among security teams as a specialized agent for vulnerability discovery, giving Anthropic an early foothold in a market that sits at the intersection of two high-value enterprise concerns: code quality and security compliance. Google's move with CodeMender is a direct attempt to prevent that foothold from becoming a moat. Google holds structural advantages here: deep integration with Google Cloud, existing relationships with enterprise security buyers, and access to the vulnerability data that flows through its own infrastructure at scale. The question is whether CodeMender can match Mythos on the thing that matters most to security practitioners, which is accuracy on real-world exploit patterns, not benchmark scores.
The broader pattern is that AI coding agents are fragmenting by specialization. General-purpose coding assistants like GitHub Copilot and Cursor are being flanked by agents built for specific high-stakes workflows. Security is the first vertical where that specialization is visibly competitive. Watch for how Google prices CodeMender's API access relative to Mythos, and whether the "select experts" framing expands to general availability before the end of Q3 2026. That timeline will signal how confident Google is in the product's production readiness.