AWS is putting its security tools inside OpenAI and Anthropic's coding software

Amazon's cloud division wants to be the security guard at every developer's door, no matter which AI model they use to write code.

AI2Day NewsdeskAI-assistedPublished Updated Editor: Lee Brown4 min read
Illustration: a boldly patterned geometric hoodie hanging on a plain concrete wall under harsh fluorescent light
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • AWS announced at Black Hat USA 2026 that its Continuum security platform will integrate into OpenAI Codex, Anthropic Claude Code, and AWS's own Kiro IDE.
  • Anthropic's Claude Mythos Preview, released in April 2026, found thousands of unknown zero-day vulnerabilities (security flaws no one has patched yet) across major operating systems and browsers, with more than 99% still unpatched.
  • The median time from a vulnerability being discovered to a criminal using it as a weapon collapsed from 771 days in 2018 to under four hours by 2024, and AWS projects under one hour by end of 2026.
  • AWS expanded its Security Hub Extended marketplace to a tenth category covering supply chain security, adding partners Chainguard and Socket.
  • Customers pay a single AWS price for Continuum; AWS absorbs the underlying AI model costs itself.

What did AWS actually announce?

AWS built a security tool called Continuum that watches for dangerous flaws as developers write code, and it'll now work inside two rival companies' coding assistants: OpenAI Codex and Anthropic Claude Code, both AI tools that help programmers write software faster.

The announcement came at Black Hat USA 2026, one of the biggest cybersecurity conferences of the year. The practical point for ordinary people: the AI tools helping developers build the apps you use every day will now have AWS's security checks running quietly in the background. Our earlier coverage of UK security testers finding that OpenAI and Anthropic AI agents went rogue during tests, published 3 August 2026, shows why automated guardrails at the code-writing stage matter more than most people realise.

Why is this suddenly urgent?

A new AI model made an already bad problem much worse, very fast.

Anthropic released Claude Mythos Preview in April 2026. During testing, it found thousands of zero-day vulnerabilities, meaning security holes nobody knew existed and therefore nobody had fixed. More than 99% of those holes are still open. At the same time, the window between a flaw being spotted and criminals weaponising it shrank from 771 days in 2018 to under four hours by 2024.

Chet Kapoor, AWS's vice president of search and security observability, told VentureBeat plainly: "CISOs have had code vulnerabilities for a while, and then Mythos came along, and it just made it a lot worse. They already had a backlog. Now the backlog is 5x more."

That backlog is what Continuum is designed to chew through.

How does Continuum actually work?

It runs in four steps.

First, it scans all of a company's code and pulls in the existing list of known problems. Second, it ranks those problems by how dangerous they are to that specific business, not just in general. Third, it builds a controlled sandbox, a locked environment where it tests whether a flaw can actually be exploited and how bad the damage could be. Fourth, it suggests a fix, whether that's a code change or a network tweak, already tested in that same sandbox.

A human approves every step.

Phase What it does
Discovery Scans code and imports known vulnerability list
Prioritization Ranks risks by real-world business impact
Validation Tests whether each flaw can actually be exploited
Remediation Proposes and pre-tests a fix

Pricing is deliberately simple. Customers pay AWS one price, and AWS picks whichever AI model does each phase best, covering those costs itself.

Should this worry or reassure ordinary people?

Honestly, a bit of both. The reassuring part is that the people building software you rely on will have better automated tools to catch dangerous mistakes before they reach you.

The cautious part: Continuum is new, and the vulnerability backlog it's trying to tackle is enormous. Most security tools claim to solve the problem; few do it completely.

Kapoor's vision is for security to move from humans staring at dashboards to AI agents, software that can carry out multi-step tasks on its own, acting at machine speed. That shift is real and happening. Whether AWS becomes the dominant layer across the whole industry is a question worth watching over the next eighteen months.

If you use any software product at work or at home, ask your IT team or vendor whether their development pipeline now includes automated security scanning. It's a reasonable question, and the answer tells you a lot about how seriously they take the current threat environment.

© 2026 AI2Day