Bottom line: Anthropic has developed security processes for an AI-agent-dominated SDLC in which Claude authors 80 percent of code, while human reviews and access controls remain as critical control points.
At Anthropic, code production has accelerated exponentially: software engineers deliver eight times more code per quarter in 2025 than in 2021, with Claude now authoring approximately 80 percent of code directly. The security team had to fundamentally restructure its processes to safeguard this dynamic without creating bottlenecks.
Anthropic has documented how it has redesigned its security controls for an AI-native software development cycle. The key point: Claude no longer functions merely as a writing assistant, but as the primary author and reviewer. More than half of the code integrated into the codebase is checked in through an internal Claude variant, while human engineers focus on steering, requirements definition, and final approval.
The security team must defend itself against three concrete threat scenarios: compromised or prompt-injected agents introducing malicious changes; supply chain and dependency poisoning attacks through manipulated inputs; and traditional application vulnerabilities at increased volume. All implemented controls are explicitly aligned with at least one of these scenarios.
Anthropic employs four overarching strategies for this: “shifting security left” through complete integration into the code development phase; deployment of strict access control and identity boundaries to limit the radius of potential damage; combination of automated deterministic and agentic reviews before and after production; and targeted deployment of human judgment at points of highest leverage.
In the planning stage, Anthropic uses a Claude Opus-based Project Security Review (PSR) that analyzes design documents against the MITRE ATT&CK Framework and proposes vulnerabilities with mitigations. The system has been extended with access to an internal knowledge index that considers organizational policies, prior decisions, and related systems. According to the company, this automation has significantly reduced the AppSec team’s time investment.
Source: claude.com · Published July 20, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.