Organizations should evaluate dependency on public AI APIs as an operational risk and incorporate private or self-hosted models into their IT risk strategy.
Anthropic is permitted to release its Claude 5 model to selected US cyber defenders following security reviews, while weaker variants remain subject to export restrictions.
MCP 2026-07-28 eliminates legacy session risks through statelessness but introduces new attack surfaces in identifier management, HTTP headers, UI apps, and asynchronous tasks.
AI models produce functional code but systematically fail to implement security safeguards like rate-limiting or input validation because they are trained on public code that does not structurally represent these aspects.
Anthropic’s Claude-3.5-Sonnet model is cleared for distribution to over 100 Trusted Partners, while Claude-3.5-Opus remains blocked and the government develops a standardized assessment framework for future security disputes.
Anthropic’s Opus 4.6 withstood 6,000 prompt injection attacks in a public security test without compromise, indicating improved defense mechanisms — but such stability results do not replace comprehensive security design in production.
Claude is increasingly being deployed for agentic tasks rather than pure conversations, revealing new data evaluation methods and more differentiated usage patterns.