Market intelligence

Google Widens CodeMender Access, Entering AI Cybersecurity Race in May 2026

Google is escalating its involvement in AI-powered cybersecurity by granting external experts API access to its CodeMender tool. The move, announced at its I/O conference, directly challenges competitors like Anthropic and OpenAI in the market for automated vulnerability detection.

2 min read

Key takeaways

  1. 01Google is expanding access to its CodeMender AI tool, inviting external experts to test its API.
  2. 02The move is a direct competitive response to Anthropic's Mythos and similar tools from OpenAI.
  3. 03Google CEO Sundar Pichai acknowledged that Anthropic demonstrated a valid use case for large AI models in security.
  4. 04The strategy targets a new potential revenue stream in enterprise and government cybersecurity auditing.
  5. 05CodeMender is transitioning from an internal research project to an external-facing commercial product.

The AI Security RaceLede

At its recent I/O conference, Google announced a significant expansion of its CodeMender project, an AI agent designed for code security first shown last October. The company is now providing API access to select external groups of specialists for testing purposes. This marks a notable step in making the tool more broadly available beyond Google's internal teams, signaling a strategic push into the automated cybersecurity market.

Challenging AnthropicEvent Summary

This strategic expansion positions Google directly against rivals like Anthropic and OpenAI. The move follows Anthropic's high-profile announcement of its Mythos model, which highlighted the potential for large AI systems to identify complex security flaws. During a press briefing, Google CEO Sundar Pichai acknowledged the competitor's influence, stating, What Mythos has done, and credit to them, is to show that there is a value for the largest-sized model in these kinds of security use cases.[1] But I think it’s something we are capable of doing as well. This indicates Google's intent to match capabilities in a burgeoning field.

From Internal Tool to ProductPublisher Context

CodeMender's evolution from an internal research project into an external-facing product marks a strategic pivot for Google. The tool was first introduced in the prior year. Now, by opening API access to developers, Google is transforming it into a commercial offering.[3] This move is aimed squarely at the expanding market for autonomous vulnerability detection and remediation, where speed and scale are critical competitive advantages. The wider availability suggests Google is confident in the tool's capabilities and ready to compete for enterprise security budgets.

A New Revenue FrontierOutlook

The push into cybersecurity represents a search for new revenue streams beyond consumer-facing chatbots and content creation tools. With pressure building on AI firms to demonstrate profitability, automated security auditing is seen as a key enterprise market. Google DeepMind CTO Koray Kavukcuoglu framed the initiative's goal as wanting to help secure the world’s code bases by both discovering and correcting vulnerabilities.[2] He also confirmed that Google has entered discussions with governments and corporate clients about deploying CodeMender to audit their critical systems, suggesting a clear path to monetization.

An Intensifying ContestWrapup

Google's entry into the AI-driven security market signifies an important shift in the technology landscape. The competition among major AI labs is moving from performance benchmarks and chatbot capabilities to specialized, high-stakes enterprise applications. As companies like Google, Anthropic, and OpenAI vie for contracts with corporations and government agencies, the development of tools like CodeMender will likely accelerate. The ultimate test will be whether these AI systems can deliver on their promise to make digital infrastructure fundamentally more secure on a global scale.

Citations

  1. [1]

    During a press briefing, Google CEO Sundar Pichai acknowledged the competitor's influence, stating, "What Mythos has done, and credit to them, is to show that there is a value for the largest-sized model in these kinds of security use cases. But I think it’s something we are capable of doing as well."

    "Google CEO Sundar Pichai told reporters during a Monday press briefing, “What Mythos has done, and credit to them, is to show that there is a value for the largest-sized model in these kinds of security use cases. But I think it’s something we are capable of doing as well.”"
  2. [2]

    Google DeepMind CTO Koray Kavukcuoglu framed the initiative's goal as wanting to "help secure the world’s code bases" by both discovering and correcting vulnerabilities.

    "The difference is that Google is now making the tool more widely available externally — and marketing it as a way to, as Google DeepMind CTO Koray Kavukcuoglu put it, “help secure the world’s code bases” by both flagging and fixing vulnerabilities."
  3. [3]

    Now, by opening API access to developers, Google is transforming it into a commercial offering.

    "Google is opening the doors to CodeMender, its AI-powered code security agent, giving external developers API access for the first time. The move transforms what was an internal research project into a product aimed squarely at the growing market for autonomous vulnerability detection and patching."

Sources

4 references

Maxime Doussin, CTO at MWM

Maxime Doussin

CTO

Maxime Doussin is the CTO of MWM, where he leads engineering, data infrastructure, and the mobile-app market-intelligence platform. He writes MWM's weekly app trend analysis, drawing on proprietary ranking data covering millions of iOS and Android apps across 150+ countries.

This article is an independent editorial analysis. App names, trademarks, and brands mentioned are the property of their respective owners. Market data and rankings referenced are based on MWM's proprietary estimates.

Believe this article infringes your intellectual property? File a dispute