Amazon Web Services (AWS) is making a significant strategic play by embedding its AI-powered security infrastructure, the Continuum platform, directly into the development environments of key rivals Anthropic and OpenAI. This bold move signals AWS’s conviction that controlling the foundational security layer for AI-driven software development holds greater long-term commercial value than focusing solely on developing proprietary AI models. Announced at Black Hat USA 2026, this integration aims to position AWS as the indispensable security control plane for enterprise software creation in the rapidly evolving AI era.
The Continuum platform, designed to proactively identify and remediate code vulnerabilities, will now seamlessly integrate with Anthropic’s Claude Code and OpenAI’s Codex, alongside AWS’s own Kiro IDE. This strategic decision places AWS’s security tooling at the very genesis of code creation, irrespective of the AI model developers utilize. Complementing this initiative, AWS has also expanded its Security Hub Extended, a curated, single-bill security marketplace launched earlier this year. The platform now boasts a tenth security category dedicated to supply chain protection, onboarding prominent partners like Chainguard and Socket. These combined announcements represent AWS’s most ambitious endeavor to date to establish itself as the de facto security nexus for enterprise software development, a crucial role in a global cloud infrastructure market that, according to Synergy Research Group, now surpasses $143 billion per quarter and is experiencing its highest growth rate in eight years.
The impetus behind these strategic moves is rooted in a pivotal development that has dramatically reshaped enterprise security protocols this year: Anthropic’s Claude Mythos Preview. Unveiled in April, Mythos, a general-purpose AI model, demonstrated unprecedented cybersecurity capabilities during pre-release evaluations. It identified thousands of previously unknown zero-day vulnerabilities across all major operating systems and web browsers. Alarmingly, over 99% of these vulnerabilities remain unpatched by their respective maintainers. Compounding the urgency, the median time from vulnerability discovery to weaponized exploit, a metric that has already plummeted from 771 days in 2018 to under four hours by 2024, is now projected to fall below one hour by the close of 2026.
Chet Kapoor, AWS’s vice president of search, security, and observability, articulated the escalating challenge in an exclusive interview with VentureBeat: "CISOs have had code vulnerabilities for a while, and then Mythos came along, and it just made it a lot worse. They already had a backlog. Now the backlog is 5x more, and that causes a problem." This exponential surge in known vulnerabilities, overwhelming any organization’s capacity for triage and remediation, is precisely the problem that AWS Continuum is engineered to solve. Kapoor further elaborated on AWS’s overarching security vision, characterizing it as a paradigm shift from "telemetry, storage, query, dashboards for humans to telemetry, context, reasoning, and actions by agents." This vision, frequently reiterated by AWS executives at Black Hat, is encapsulated by the concept of autonomous security operating at machine speed.
At its core, Continuum operates on what AWS terms an "agent-team loop architecture." This sophisticated orchestration framework intelligently selects the optimal AI model for each specific task, seamlessly connects to a customer’s existing environment, and delivers validated, secure code. The platform executes its functions through four distinct phases. Kapoor detailed these phases for VentureBeat:
The Discovery phase leverages multiple frontier AI models to meticulously scan codebases and ingest a customer’s existing vulnerability backlog.
Prioritization, which Kapoor highlighted as "one of our biggest value adds," contextualizes each identified vulnerability against the customer’s unique operational environment and business risk profile. "You go from 100 to 2,000, and now you’re like, whoa, I didn’t even know which 100 to focus on," he explained, underscoring the platform’s ability to cut through the noise of an overwhelming vulnerability landscape.
Validation involves building reproducible exploits within an isolated sandbox environment to definitively confirm the exploitability of a vulnerability. "Once I do them, how will it behave? You create a sandbox to go off and make that happen. So you can figure out what the blast radius is," Kapoor elaborated. This phase encompasses both first-party code developed by customers and third-party open-source components they rely on.
Finally, Remediation offers actionable fixes – encompassing network configuration adjustments, policy modifications, or code patches – that have been rigorously tested within the same sandbox environment. Crucially, human oversight remains central to the process, with organizations able to approve outcomes at varying levels of autonomy based on their comfort and operational needs.
The commercial model for Continuum is equally strategic. Customers pay a single, unified price to AWS for the platform. AWS, in turn, absorbs the underlying token costs associated with whichever frontier AI model performs most effectively during each phase of the security scan. "The customer purchases Continuum, period," Kapoor affirmed. "We optimize on which model to use for what because, quite frankly, GPT Cyber is good at some things, Mythos is good at some things." This approach positions AWS as the provider of an essential orchestration layer, abstracting away the complexities of model selection and cost management for the end-user.
Perhaps the most strategically significant aspect of AWS’s announcement is the integration of Continuum into OpenAI’s Codex and Anthropic’s Claude Code. AWS directly competes with both companies in the realm of cloud AI services, holding a substantial investment in Anthropic while OpenAI operates its own burgeoning infrastructure that vies for similar enterprise AI workloads. The fact that both companies agreed to embed a rival’s security tooling within their developer environments is a testament to the perceived value of AWS’s security proposition.
When directly questioned about these competitive dynamics, Kapoor deftly reframed the narrative. "Who is the competitor?" he posed. "I can keep thinking about Anthropic and OpenAI to be partners. I don’t understand the word ‘competitor’ in your description of the question." He further emphasized, "They’re partners with us. We use their models. We plug into their environments. Which is why we actually brought them together to do this." Kapoor’s rationale is that relying on a single AI model provider would be inherently limiting, given the rapid pace of innovation in the field. "I don’t think it’s good enough to just do it with one company," he stated. "Everybody is going to leapfrog each other over a period of time." By shouldering token costs and presenting a unified billing solution, AWS effectively positions Continuum as foundational infrastructure rather than a mere model wrapper. The enduring competitive asset, in this strategic view, is the orchestration harness, not the AI engine itself. As Kapoor articulated in his blog post detailing the partnership, "An AI harness is the orchestration layer that wraps around a model to connect it to tools, guardrails, memory, and workflows, so it delivers outcomes. Think of the model as the engine and the harness as everything around it. You need both to have a high-performance car."
This perspective is echoed by AWS partners. Val Henderson, CEO of AWS Premier Partner Caylent, commented to CRN, "Model choice was never the hard part for enterprises. Trust in what the model does in production is."
The second major announcement from AWS at Black Hat significantly enhances Security Hub Extended by introducing supply chain security as its tenth dedicated category, featuring Chainguard and Socket as curated partners. The Extended plan now encompasses 23 curated partner solutions, all consolidated under a single AWS bill with no long-term commitment requirements. This comprehensive offering spans endpoint, identity, email, network, data, browser, cloud, AI, security operations, and the newly added supply chain security.
Michael Fuller, AWS’s director of security services, explained that customer demand was the primary driver for the inclusion of supply chain security. "Over the last six to eight months, it’s gotten quite a bit of news around what’s happening in the supply chain space, with the fact that everybody builds on open source," Fuller observed. "Our customers quickly reached out and said, ‘Security Hub Extended is resonating. We would love to see a supply chain security category with some key players there because it’s a hot topic for us.’"
The selection of Chainguard and Socket was deliberate, aiming for complementary rather than overlapping capabilities. Chainguard specializes in providing hardened, secure-by-default container images and packages meticulously rebuilt from verified source code. Socket, on the other hand, focuses on behavioral monitoring of packages as they are integrated into a developer’s environment, actively detecting threats such as typosquatting, maintainer account takeovers, and obfuscated malicious code. "Together, between the three of us – us with consolidating that, ChainGuard providing really good hardened and cleaned images and packages, and then Socket providing a behavioral analysis over the top – gives customers a really good holistic supply chain security offering," Fuller stated.
This complementary approach addresses two distinct attack vectors. An attacker might publish a malicious package that contains no known vulnerabilities, a threat mitigated by Chainguard’s clean-build methodology. Alternatively, an attacker could compromise a legitimate maintainer’s account and introduce a tainted update to a trusted package, a scenario that Socket’s behavioral detection mechanisms are designed to identify. Fuller emphasized that both vectors are amplified in the AI coding era, as AI agents are susceptible to the same supply chain risks as human developers: "Agents can be misled on, ‘Hey, this is a well-known package that you’re looking for,’ and therefore pull it down, even though it’s been maliciously obfuscated."
The partner selection strategy behind Security Hub Extended reflects a deliberate philosophy that distinguishes it from the broader AWS Marketplace, which already hosts tens of thousands of security offerings. Fuller explained that customers articulated clear principles for their desired marketplace experience: "One was don’t give me hundreds of offerings. We already have the AWS Marketplace. Two was give me a sweet spot. Our customers were saying, give me two in each category, and when you look at those two, don’t give me head-to-head competitors. Give me one that I may know well, that is an established player, and give me one that’s taking a different approach."
Fuller cited the security operations category as a prime example of this strategy, featuring "Splunk, hard to argue not an established leader in security operations, and then you have Seven AI that’s kind of taking a very different approach, and they’re complementary in a lot of ways."
The decision to build internally versus partner follows a similar logic. For areas where AWS lacks a structural advantage, such as endpoint detection and response, it exclusively partners. For cloud security, AWS develops its own native tools due to its deep understanding of its own infrastructure, but still partners with providers like Upwind to offer customers additional choice. "At the end of the day, what we’re trying to do here is ensure that our customers can operate in the most secure way possible on AWS, not necessarily grow a large security business as the core goal," Fuller remarked. "That’s why it’s very easy for us to decide to do both building ourselves, but also then inviting partners to participate."
The pricing model further enhances accessibility. Fuller indicated that customers expressed a demand for pay-as-you-go options alongside traditional multi-year commitments. "All of the Security Hub Extended offerings have a public-facing, pay-as-you-go price, just like our first-party offerings do within AWS," he stated. "So that gives customers the option to go kick the tires, get going, even scale up and use the services without going through a traditional sales cycle."
Both AWS executives addressed an emerging security concern that is rapidly gaining traction among CISOs: the proliferation of unregistered AI agents, colloquially termed "shadow agents." These agents enable novel attack patterns that pose significant risks. Kapoor acknowledged that shadow agents represent a genuine and escalating problem, though he carefully differentiated it from the Continuum announcement. "There are many agents that are registered with registration directories, whether it’s Vertex, whether it’s Agent Core, whatever else it might be, but there are many agents that are not registered with the registry, and those are what people are calling shadow agents because they can actually do some harm," he explained. "Discovering shadow agents is not easy. The industry is working on it."
Fuller provided more granular insights into AWS’s existing countermeasures. Security Hub now incorporates a free AI inventory capability that utilizes three data layers: AWS Config identifies AI-related services like SageMaker, Bedrock, and Agent Core across an organization; Amazon Inspector scans compute instances and containers for AI-related software; and GuardDuty compares DNS request and response logs against known AI tools and agentic workloads.
Beyond inventory management, Fuller revealed that GuardDuty now actively monitors data plane events, including prompts, prompt volume patterns, and inference cost analysis, to detect what AWS terms "cost harvesting." This attack vector mirrors the widespread cryptocurrency mining that became prevalent after cloud credential compromises. An attacker gains access to an AWS account and illicitly consumes as much free AI inference as possible before detection. "We’re seeing what we’re calling cost harvesting," Fuller stated. "They’ll spin up, basically try to get as much free inference as they can until that’s discovered." He noted that this phenomenon is "the same thing that’s happening in AI" as occurred with crypto mining, and GuardDuty’s established capabilities for detecting credential compromise and unauthorized compute usage are directly applicable to this new threat.
Although both announcements were made in close proximity, AWS is strategically treating the underlying products as distinct. Kapoor described Continuum to VentureBeat as a standalone product, separate from Security Hub Extended. AWS has declined to discuss its longer-term roadmap for these initiatives. However, the design logic clearly indicates an integrated vision. Continuum is designed to secure the code that enterprises develop and the open-source components they integrate. Security Hub Extended, conversely, addresses all other aspects of enterprise security. The newest category within Security Hub Extended, supply chain security, represents the clearest area of overlap. Continuum’s validation phase scrutinizes third-party dependencies alongside a customer’s proprietary code, while Chainguard and Socket harden and monitor these same packages from an external perspective. One capability is developed in-house, the other curated from partners, and both converge on the same critical attack surface.
Both initiatives are underpinned by a common premise: enterprises are no longer seeking exhaustive catalogs of security solutions; they desire informed recommendations. "Customers want an opinionated point of view on how they should do security in the AI era," Kapoor asserted. "That’s what Security Hub Extended was about – actually going off and giving them our opinion." AWS will continue to offer customers choice, he added, "whether it is something that we ship or whether it is something from a partner." This doctrine of providing a curated recommendation, coupled with an escape hatch for alternative solutions, forms the connective tissue between the curated marketplace and the first-party agent platform, rendering the boundary between them more fluid than the existence of two separate announcements might suggest. Security Hub has already integrated capabilities that were nascent a year ago, including the free AI inventory and cost harvesting detection features detailed by Fuller. The console serves as the primary interface through which AWS delivers its security opinion to enterprises. Continuum, in this context, represents the most potent expression of that opinion to date.
The audience for this informed guidance has also evolved, according to Kapoor. He posited that the advent of advanced AI models like Mythos has elevated security from a CISO-level responsibility to a CEO and board-level imperative. "Boards are now asking for updates on what’s going on with security in the enterprise because it’s a business threat now, it’s a business risk."
The twin launches at Black Hat align with a broader strategic trajectory that AWS has been aggressively pursuing throughout 2026. The company significantly reimagined Security Hub at re:Invent 2025 by consolidating GuardDuty, Inspector, CSPM, and Access Analyzer into a unified console. In February, Security Hub Extended was launched with 14 curated partner solutions, expanding to 21 across nine categories by May, and now stands at 23 across 10 categories. Continuum, initially introduced at the New York Summit in June, saw significant expansion with integrations into OpenAI and Anthropic’s environments at Black Hat in August.
AWS reported $42.2 billion in revenue for the second quarter of 2026, with cloud sales experiencing a robust 37% year-over-year expansion. The company commands a substantial 28% share of the global cloud infrastructure market, leading its closest competitors, Microsoft (20%) and Google (15%). Fuller stated that AWS serves "tens of thousands of customers using one or multiple of our security services, essentially across all geos that we operate in, and in every industry, and both commercial and government." The Extended plan aims to leverage this extensive customer base, converting them into users of partner security solutions, thereby deepening engagement and solidifying AWS’s position as the default platform, making it more challenging for competitors to displace.
By assuming the role of seller of record for 23 partner security solutions and embedding Continuum within the coding environments of OpenAI and Anthropic, AWS is constructing a framework that transcends a mere product line. It is building the essential connective tissue that links enterprises to every AI model they utilize, every open-source package they integrate, and every security vendor they deploy. In an era where frontier AI models are advancing at such a pace that today’s cutting-edge vulnerability scanner quickly becomes tomorrow’s baseline requirement, the enduring element is not the model itself, but the orchestration harness that seamlessly connects the model to the customer’s environment, policies, and risk tolerance.
Kapoor, reflecting on a chance encounter on a flight to Black Hat, offered a poignant summation of the current security landscape. A former CISO, now a CTO, confided his unease: "I don’t feel safer now." Kapoor’s response, he shared with VentureBeat, was equally direct: "We’re working on it." Ultimately, the success of AWS’s endeavors may hinge on whether that work fundamentally makes the world safer, or simply makes AWS indispensable to every organization striving to achieve that goal.

