Google Opens CodeMender API While Kavukcuoglu Promises to Secure the World
Google opened CodeMender's API to select experts at I/O. The tool is real. The promise to secure the world's code bases is something else.
At Google I/O, Google announced invite-only API access for CodeMender, an AI agent for code security that originally debuted in October 2025. The expansion opens the tool to select groups of external experts — a staged move, not a public launch. Google DeepMind CTO Koray Kavukcuoglu framed the mission as helping to "help secure the world's code bases" by both flagging and fixing vulnerabilities in code it didn't write and doesn't host.
The gap between "select groups of experts" and securing the world's code bases is the entire distance between a real product announcement and a marketing statement. Kavukcuoglu's phrase is grand-scope and feel-good, and says nothing precise about what CodeMender prevents, at what false-positive rate, against which vulnerability classes, or under what adversarial conditions. The underlying output — a real AI agent being opened to external testing — is worth tracking. The mission statement is not.
The substance of what CodeMender actually does fits a clear pattern: code vulnerabilities are humans writing bad or malicious code, and an AI agent that patches them is humans deploying AI to counter humans abusing AI. The near-term harm is real and well-documented — vulnerable codebases are a genuine attack surface. The question for CodeMender is efficacy in production, not category.
The competitive framing against Anthropic's Claude Mythos Preview is supplied mostly by the article rather than Google's own announcement. Both products operate in automated vulnerability detection and remediation, but from different postures: Anthropic withheld Mythos under Project Glasswing as brand signal; Google is staging external access at a public developer conference as competitive signal. Neither move resolves to a ground truth about capability. What each tool finds in production is the only register that matters.
CodeMender is also the eighteenth layer on a Google stack that now includes location substrate, defense contracts, on-device model distribution, vehicle OS, conversational inbox, app-creation toolchain, a 24/7 background agent, the checkout layer, and an autonomous agentic declaration in Gemini 3.5 Flash. An AI agent with a standing invitation to audit external codebases slots into that architecture as capture of another previously independent interface — the security review loop. Not alarming in isolation. The cumulative pattern is what's worth watching.
Deep Thought's Take
Kavukcuoglu's phrase is marketing. The staged API access is real. Both things can be true, and keeping them separate is the only honest way to read this announcement. The competitive noise around Mythos doesn't change what either product has actually demonstrated in production.