AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push
The summary is cut off mid-sentence, so I’ll pull the VentureBeat piece and the official AWS announcement and write the paragraphs only from those facts.The…
By Dillip Chowdary • Aug 15, 2026 • Source: VentureBeat
What happened
The summary is cut off mid-sentence, so I’ll pull the VentureBeat piece and the official AWS announcement and write the paragraphs only from those facts.The request is body copy only, not a full publish. I’ll read the source articles next so the paragraphs stay on verified names, numbers, and mechanics.VentureBeat blocked the fetch. I’ll pull the rest of the details from the official AWS post and secondary coverage so the paragraphs stay factual.Amazon Web Services announced at Black Hat USA 2026 this month that Continuum, its platform for code vulnerabilities, will integrate directly into Anthropic Claude Code and OpenAI Codex, alongside AWS’s own Kiro IDE. VentureBeat described the move as AWS threading its AI-powered security infrastructure into the coding environments built by two of its fiercest rivals, and as a bet that controlling the security layer matters more than controlling the model. Continuum for code vulnerabilities is in preview. The Claude Code, Codex, and Kiro integrations are listed as coming soon. Chet Kapoor, vice president of security, search and observability at AWS, wrote that the work extends Continuum into the workflows where code is being written so developers can discover, contextually prioritize, validate, and remediate without leaving those tools.
The mechanism is more specific than a scanner badge in a sidebar. Inside Claude Code, Codex, and Kiro, on-demand vulnerability scans flag potential issues and send those findings to Continuum. Continuum then ranks them against the customer’s actual AWS environment, using configurations, AWS Identity and Access Management policies, network topology, and exposure surfaces rather than a generic severity score. It validates candidates in a sandbox and returns prioritized, contextual intelligence to the coding assistant, which is supposed to adjust its next recommendations. AWS calls the internals an agent-team loop: a harness that selects a model per task, connects into the customer environment, and treats that orchestration the way AWS already treats identity, discovery, policy, observability, and compliance. The company says different frontier models excel at different steps, and Continuum is the layer that picks the model for detection, prioritization, validation, or remediation instead of leaving that stitching to each security team.
The technical detail

For engineers and builders, the claimed win is that the old write, scan, triage, prioritize, fix, and rescan chain collapses into the suggestion sitting in the editor. Existing estates use Continuum for code vulnerabilities from AWS to work across an environment. Greenfield work is supposed to use a Continuum plugin inside Codex, Claude Code, or Kiro so suggestions arrive already security-validated. That matters if you already generate code in those assistants and then lose a day pushing findings through a separate AppSec queue that does not know your IAM graph or which subnet is actually reachable. It also matters if your team has been building shadow orchestration to glue models, agents, and scanners together every time a model or framework ships. AWS is arguing that the harness is the product and that customers should stop reimplementing it.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Why it matters for builders
The competitive read is the part VentureBeat stressed. AWS competes with both OpenAI and Anthropic across cloud AI services. Amazon holds a large investment in Anthropic. OpenAI runs its own growing infrastructure that competes for the same enterprise AI workloads. Both still agreed to embed Continuum inside their developer environments. That is not AWS winning the coding-model race. It is AWS trying to sit under whichever model the developer already opened, the same way a cloud security control plane sits under whichever compute the app already uses. In the same Black Hat window AWS also expanded Security Hub Extended, including supply-chain signals meant to catch malicious dependencies before they land in an application, which is the other half of securing AI-generated code: the packages the assistant pulls in, not only the lines it writes.
Market and competitive context
What to watch next is whether the plugin actually ships into Claude Code and Codex rather than remaining a preview blog post, and whether sandbox validation changes what the assistant proposes or only annotates it. Early design partner Rivian, through CISO Mike Johnson, said Continuum connecting source code with enterprise knowledge lets teams pinpoint vulnerabilities that are truly meaningful and shortens the timeline to fix serious ones. That is the test: fewer noise tickets, faster real fixes, and recommendations that reflect IAM and network exposure, not another unranked list. Request access remains the path for Continuum for code vulnerabilities. The IDE integrations are still coming soon, so the operational question for platform teams is how they will authenticate the plugin, what data leaves the repo into Continuum, and how findings round-trip into existing ticketing and policy gates.
What to watch next
Open questions sit on both the trust and the architecture sides. Findings that originate in a rival coding agent and get scored by AWS against AWS-only context will be incomplete for workloads that are not on AWS, or that span accounts Continuum cannot see. A sandbox validation that does not reproduce production IAM, identity federation, or data-plane paths will still ship confident remediations that fail in production. There is also a data-path question: on-demand scans sending code findings from Claude Code or Codex into Continuum is a new egress surface, and preview software in an agent loop that can rewrite suggestions is a supply chain of its own. Related prior art is the rest of the agentic AppSec stack AWS has been assembling, from Continuum’s earlier preview for code vulnerabilities to Security Hub Extended and partner rule sets, plus the Frontier Model Forum work AWS cites for shared evaluation of which model should run which security step. The unresolved issue is not whether models can find more bugs. It is whether a single harness owned by the cloud provider, sitting inside two competing coding products, becomes the control point teams actually accept.
Advertisement