Meta and Microsoft Reduce Internal Use of Claude AI
Meta and Microsoft are cutting internal Claude use while pushing their own coding assistants.
The Information reported that Meta and Microsoft are steering employees away from Anthropic's Claude toward their own coding assistants. Microsoft's forecast internal Anthropic spend, once above $1 billion a year, reportedly fell by more than a third, and many cloud and AI employees saw monthly limits cut from $100,000 to about $10,000, while customer use of Anthropic models on Microsoft platforms still grew. Meta's Claude Code users reportedly fell from about 60,000 to 30,000 as MetaCode and Muse Code gained users, even after Meta spent over $105 million on Claude Code in 28 days. The report also cites previously patched Claude Code issues CVE-2025-59536 and CVE-2026-21852 and Microsoft's RoguePilot Codespaces flaw as reasons to govern agent permissions.
- Microsoft's projected internal Anthropic spend fell by more than one third.
- Monthly AI limits dropped from $100,000 to about $10,000 per employee.
- Meta's Claude Code users fell from about 60,000 to 30,000.
- Patched Claude Code flaws enabled unauthorized execution and API key theft.
Vulnerabilities mentionedAll →
- CVE-2025-595368.726%Code Injection in Anthropic Claude Code Startup Trust Dialog (pre-1.0.111)published · Anthropic Claude Code
- CVE-2026-218525.325%API Key Exfiltration via Attacker-Controlled Base URL in Anthropic Claude Code
Full article488 words · extracted from gbhackers.com · click to collapse
Meta and Microsoft are reducing employee reliance on Anthropic’s Claude AI while promoting their own coding assistants, according to an October 5 report by The Information.
This change relates to internal budgets and development workflows, not a complete withdrawal of Claude from Microsoft’s customer offerings.
This reported shift highlights competitive tension, as both companies use Anthropic technology while also developing their own alternatives.
For cybersecurity teams, switching assistants raises important questions regarding permissions, credential exposure, and the security controls that govern automated development.
The CSN report indicates that Microsoft originally projected annual internal spending on Anthropic technology to exceed $1 billion. However, this forecast has reportedly dropped by more than a third after managers encouraged employees to reduce their use of Claude and favor GitHub Copilot and OpenAI models instead.
Monthly AI spending limits within Microsoft’s cloud and AI division have reportedly dropped from $100,000 per employee to about $10,000 in most cases, representing spending ceilings rather than each employee’s actual expenditure. Some engineers have expressed frustration with the reduced flexibility to experiment.
Nonetheless, these internal restrictions do not signal changes to customer availability; enterprise spending on Anthropic models through Microsoft platforms continues to grow.
Meta’s user count for Claude Code has reportedly declined from around 60,000 earlier this year to approximately 30,000. While layoffs contributed to this decrease, the report suggests a bigger factor is efforts to encourage adoption of Meta’s own coding tools.
These alternatives include MetaCode and Muse Code, which Meta models power. MetaCode has reportedly attracted more than 30,000 internal users, while Muse Code has exceeded 6,000 employee users. Additionally, Meta began testing Muse Code with external customers in August.
Despite this decline in user adoption, Meta reportedly spent over $105 million on Claude Code during a single 28-day period, indicating that user counts alone cannot determine whether overall expenditure has decreased.
Switching to proprietary assistants does not eliminate the security risks of agents accessing repositories, executing commands, or handling authentication credentials.
Previously disclosed vulnerabilities in Claude Code, specifically CVE-2025-59536 and CVE-2026-21852, allowed unauthorized execution and API key theft through repository-controlled settings.
Malicious configurations could exploit Hooks, Model Context Protocol integrations, and trust-validation weaknesses. Anthropic implemented fixes before making these issues publicly known.
Microsoft’s ecosystem has faced similar vulnerabilities. The patched RoguePilot vulnerability involved malicious instructions embedded in a GitHub Issue that manipulated Copilot within Codespaces.
Researchers demonstrated an attack chain that included a symbolic link, access to a privileged GitHub token, and exfiltration through a remote JSON schema request.
For security teams managing these migrations, the practical priority is to maintain consistent governance: treat repository content as untrusted, restrict agent permissions, enforce workspace boundaries, and issue minimally scoped, short-lived credentials across approved coding environments.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.