ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI information
Anthropic Expands Cyber Verification Program: Three Tiers Open Its Strongest Models to More Security Teams

Anthropic Expands Cyber Verification Program: Three Tiers Open Its Strongest Models to More Security Teams

AI information • Admin • • 8 views

Anthropic announced an expanded Cyber Verification Program (CVP) on its official news page on October 6, 2026, merging the previously separate Project Glasswing and the original CVP into a single tiered system. Vetted security professionals can use Claude models with reduced cyber safeguards — including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 — for defensive work and authorized testing.

Why a separate door exists at all

Cyber capability is inherently dual use: a model that helps a defender find a vulnerability can also help an attacker exploit one. Anthropic's generally available models therefore carry conservative cyber safeguards that block most offensive-security requests — which also shuts out legitimate defenders. For the past six months, two programs opened a narrow door to trusted organizations: Project Glasswing for groups securing critical software, and the CVP for vetted security teams. The expansion merges the two into one tiered entrance.

What each of the three tiers allows

Defense Access covers security operations, incident response, malware reverse engineering and vulnerability analysis. The expected applicant pool is broad: security teams at companies, nonprofits, universities and government bodies, operators of critical infrastructure such as regional hospitals and municipal utilities, smaller security firms, open-source maintainers, and individual researchers with a track record of reported vulnerabilities. Anthropic says it aims to respond within a few days.

Red Team Access adds authorized penetration testing and red-teaming on top of defensive work, and is for organizations only — individual researchers are not eligible. Review takes a few weeks, with Defense Access granted in the meantime. It is not unlimited: actions that could cause physical harm or mass disruption, such as deploying ransomware or damaging physical systems, are still blocked in real time.

Specialized Access has the fewest blocks and is reserved for a small set of deeply vetted organizations authorized to test safety-critical systems — flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government networks — with each review conducted in collaboration with the US government. Existing Project Glasswing members move into this tier.

After tiering the safeguards, do they still hold?

Anthropic published a comparison from CyScenarioBench, an evaluation of ten multi-stage cyber-operation scenarios, running Claude Opus 5.5 five times per scenario in each tier. Without CVP access, every task was blocked at the first prompt. In Defense Access, 46 of 50 trials were blocked at some point and four succeeded. In Red Team Access, nothing was blocked, and 34 of 50 tasks were completed — essentially the same completion rate as with no safeguards applied.

The point of those numbers is that tiering does not remove the safeguards; it binds blocking strength to how deeply the applicant was vetted. A second figure comes from Project Glasswing: between April and July 2026, partner organizations used Claude Mythos models to uncover at least 129,000 verified software vulnerabilities.

Two constraints deserve attention. Enrolled organizations must accept data retention so Anthropic can monitor for misuse; Enterprise Frontier Safeguards, a solution combining zero data retention with robust safeguards, is expected later this fall. And the whole system — review standards and tier placement — is run by Anthropic itself; whether it holds up at application scale will only be clear once more organizations complete the process. For security teams, the practical step now is concrete: match your work to the tier whose scope fits it, then apply.

Recommended Tools

More