Three levels of access
Anthropic is replacing two separate programs with three access levels, each matched to the applicant’s work and subject to its own vetting and safeguards.
Public models will still support code review, fixes for known issues, searches for vulnerabilities in a user’s own source code, and triage of security alerts.
CVP participants must retain data so Anthropic can monitor misuse. Later this fall, the company plans to release Enterprise Frontier Safeguards, which it says will combine the privacy of zero-data-retention mode with robust safeguards. Until then, participants with Claude Fable 5.1 or Claude Mythos 5.1 in zero-data-retention mode can also use CVP without retaining data.
What the benchmark shows
Anthropic tested Claude Opus 5.5 on CyScenarioBench, which measures whether models can plan and carry out multi-step cyber operations in realistic settings. The company ran each of the benchmark’s 10 tasks five times at each access level.
On CyScenarioBench, our safeguards blocked 46 of 50 tasks on Claude Opus 5.5 in the Defense Access tier, while the Red Team Access tier on Claude Opus 5.5 did not block any tasks, and completed 34 of 50—the same completion rate as when no safeguards are applied.
Source: anthropic.com
Anthropic says the results show it can extend advanced cyber capabilities to more defenders while continuing the work started with Project Glasswing. It also plans to keep improving classifiers that account for access levels.

These results represent a lower bound on the program’s impact on third-party code, as they’re based on partial data from 33 partner reports and Anthropic’s open-source partnerships. Data limitations include that organizations took different approaches to triaging, and fewer than 50% of partners disclosed patched numbers, often because their fixes were still in progress, so the patch rate is significantly undercounted.
Source: anthropic.com
The evidence is useful but narrow: it describes one model on one benchmark, not how often the tiers will block harmful activity in day-to-day use. I think that is the harder question behind this expansion. The program’s value depends not only on letting legitimate teams do more, but on whether Anthropic can reliably distinguish their work from misuse as access broadens.
The scale of Glasswing’s findings
Project Glasswing partners found at least 129,000 confirmed software vulnerabilities from April to July 2026 using Claude Mythos. Anthropic found another 5,500 confirmed vulnerabilities in its own open-source project reviews from April to October 2026.
More than 33,000 confirmed vulnerabilities have already been rated critical or high severity. Anthropic cautions that the figure is based on a survey of only some Glasswing partners and expects the actual impact could be at least five times greater. Several partners said finding the same number without Claude Mythos would have taken months or years longer.
Those figures make the case for expanding access, but they also expose a gap in the announcement: Anthropic has not yet provided a fuller accounting of how the vulnerabilities were verified or how many have been fixed. The company says it will share more about its work protecting open-source software and critical infrastructure in the coming weeks.
Applying and using CVP
Organizations can apply to CVP, where Anthropic will review each applicant and request evidence of safeguards appropriate to the requested level. Existing participants keep their settings for earlier models. Anthropic will assess their eligibility for Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 under the updated rules; administrators must separately assign access to the relevant workspaces.
CVP is available on Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry. On Amazon Bedrock, it is available only to customers with access to Enterprise Frontier Safeguards.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X