i
News
News · 2026-10-06

Anthropic expands cyber access through three tiers for vetted defenders

@neuronium_ai @neuronium_ai

Anthropic is widening its Cyber Verification Program, folding Project Glasswing into a tiered system that gives more vetted organizations access to Claude’s cyber capabilities. The change formalizes a distinction the company has been managing for six months: public models remain constrained, while approved defenders can use less restricted versions for security work. Anthropic’s own tests suggest the tiers can separate routine defense from authorized attack simulation, though the announcement leaves open how well those safeguards will hold beyond a benchmark.

Cover: Anthropic expands cyber access through three tiers for vetted defenders

Three levels of access

Anthropic is replacing two separate programs with three access levels, each matched to the applicant’s work and subject to its own vetting and safeguards.

Defense Access covers defensive work such as security monitoring, incident response, malware reverse engineering, and vulnerability analysis. Eligible applicants include security teams responsible for their own systems, critical-infrastructure operators, small security companies, open-source maintainers, and experienced vulnerability researchers. Anthropic expects many defensive organizations to qualify and says it aims to respond within days.
Red Team Access adds authorized penetration testing and red-team work. It is open to corporate and government red teams, cybersecurity companies, and penetration-testing firms. Applicants may test only systems they are authorized to assess. Safeguards still block activity that could cause physical harm or widespread disruption, including ransomware deployment and testing safety-critical systems. Reviews may take several weeks; eligible applicants will receive Defense Access while they wait. Individual researchers cannot apply for this level.
Specialized Access has the fewest cyber restrictions and is reserved for vetted organizations authorized to test systems that could affect lives or disrupt markets, including flight-control systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks. Anthropic says it is reviewing each organization in detail with the US government. Project Glasswing participants will move to this level without being reapproved for models they already have.

Public models will still support code review, fixes for known issues, searches for vulnerabilities in a user’s own source code, and triage of security alerts.

CVP participants must retain data so Anthropic can monitor misuse. Later this fall, the company plans to release Enterprise Frontier Safeguards, which it says will combine the privacy of zero-data-retention mode with robust safeguards. Until then, participants with Claude Fable 5.1 or Claude Mythos 5.1 in zero-data-retention mode can also use CVP without retaining data.

Overview of the Cyber Verification Program tiers.

Overview of the Cyber Verification Program tiers.

Source: anthropic.com

What the benchmark shows

Anthropic tested Claude Opus 5.5 on CyScenarioBench, which measures whether models can plan and carry out multi-step cyber operations in realistic settings. The company ran each of the benchmark’s 10 tasks five times at each access level.

Without CVP access, every task was blocked at the first prompt.
With Defense Access, a block occurred in 46 of 50 runs; the model completed the other four tasks.
With Red Team Access, there were no blocks, and Claude Opus 5.5 completed 34 of 50 tasks. That is close to the 67.6% score from the model without cyber safeguards, which Anthropic uses as a benchmark for Specialized Access.
On CyScenarioBench, our safeguards blocked 46 of 50 tasks on Claude Opus 5.5 in the Defense Access tier, while the Red Team Access tier on Claude Opus 5.5 did not block any tasks, and completed 34 of 50—the same completion rate as when no safeguards are applied.

On CyScenarioBench, our safeguards blocked 46 of 50 tasks on Claude Opus 5.5 in the Defense Access tier, while the Red Team Access tier on Claude Opus 5.5 did not block any tasks, and completed 34 of 50—the same completion rate as when no safeguards are applied.

Source: anthropic.com

Anthropic says the results show it can extend advanced cyber capabilities to more defenders while continuing the work started with Project Glasswing. It also plans to keep improving classifiers that account for access levels.

These results represent a lower bound on the program’s impact on third-party code, as they’re based on partial data from 33 partner reports and Anthropic’s open-source partnerships. Data limitations include that organizations took different approaches to triaging, and fewer than 50% of partners disclosed patched numbers, often because their fixes were still in progress, so the patch rate is significantly undercounted.

These results represent a lower bound on the program’s impact on third-party code, as they’re based on partial data from 33 partner reports and Anthropic’s open-source partnerships. Data limitations include that organizations took different approaches to triaging, and fewer than 50% of partners disclosed patched numbers, often because their fixes were still in progress, so the patch rate is significantly undercounted.

Source: anthropic.com

The evidence is useful but narrow: it describes one model on one benchmark, not how often the tiers will block harmful activity in day-to-day use. I think that is the harder question behind this expansion. The program’s value depends not only on letting legitimate teams do more, but on whether Anthropic can reliably distinguish their work from misuse as access broadens.

The scale of Glasswing’s findings

Project Glasswing partners found at least 129,000 confirmed software vulnerabilities from April to July 2026 using Claude Mythos. Anthropic found another 5,500 confirmed vulnerabilities in its own open-source project reviews from April to October 2026.

More than 33,000 confirmed vulnerabilities have already been rated critical or high severity. Anthropic cautions that the figure is based on a survey of only some Glasswing partners and expects the actual impact could be at least five times greater. Several partners said finding the same number without Claude Mythos would have taken months or years longer.

Those figures make the case for expanding access, but they also expose a gap in the announcement: Anthropic has not yet provided a fuller accounting of how the vulnerabilities were verified or how many have been fixed. The company says it will share more about its work protecting open-source software and critical infrastructure in the coming weeks.

Applying and using CVP

Organizations can apply to CVP, where Anthropic will review each applicant and request evidence of safeguards appropriate to the requested level. Existing participants keep their settings for earlier models. Anthropic will assess their eligibility for Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 under the updated rules; administrators must separately assign access to the relevant workspaces.

CVP is available on Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry. On Amazon Bedrock, it is available only to customers with access to Enterprise Frontier Safeguards.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X