Anthropic on October 6, 2026 announced an expanded Cyber Verification Program that makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals across three access tiers. Each tier includes access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models going forward.
Anthropic described cybersecurity as inherently dual use, saying the same capabilities that let a security team find and fix a vulnerability can also help a malicious actor exploit it. The company said its generally available models, including Claude Opus 5.5, Claude Fable 5.1, and Claude Sonnet 5.5, carry conservative cyber safeguards that block most cyber work, an approach it said is intended to limit harmful activity by malicious actors while it works to reduce false positives for secure coding.
For the six months preceding the announcement, Anthropic provided trusted access through two programs: Project Glasswing, which gave organizations securing critical software access to Claude Mythos, and the original Cyber Verification Program, which gave vetted security teams reduced safeguards on Claude Opus and Claude Sonnet models. The two programs are now integrated into the single expanded offering. Anthropic said its generally available models remain usable by all users for tasks such as code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts.
Defense, Red Team, and Specialized Access
Defense Access covers defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities. Examples of qualifying organizations include security teams at companies, nonprofits, universities, and government bodies defending systems they own or maintain; critical-infrastructure operators of any size, such as regional hospitals or municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a track record of reported vulnerabilities. Anthropic said it expects many organizations conducting defensive cybersecurity work to qualify for this tier, and that it aims to respond to applications within a few days.
Red Team Access adds authorized penetration testing and red-teaming against systems an organization is authorized to test, including IT systems in critical industries. Examples of qualifying organizations include in-house red teams, government red teams, and security and penetration testing firms. Users in this tier still face real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or penetration testing high-risk safety systems. Anthropic said it expects applications at this tier to take a few weeks to review, enrolls qualifying organizations in Defense Access while their Red Team Access applications are reviewed, and limits the tier to organizations.
Specialized Access carries the fewest cyber blocks and is reserved for a limited set of verified organizations authorized to test safety systems that could affect people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks. Anthropic currently reviews every organization at this tier in depth in collaboration with the US government, and existing Project Glasswing members transition to this tier without requiring reapproval for current models.
According to the program’s Claude Help Center page, individuals may apply only for Defense Access and must be on a paid plan, while Red Team Access and Specialized Access are open to organizations only. Each organization files a single application, and Anthropic places the applicant at the highest tier supported by the information it receives, aiming to send a decision or a request for more information within seven business days. As part of the process, Anthropic verifies all applicants and requests proof of the required security controls for the relevant tier. The Help Center states that eligibility reflects factors including the nature of an organization’s work, Anthropic’s ability to verify who it is, the legal and regulatory environment it operates in, the risk of diversion or compelled access, and who the work is ultimately for, with a more cautious approach where an organization primarily serves military, intelligence, or law enforcement customers.
Safeguard Testing on CyScenarioBench
To assess the efficacy of the program’s protections, Anthropic ran Claude Opus 5.5 through CyScenarioBench, an evaluation it described as measuring whether models can plan and execute multi-stage cyber operations under realistic constraints, with safeguards tuned for the different CVP tiers. The testing covered five attempts at each of 10 challenges in each access tier.
Anthropic reported that without CVP access, every task was blocked on the first prompt. In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded. In the Red Team Access tier, no blocks occurred and Claude Opus 5.5 successfully completed 34 of the 50 tasks, which Anthropic described as effectively equivalent to the model’s 67.6 percent success rate on the evaluation with no safeguards applied, a result it said is representative of Specialized Access. The company said the evaluations give it confidence that advanced cyber capabilities can be made safely available to a broader set of defenders, and that it will continue to refine its tier-based classifiers over time.
Reported Vulnerability Figures From Project Glasswing
Anthropic said Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, and that its own open-source scanning efforts found an additional 5,500 verified software vulnerabilities between April and October 2026. More than 33,000 of these verified vulnerabilities have so far been rated critical- or high-severity, the company said.
The company described the figures as a likely undercount, noting they are based on survey data from only a subset of Glasswing partners, 33 partner reports in total, and said it expects the true impact to be at least five times higher. Anthropic said organizations took different approaches to triaging, and that fewer than 50 percent of partners disclosed patched numbers, often because their fixes were still in progress, so the patch rate is significantly undercounted.
When asked how long it would have taken to find the same number of vulnerabilities without Claude Mythos models, several partners told Anthropic the models had increased their rate of vulnerability finding by months or even years. The company pointed to published accounts from partners Booz Allen and Comcast about their experience.
Data Retention, Availability, and Application Details
Data retention is required for organizations enrolled in the program so Anthropic can monitor for cyber misuse. Once Enterprise Frontier Safeguards, a solution Anthropic described as combining the privacy of zero data retention with robust safeguards, becomes available in the fall of 2026, eligible organizations will be able to store data in cloud infrastructure they control. Until then, organizations with zero-data-retention access to Claude Fable 5.1 or Claude Mythos 5.1 can also use CVP with zero data retention.
CVP is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. On Amazon Bedrock it is available only to customers eligible for Enterprise Frontier Safeguards; the Help Center states that Amazon Bedrock does not yet support human review of automated safety flags, which CVP requires by default, and that Anthropic is working to expand CVP to all customers on Bedrock. Third-party platforms such as coding tools support Defense Access and Red Team Access only; Specialized Access is not available through them.
Organizations previously enrolled in Project Glasswing or CVP do not need to apply again; their existing access keeps working under their current terms, and they will be transitioned to the relevant new tier for Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Anthropic’s Usage Policy continues to apply in full, and the Help Center states the company may review, narrow, or withdraw a grant. Building a client-facing product on these capabilities is governed separately by Anthropic’s Cyber Productization Policy, with a productization application to become available to CVP users.
Defense Access organizations have until December 15, 2026 to adopt phishing-resistant multi-factor authentication and stop using API keys; until then, multi-factor authentication of some kind is required and API keys expire every seven days. Access to Mythos on third-party cloud providers trails application approval by approximately five business days. Anthropic has scheduled a webinar on the program for October 14, 2026 at 9 a.m. Pacific time.
Credit: Source link


























