Anthropic Cyber Verification Program Expands Access for Security Teams
-
- by THEFLGHT,
- October 07, 2026
- in Artificial-Intelligence
The Anthropic Cyber Verification Program now offers three access tiers that let vetted security professionals use the company’s strongest models with fewer cyber restrictions. Anthropic launched the expanded program on October 6 after combining its original verification initiative with Project Glasswing.
The expanded program establishes four important controls:
- Defense, Red Team and Specialized access tiers.
- Identity and security-control checks for every applicant.
- Broader access to Opus, Sonnet and Mythos models.
- Monitoring and data retention to detect misuse.
Anthropic Cyber Verification Program Adds Three Tiers
Anthropic’s announcement says every tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models. The program changes which requests those systems will block according to the applicant’s verified work and the risks of the systems being tested.
Defense Access covers activities such as incident response, malware analysis and vulnerability validation. Company, university, nonprofit and government security teams may apply, alongside critical-infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a record of responsibly reported flaws.
Red Team Access adds authorized penetration testing and adversarial security assessments. It is limited to organizations, and Anthropic expects reviews to take several weeks. Controls remain in place against actions that could cause physical harm or mass disruption, including ransomware deployment and attacks on high-risk safety systems.
Specialized Access has the fewest cyber blocks. Anthropic reserves it for a small number of organizations authorized to test systems such as power grids, flight operations, telecom networks and interbank transfers. The company says it reviews these applicants with the U.S. government.
Project Glasswing Reported 134,500 Verified Vulnerabilities
The expansion follows six months of work through Project Glasswing and the earlier Cyber Verification Program. Glasswing partners reported at least 129,000 verified software vulnerabilities between April and July 2026, while Anthropic’s open-source scanning found another 5,500 between April and October.
More than 33,000 of those vulnerabilities have been rated critical or high severity. Anthropic describes the totals as a lower bound because its analysis includes partial data from 33 partner reports, organizations used different triage methods and fewer than half disclosed how many flaws they had patched.
Reuters independently reported the program’s structure and the vulnerability totals. The figures show discovery volume, not a complete count of fixed issues, independently audited model performance or proof that each finding would have been exploitable in a production environment.
That distinction is important because automated scanners can create a large review burden. Organizations still need human triage, coordinated disclosure and testing to confirm severity and avoid releasing exploit details before maintainers can ship fixes.
Background Reading
Reduced Cyber Blocks Come With Monitoring
Anthropic tested how the tiered controls behaved on CyScenarioBench, which asks models to plan and execute multi-stage cyber operations. The generally available model blocked every one of 50 trials on the first prompt, while the Defense tier blocked 46 trials at some point and allowed four to succeed.
In Red Team Access, Opus 5.5 encountered no blocks and completed 34 of 50 trials. Anthropic says that result was effectively equivalent to the model’s 67.6% success rate without safeguards, which represents the behavior expected under Specialized Access.
The evaluation is company-run and covers ten benchmark challenges attempted five times in each configuration. It demonstrates that the classifiers produce materially different access levels, but it does not establish how reliably the controls distinguish legitimate testing from abuse across every real network and toolchain.
Organizations enrolled in the program must accept data retention so Anthropic can monitor for misuse. The company says a forthcoming Enterprise Frontier Safeguards product will combine zero data retention with security controls by letting eligible customers store information in infrastructure they control.
Security Teams Must Prove Authorization and Controls
Applicants must provide evidence that they meet the verification and security requirements of the requested tier. Existing Cyber Verification Program members will keep their previous settings and be evaluated automatically for access to the newer Opus, Sonnet and Mythos models.
The service is available through the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. Amazon Bedrock access is limited to customers eligible for Enterprise Frontier Safeguards, making cloud availability dependent on both the access tier and the platform’s data-control arrangement.
The program addresses a real dual-use problem. The same model behavior that helps a defender find a hidden memory flaw can help an attacker reproduce or exploit it. Broadly weakening safeguards would increase misuse risk, while blocking advanced testing can leave defenders without tools that adversaries may eventually obtain elsewhere.
The next evidence will come from application volume, approval times, disclosed fixes and misuse incidents under the new tiers. Independent assessments will also need to test whether Anthropic’s verification, monitoring and real-time blocks protect sensitive systems without preventing legitimate defenders from completing authorized work.
0 Comments:
Leave a Reply