Anthropic’s Cyber Verification Program is getting a serious upgrade. On Tuesday, the company announced it’s folding two of its security-access initiatives (the original Cyber Verification Program and Project Glasswing) into one expanded three-tier offering that gives vetted defenders access to Claude’s most powerful models with the usual cyber guardrails dialed down or removed entirely.
Here’s the catch: the exact same AI capability that finds a zero-day in your codebase could find one in someone else’s. Anthropic knows it. That’s why every tier of the new CVP ships with its own verification requirements, and the top tier is vetted jointly with the U.S. government.
What the three tiers actually get you
All three tiers include Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models. The difference is how much the blocking classifiers get in the way.
Defense Access is the broadest door. It covers SOC work, incident response, malware reverse engineering, and vulnerability analysis. Eligible applicants include corporate security teams defending their own systems, critical infrastructure operators, small security firms, open-source maintainers, universities, and individual researchers with a track record of reported vulnerabilities. Anthropic says it aims to respond to these applications within a few days.
Red Team Access adds authorized penetration testing and red-teaming against systems the applicant is permitted to test. This one is organizations only — individual researchers don’t qualify, and reviews take a few weeks. Qualifying applicants get Defense Access in the meantime. One hard line remains: actions that could cause physical harm or mass disruption, like deploying ransomware, are still blocked in real time.
Specialized Access has the fewest cyber blocks, and the guest list is tiny. It’s reserved for organizations authorized to test safety-critical systems — power grids, flight operations, telecom networks, interbank transfer infrastructure. Anthropic vets each applicant for this tier together with the U.S. government, and existing Glasswing members are transitioning into it.
The numbers behind the move
Anthropic isn’t doing this on faith. The case studies come from Glasswing, the retired predecessor program. Through it, partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026 alone. More than 33,000 of those were rated critical or high-severity. Anthropic’s own open-source scanning found another 5,500 vulnerabilities between April and October, and the company says the true impact is likely at least five times higher than the verified count.
Only 2 of 300 Anthropic-flagged vulnerabilities — 0.67 percent — have been actively exploited in the wild, per VulnCheck data cited in coverage of the announcement. That’s the optimistic read: the defenders are finding them before the attackers are.
And partners including Booz Allen and Comcast reported that Claude Mythos accelerated their vulnerability-detection timelines by months or even years.
How Anthropic tested the tiers
The company also published internal benchmark results from CyScenarioBench, its cyber-capability evaluation. They’re worth reading with the usual salt: these are company-run numbers, not independently validated.
Across 50 trials, a model with no CVP access was blocked on every task. Defense Access blocked 46 of the 50. And in the Red Team tier? No blocks at all. “In the Red Team Access tier, no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks — effectively equivalent to the model’s 67.6% success rate on this evaluation with no safeguards applied,” Anthropic wrote, per AI Weekly’s report.
That number is the whole argument for the program in one line. Defense-tier filtering keeps a meaningful barrier up for everyday users. But for vetted professionals, the filters were getting in the way of legitimate work. So Anthropic is opening the tap carefully, in three stages, with a government checkpoint at the top.
The catch nobody’s hiding
There are a couple of strings attached. Organizations in the new program must agree to data retention so Anthropic can monitor for misuse. A forthcoming Enterprise Frontier Safeguards service will let eligible customers store data in their own controlled cloud infrastructure instead; until then, organizations with zero data retention can use CVP with Opus 5.5, Sonnet 5.5, or the Frontier models with zero data retention.
That tradeoff — hand your data to Anthropic for monitoring, or wait for the zero-retention tier — is going to be the conversation in enterprise security shops this week. IDC analysts quoted in coverage of the launch warned that enterprises should layer additional controls of their own when agents get reduced safeguards or privileged access. Fair. Anthropic vetting you doesn’t mean your agent can’t be tricked.
Why this matters
Context counts here. This is the same week Jamie Dimon told Bloomberg TV that Anthropic’s Mythos pushed AI cyber risk “up 10-fold” at banks. The U.S. government is simultaneously scrutinizing which AI models get to touch critical systems, and Anthropic’s Pentagon fight over Claude’s military use is still working through appeals courts.
So the CVP expansion is Anthropic answering two audiences at once. To defenders: here’s the most capable AI we’ve built, with the training wheels off, because you need it to find flaws faster than the bad guys. To regulators: we’re not handing it to everyone — the scariest access level gets a joint review with the U.S. government.
It’s a reasonable stance. Whether the vetting holds is the entire question.
Sources: Reuters, The Decoder, SecurityWeek, AI Weekly
FAQ
What is Anthropic’s Cyber Verification Program?
It’s a vetting program that gives approved security professionals access to Claude’s most capable models with cyber safety filters reduced or removed, so defenders can use the same AI power attackers might. The revamped version combines the original CVP with Project Glasswing into three tiers: Defense, Red Team, and Specialized Access.
How many vulnerabilities did Project Glasswing find?
Partners in the now-folded-in Project Glasswing uncovered at least 129,000 verified software vulnerabilities between April and July 2026, with more than 33,000 rated critical or high-severity, according to Anthropic.
Who can apply for the Anthropic Cyber Verification Program?
Defense Access is open to corporate security teams, critical infrastructure operators, open-source maintainers, universities, and individual researchers. Red Team Access is limited to organizations. Specialized Access is reserved for entities vetted jointly with the US government to test safety-critical systems like power grids and banking infrastructure.
Does Anthropic remove all safety restrictions in the Cyber Verification Program?
No. Restrictions are tiered. Defense Access still blocks most real attack work, Red Team Access permits authorized penetration testing but blocks actions like deploying ransomware in real time, and Specialized Access has the fewest restrictions.
