×

Anthropic Expands Cyber ​​Verification Program to Three Access Levels – Unite.AI

Anthropic Expands Cyber ​​Verification Program to Three Access Levels – Unite.AI

Anthropic on October 6, 2026 announced an expanded cyber verification program that makes advanced cyber capabilities and reduced blocking classifiers available to qualified security professionals across three levels of access. Each level includes access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new future models.

Anthropic described cybersecurity as inherently dual-use, saying that the same capabilities that allow a security team to find and patch a vulnerability can also help an attacker exploit it. The company said its generally available models, including Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5, come with conservative cyber protections that block most cyber work, an approach it says is intended to limit malicious activity by malicious actors while working to reduce false positives for secure coding.

In the six months preceding the announcement, Anthropic provided reliable access through two programs: Project Glasswing, which provided organizations granting access to critical software to Claude Mythos, and the original Cyber ​​Verification Program, which provided audited security teams with reduced protections on the Claude Opus and Claude Sonnet models. The two programs are now integrated into a single expanded offering. Anthropic said its generally available templates remain usable by all users for tasks such as code review, patching known issues, finding vulnerabilities in proprietary source code, and triaging security alerts.

Defense, Red Team and Specialized Access

Defense Access covers defensive work, including security operations center and incident response activities, malware reverse engineering, and vulnerability analysis and validation. Examples of qualifying organizations include security teams at businesses, non-profit organizations, universities, and government agencies that defend systems they own or maintain; operators of critical infrastructures of any size, such as regional hospitals or municipal services; smaller security companies; open source maintainers; and individual researchers with a track record of reported vulnerabilities. Anthropic said it expects many organizations performing defensive cybersecurity work to qualify for this tier and that it aims to respond to requests within a few days.

Red Team Access adds authorized penetration testing and red-teaming against the systems an organization is authorized to test, including IT systems in critical industries. Examples of qualified organizations include internal red teams, government red teams, and security and penetration testing companies. Users at this level still face real-time blocks on actions that could cause physical harm or mass disruption, such as ransomware distribution, physical system corruption, or penetration testing of high-risk security systems. Anthropic said it anticipates applications at this tier will take a few weeks to review, enrolls qualified organizations in Defense Access while their Red Team Access applications are reviewed, and limits the tier to organizations.

Specialized access involves the fewest cyber locks and is reserved for a limited set of verified organizations authorized to test security systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecommunications networks, interbank transfer infrastructures, and government administrative networks. Anthropic currently thoroughly reviews each organization at this level in collaboration with the U.S. Government, and existing Project Glasswing members transition to this level without requiring reapproval for current models.

According to the program’s Claude Help Center page, individuals can only request Defense access and must be on a paid plan, while Red Team access and Specialized access are only open to organizations. Each organization submits a single application, and Anthropic places the applicant at the highest level supported by the information they receive, with the goal of submitting a decision or request for additional information within seven business days. As part of the process, Anthropic reviews all applicants and requires evidence of the security controls required for the relevant level. The Help Center says suitability reflects factors including the nature of an organization’s work, Anthropic’s ability to verify who it is, the legal and regulatory environment in which it operates, the risk of diversion or forced access, and who the work is ultimately aimed at, with a more cautious approach where an organization primarily serves military, intelligence, or law enforcement clients.

Safeguard test on CyScenarioBench

To evaluate the effectiveness of the program’s protections, Anthropic ran Claude Opus 5.5 via CyScenarioBench, an evaluation that measures whether models can plan and execute multi-stage cyber operations under realistic constraints, with protections optimized for different CVP levels. The test involved five attempts at each of the 10 challenges in each access level.

Anthropic reported that without CVP access, every task was blocked at the first prompt. In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks were successful. In the Red Team Access tier, no crashes occurred and Claude Opus 5.5 successfully completed 34 of 50 tasks, which Anthropic described as effectively equivalent to the model’s 67.6% success rate on the evaluation with no protection applied, a result it says is representative of specialized access. The company said the assessments give it confidence that advanced cyber capabilities can be safely made available to a broader set of defenders and that it will continue to refine its layer-based classifiers over time.

Vulnerability data reported by the Glasswing project

Anthropic said Glasswing partners discovered at least 129,000 verified software vulnerabilities between April and July 2026, and that its open source scanning efforts found another 5,500 verified software vulnerabilities between April and October 2026. More than 33,000 of these verified vulnerabilities have so far been classified as critical or high severity, the company said.

The company described the figures as a likely underestimate, noting that they are based on survey data from only a subset of Glasswing partners — 33 partner relationships in total — and said it expects the true impact to be at least five times higher. Anthropic said organizations took different approaches to triage and that fewer than 50% of partners disclosed patch numbers, often because fixes were still in progress, so the patch rate is significantly underestimated.

When asked how long it would have taken to find the same number of vulnerabilities without the Claude Mythos models, several partners told Anthropic that the models had increased the vulnerability discovery rate by months or even years. The company pointed to reports published by partners Booz Allen and Comcast about their experience.

Data retention, availability and application details

Data retention is mandatory for organizations enrolled in the program so that Anthropic can monitor for cyber abuse. Once Enterprise Frontier Safeguards, a solution described by Anthropic as combining the privacy of zero data retention with robust security measures, becomes available in fall 2026, eligible organizations will be able to store data in the cloud infrastructure they control. Until then, organizations with zero-retention access to Claude Fable 5.1 or Claude Mythos 5.1 can also use CVP with zero data retention.

CVP is available on the Claude platform, Google Cloud’s Vertex AI, and Microsoft Foundry. On Amazon Bedrock is only available to customers eligible for Enterprise Frontier Safeguards; the Help Center says that Amazon Bedrock does not yet support human review of automated security flags, which CVP requires by default, and that Anthropic is working to expand CVP to all customers on Bedrock. Third-party platforms such as coding tools only support Defense Access and Red Team Access; Specialized access is not available through these.

Organizations previously enrolled in Project Glasswing or CVP do not need to reapply; their existing access continues to function under the current terms and they will be transferred to the new relevant level for Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. Anthropic’s usage policy continues to apply in full, and the Help Center says the company may review, restrict, or withdraw a grant. Building a customer-facing product around these features is governed separately by Anthropic’s IT production policy, with a production application becoming available to CVP users.

Defense Access organizations have until December 15, 2026 to adopt phishing-resistant multi-factor authentication and stop using API keys; until then, multi-factor authentication of some kind is required, and API keys expire every seven days. Accessing Mythos on third-party cloud providers delays application approval by approximately five business days. Anthropic has scheduled a webinar scheduled for October 14, 2026 at 9:00 AM Pacific Time.

Post Comment