Anthropic has expanded its Cyber Verification Program (CVP), giving vetted cybersecurity organizations controlled access to some of its most capable AI models with fewer cyber restrictions. The company says the goal is to give defenders enough capability to find and fix serious vulnerabilities without making the same unrestricted capabilities broadly available to malicious actors.
What Anthropic Changed
The updated CVP combines Anthropic's previous Cyber Verification Program with Project Glasswing, an initiative focused on securing critical software. The new system has three access levels: Defense Access, Red Team Access and Specialized Access.
Qualifying organizations can receive access to models including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, along with future models covered by the program.
Three Levels of AI Cyber Access
Defense Access
This tier is aimed at defensive security operations. Anthropic lists incident response, malware reverse engineering, vulnerability analysis and validation among the intended uses.
Red Team Access
This level is designed for authorized penetration testing and red-team work. It provides fewer cyber blocks than the defensive tier, but applicants must still pass Anthropic's verification requirements.
Specialized Access
This is the most restricted and powerful tier. Anthropic says it is reserved for verified organizations testing systems where failures could affect people's lives or major infrastructure, including power grids, flight systems, telecom networks, interbank infrastructure and government administrative networks.
Why Anthropic Is Reducing Some Safeguards
Cybersecurity is a difficult AI safety problem because the same capability can help defenders discover a vulnerability and help attackers exploit it. Anthropic says its general-purpose models keep conservative cyber safeguards that block many high-risk activities.
Security professionals, however, can run into the same safeguards while legitimately investigating an attack or testing software they are authorized to assess. CVP is Anthropic's attempt to separate those use cases through identity verification, organizational controls and different levels of access.
Anthropic Says AI Found 129,000 Vulnerabilities
Anthropic says organizations participating in Project Glasswing identified at least 129,000 verified software vulnerabilities between April and July 2026. Its own open-source scanning work identified another 5,500 verified vulnerabilities between April and October.
More than 33,000 of the vulnerabilities identified through the reported program data have so far been classified as critical or high severity.
Anthropic cautions that these figures are not a complete measurement of the global vulnerability landscape. The company says the data came from only a subset of partners and expects the true impact to be substantially larger.
A Test of How Much the Guardrails Matter
Anthropic also published results from CyScenarioBench, an evaluation involving realistic multi-stage cyber operations. In the company's tests, all attempts were blocked under the normal model configuration. The Defense tier blocked 46 of 50 trials at some point, while the Red Team tier produced no blocks and completed 34 of 50 tasks.
These results are Anthropic's own evaluation and should not be treated as an independent benchmark. They do, however, show the trade-off the company is trying to manage: stronger restrictions reduce dangerous capability, while authorized security teams may need those capabilities to perform legitimate testing.
The Safety Problem Gets Harder
Giving powerful models fewer restrictions creates an obvious risk. An account belonging to a legitimate security organization could potentially be compromised, misused or intentionally abused.
Anthropic says it will verify applicants and require security controls. The company also requires data retention for organizations enrolled in the program so that cyber misuse can be monitored, while additional privacy options are planned through its Enterprise Frontier Safeguards system.
Why This Matters for AI Security
This program represents a broader shift in how AI companies are approaching cyber defense. Instead of trying to make one universal model policy work for every user, Anthropic is experimenting with permissioned AI capability: ordinary users receive stronger safeguards while verified defenders can receive additional access.
If the approach works, similar tiered systems could become common for other high-risk AI capabilities where legitimate experts need access that ordinary users should not automatically receive.
Abhijeet Take
This is one of the more important AI-security experiments happening quietly right now.
The uncomfortable truth is that the best AI for finding vulnerabilities may also be extremely useful for exploiting them. Simply making a model less capable is not a perfect answer, because defenders lose the same advantage.
Anthropic's answer is basically: verify the person, verify the organization, then unlock more capability based on the job. I think that direction makes more sense than pretending a single safety filter can perfectly distinguish good and bad cyber activity.
But the real test will be accountability. If these models are given more freedom, the industry needs strong logging, access controls and clear consequences for misuse. Otherwise, reducing the guardrails could simply move the risk from public models into trusted accounts.
FAQ
What is Anthropic's Cyber Verification Program?
It is a controlled-access program that gives verified cybersecurity organizations additional access to advanced Claude models for defensive and authorized security work.
Who can apply?
Anthropic says the program is aimed at qualifying organizations and security teams. Eligibility and verification requirements depend on the access tier.
What is Specialized Access?
It is the most restricted tier and is intended for organizations testing safety-critical systems such as power grids, flight systems and financial infrastructure.
Does this mean Claude has no safety restrictions?
No. Access is tiered and controlled. The program specifically changes cyber safeguards for verified users based on their authorized work.
Sources
Anthropic — “Expanding the Cyber Verification Program,” October 6, 2026.
Reuters — “Anthropic opens its most powerful AI models to more security teams,” October 6, 2026.
