Key Points
- Anthropic is expanding its Cyber Verification Program into three access tiers with fewer blocking classifiers.
- The tiers merge Project Glasswing and the earlier program, covering Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1.
- Vetted teams gain offensive-capable tooling that Anthropic says it otherwise blocks for ordinary users.
The latest:
Qualifying security professionals can now apply for advanced cyber capabilities and reduced blocking classifiers under an expanded Cyber Verification Program, Anthropic said on October 6, 2026. The company structured access into three tiers — Defense, Red Team and Specialized — each including its most capable models. Anthropic framed cybersecurity as inherently dual use, saying the capabilities that let defenders fix a vulnerability can also help an attacker exploit it.
Details:
- The three tiers: According to Anthropic, Defense Access covers security operations center and incident response work, reverse-engineering malware, and analyzing and validating vulnerabilities. Red Team Access adds authorized penetration testing and red-teaming. Specialized Access carries the fewest cyber blocks and is reserved for a limited set of verified organizations.
- Critical infrastructure: Specialized Access is restricted to organizations authorized to test safety systems that could affect people’s lives, Anthropic said, naming flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networks. Those applications are reviewed in depth in collaboration with the US government.
- The models: Each tier includes Anthropic’s most capable models — Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 — the company said. The program merges two separate efforts run over the past six months, Project Glasswing and the original Cyber Verification Program, into one expanded offering.
- The benchmark: Anthropic said it tested Claude Opus 5.5 on CyScenarioBench, an evaluation measuring whether models can plan and execute multi-stage cyber operations under realistic constraints. Without program access, every task was blocked on the first prompt, according to the company.
- The numbers: In the Defense Access tier, 46 of 50 trials were blocked at some point, Anthropic reported. In Red Team Access, no blocks occurred at all and Claude Opus 5.5 completed 34 of 50 tasks — the clearest published measure of how far the tiers diverge.
- Vulnerability findings: Partners working through Project Glasswing uncovered at least 129,000 verified software vulnerabilities between April and July 2026, Anthropic said, with more than 33,000 rated critical- or high-severity. The company’s own open-source scanning found an additional 5,500 verified vulnerabilities between April and October 2026.
- Where it runs: The program is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry, according to Anthropic. Access through Amazon Bedrock is limited to customers eligible for Enterprise Frontier Safeguards. The company did not publish approval timelines or the number of organizations admitted to any tier.
- Outside coverage: Reuters reported the announcement under the headline “Anthropic opens its most powerful AI models to more security teams,” framing the change as a widening of access to the company’s frontier systems rather than a narrow adjustment to an existing program.
Background:
Anthropic ran trusted-access cyber work through two separate channels for six months: Project Glasswing and the Cyber Verification Program. The expansion consolidates both into one tiered structure, replacing parallel approval paths with a single application scaled to the applicant’s stated work.
Between the lines:
The benchmark figures Anthropic published set the terms of the trade-off it is making. A system that blocks every task on the first prompt by default completes 34 of 50 once a user clears Red Team vetting — meaning the safeguard separating defensive research from offensive capability is now the verification process itself, not the model. That shifts the burden onto who Anthropic admits, which is why Specialized Access, covering power grids and interbank infrastructure, is tied to US government review.
What’s next
Watch whether Anthropic publishes how many organizations are approved per tier, whether any Specialized Access grants are disclosed, and whether vulnerability counts from the merged program follow the same cadence as the April–October 2026 figures.