Anthropic announced an expanded Cyber Verification Program on 6 October 2026, combining its existing security access programmes into three tiers for qualifying professionals, Unite.AI reported. The arrangement gives applicants access to the same three Claude model families but varies the cyber requests that its safeguards will allow, according to the company.
Key points
- Defense Access, Red Team Access and Specialized Access have different verification requirements and cyber restrictions.
- Each tier includes Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, as well as future models.
- Anthropic says Project Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026.
- In Anthropic’s CyScenarioBench test, Red Team Access blocked none of the trials, and the model completed 34 of 50 tasks.
Anthropic puts three models behind tiered safeguards
All three tiers include Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, with future models also covered. The distinction is in what applicants are verified to do and which cyber safeguards apply to their requests. Anthropic says the arrangement ties greater access to verified identity and oversight, rather than making it available to every paying customer.
A blocking classifier works like a checkpoint for a request: it can stop a cyber task before a capable model carries it out. Giving a verified group fewer blocks changes what it can ask the model to attempt, even when another tier has access to the same model. Anthropic says its generally available models retain conservative cyber safeguards, while remaining usable for work including reviewing code, patching known issues and finding vulnerabilities in owned source code.
Checking owned software for security flaws could involve finding a vulnerability and validating it with fewer blocked requests, provided the work qualified for the relevant access tier. Testing a system beyond an organisation’s authorisation would remain outside the permitted work described for Red Team Access.
Defense Access covers work such as incident response, malware analysis and vulnerability validation. Security teams, operators of critical infrastructure, open-source maintainers and researchers with a record of reporting vulnerabilities can apply. Individuals can apply for this tier if they are on a paid plan, while the other two tiers are limited to organisations.
Red Team Access extends permission to authorised penetration testing. It retains real-time blocks on activities that could cause physical harm or widespread disruption, including ransomware deployment and tests of high-risk safety systems. Specialized Access has the fewest cyber blocks and is reserved for a small set of organisations authorised to test safety-critical systems, including power grids, flight operating systems and interbank transfer infrastructure. Anthropic reviews applicants for that tier with the US government, Reuters reported.
Project Glasswing enters the new programme
The new structure brings together Project Glasswing, which gave organisations securing critical software access to Claude Mythos, and the original Cyber Verification Program, which offered vetted security teams reduced safeguards on Claude Opus and Sonnet. Anthropic had operated the two programmes for six months. Existing Glasswing members move into Specialized Access without seeking reapproval for current models.
Anthropic says Glasswing partners identified at least 129,000 verified software vulnerabilities between April and July 2026, more than 33,000 of them rated critical or high severity, StreetInsider reported. The company says its own scans of open-source software found an additional 5,500 verified vulnerabilities between April and October 2026. Anthropic described the partner figures as a likely undercount because they came from a survey of a limited number of partners.
Those figures concern vulnerabilities the company says were found and verified, rather than repairs made to the affected software. The distinction matters to organisations using the programme for defensive work: finding a flaw and deciding how to address it are separate parts of securing a system.
Claude Opus 5.5 faces CyScenarioBench
Anthropic tested the tier-specific safeguards on Claude Opus 5.5 using CyScenarioBench, an evaluation of planning and carrying out multi-stage cyber operations. The test covered five attempts at each of 10 challenges. Without programme access, the safeguards blocked every task at its first prompt. Under Defense Access, a block occurred at some point in 46 of 50 trials.
Under Red Team Access, none of the trials was blocked and Claude completed 34 of 50 tasks. The 34-of-50 result was close to the 67.6% baseline success rate without safeguards. A block records an interruption by a safeguard, whereas completion records success at the challenge; the two measurements answer different questions about what happened in the test.
Enrolled organisations must retain data for misuse monitoring. Anthropic says access is available through the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. Amazon Bedrock access is available to customers eligible for Enterprise Frontier Safeguards.