Expanding the Cyber Verification Program
Anthropic Anthropic
Anthropic expanded its Cyber Verification Program into three access tiers for security teams. It’s trying to give defenders stronger Claude access without opening the door to abuse.
Based on reporting by Anthropic, Anthropic — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Anthropic is folding its two cyber-access efforts into a single, expanded Cyber Verification Program. The pitch is simple enough: give trusted security professionals more capable Claude models, while keeping tighter controls on the public versions that would be too easy to abuse for harmful cyber work.
The new setup has three tiers. Defense Access is the broadest, covering incident response, reverse engineering malware, checking vulnerabilities, and other defensive work. Red Team Access adds authorized penetration testing, but only for organizations testing systems they’re allowed to touch. Specialized Access is the smallest pool, reserved for organizations testing systems where failures could affect people’s lives or disrupt markets, including flight systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks.
Anthropic says generally available models such as Claude Opus 5.5, Claude Fable 5.1, and Claude Sonnet 5.5 still have conservative cyber safeguards that block most cyber tasks. The company says the new program lets defenders reach models including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models, while keeping real-time blocks in place for actions that could cause physical harm or mass disruption, like ransomware or damaging physical systems.
The company also says it has spent the past six months running two separate programs, Project Glasswing and CVP, and is now combining them. Existing Project Glasswing members will move into the most restricted tier, and current CVP users will keep their settings for older models while being evaluated for access to the expanded program.
Anthropic is backing the change with internal testing. On its CyScenarioBench evaluation, Claude Opus 5.5 was blocked on the first prompt for every task without CVP access. In Defense Access, 46 of 50 trials were blocked at some point. In Red Team Access, there were no blocks, and the model completed 34 of 50 tasks, which Anthropic says matched its 67.6% success rate with no safeguards. The company says those results give it confidence to widen access.
It also points to early results from Project Glasswing. Between April and July 2026, partners found at least 129,000 verified software vulnerabilities, and Anthropic’s own open-source scanning added another 5,500 between April and October 2026. More than 33,000 of those were rated critical or high severity. Anthropic says that is likely an undercount, based on partial survey data, and that the true impact is probably at least five times higher.
My take — AI-written commentary, not fact-checked reporting
This is the right instinct: keep the public model locked down and hand sharper tools to people who can prove they’re defenders. The annoying part is how much modern AI safety still boils down to paperwork, trust, and who gets a badge that says “we’re the good guys.” That’s not elegant, but it’s better than pretending the same model should be equally friendly to a hospital SOC and a ransomware crew.
Read more about this at: Anthropic