Cybersecurity & Protection

Anthropic Merges Its Cyber Programs and Introduces Three Access Tiers for Claude

Oct 7, 2026 3 min read
All articles

Anthropic is expanding its Cyber Verification Program (CVP). Depending on their access tier, security researchers and organizations will be able to use Claude capabilities that are more tightly restricted in the generally available models.

Until now there were two separate programs. Through Project Glasswing, selected organizations got access to Claude Mythos, a limited model variant with extended cyber capabilities. Through the CVP, verified security teams could use Claude Opus and Sonnet with less restrictive cyber filters, but there was only a single access tier. Now Anthropic is merging both approaches into an expanded CVP and splitting access into three tiers. All three cover Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1, with more models to follow. Existing Glasswing participants move to the highest tier.

Anthropic is responding to the dual-use problem of cyber AI: the same capabilities that find and fix vulnerabilities can also be abused for attacks. So the company is tying access more closely to verification and to the scope of the cyber work.

The three tiers at a glance

The lowest tier, "Defense Access," targets defensive work such as incident response, malware analysis, reverse engineering, or analyzing and validating vulnerabilities. Besides organizations, individual security researchers can apply here as well, provided they have a track record of reporting vulnerabilities.

The middle tier, "Red Team Access," additionally allows authorized penetration testing and red teaming and is open to organizations only. The highest tier, "Specialized Access," is meant for especially sensitive testing, for example on power grids, flight operations systems, telecom networks, or interbank transfer infrastructure. Anthropic says it vets applicants for this tier together with the US government. The higher the tier, the riskier the permitted tasks and the stricter the entry requirements.

Anthropic shows how differently the cyber filters intervene using Claude Opus 5.5 on CyScenarioBench, a benchmark for multi-stage offensive cyber operations. Without the CVP, all 50 attempts were blocked at the very first prompt. With Defense Access, the filter stepped in on 46 of 50 runs, and with Red Team Access none of the 50 attempts were blocked. Anthropic's usage policies still apply in full: even at Red Team Access, real-time filters are supposed to block things like ransomware and actions with potential physical harm.

Project Glasswing: more than 130,000 verified vulnerabilities

Alongside the reshuffle, Anthropic shares new results from Project Glasswing. Partners found at least 129,000 verified software vulnerabilities between April and July, and another 5,500 came from Anthropic's own scans of open-source software between April and October. More than 33,000 of them are rated critical or high. The partner figures rely on incomplete data from 33 partner reports, so Anthropic treats the results as a lower bound.