Anthropic has expanded its Cyber Verification Program, creating three access tiers for security professionals who need advanced cyber capabilities that may be restricted in generally available Claude models. The program combines Anthropic's previous Cyber Verification Program with Project Glasswing, an initiative that gave selected organizations access to more capable cyber tooling for defensive work.

All three tiers include access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models, but the verification requirements and safeguards differ by use case. Anthropic says the Defense tier is intended for work such as incident response and malware analysis. The Red Team tier extends access for authorized penetration testing and red-team work by organizations. The most restricted Specialized tier is aimed at vetted organizations working on safety-critical systems such as power grids, aviation systems and interbank transfer infrastructure.

The policy change addresses a central tension in AI cybersecurity. Strong safeguards can reduce malicious use, but they can also block legitimate defenders from validating exploits, analyzing malware or reproducing vulnerabilities. Anthropic is attempting to separate those cases through identity and organization verification, differentiated controls and tier-specific access rather than applying one refusal policy to every user.

Anthropic also published large vulnerability figures from Project Glasswing. It says partners identified at least 129,000 verified software vulnerabilities between April and July 2026, while Anthropic's own open-source scanning found another 5,500 through October. More than 33,000 were rated critical or high severity. Reuters independently reported the program expansion and those figures, while noting that Anthropic considers the totals an undercount because the partner data came from only a subset of participants.

The development is significant because it treats model safeguards as an access-control and governance problem, not only a model-behavior problem. More capable cyber models can be useful to defenders and dangerous to attackers, so the effectiveness of the approach will depend on vetting, monitoring and whether reduced restrictions remain confined to legitimate work. The core program expansion is independently confirmed, but the vulnerability totals and effectiveness claims originate from Anthropic and its participating partners rather than an independent audit.

References