Anthropic expands Claude cyber program with three tiers

Anthropic expands Claude cyber program with three tiers

Anthropic has widened its Cyber Verification Program (CVP), letting vetted security professionals use advanced Claude capabilities with fewer automated blocks on sensitive work like malware analysis and vulnerability testing.

As part of the expansion, the company has folded CVP and Project Glasswing into one program. Access is now split into three tiers, and the tier an applicant gets depends on the scope of their cybersecurity work. Each tier has its own verification requirements and security controls, matched to the tasks it allows.

Defense Access for everyday defenders

The entry tier, Defense Access, covers incident investigation, malware analysis, and vulnerability analysis and validation. It is aimed at security teams at businesses, nonprofits, universities and government bodies that protect systems they own or maintain.

Critical infrastructure operators, smaller security firms, open-source maintainers, and individual researchers with a track record of reporting vulnerabilities can also apply. Anthropic expects many companies doing defensive security work to qualify and says it aims to answer applications within a few days.

Red Team Access adds offensive testing

The second tier, Red Team Access, includes everything in Defense Access plus authorized penetration testing and simulated attacks. It is built for internal and government red teams and for security testing firms.

Participants may only test systems they are authorized to assess. Some actions stay blocked in real time, including deploying ransomware, testing high-risk safety systems, and anything else that could cause physical harm or widespread disruption.

Reviews for this tier may take a few weeks. Qualifying organizations get Defense Access while they wait. Individual researchers cannot currently apply for Red Team Access.

Specialized Access for high-risk systems

The top tier, Specialized Access, has the fewest cybersecurity blocks. It is limited to a small group of verified organizations authorized to test high-risk systems, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networks. In these environments, a disruption could affect people's lives or markets.

Anthropic reviews each applicant for this tier together with the US government. Current Project Glasswing members move into Specialized Access without reapproval for the models they already use.

Users outside the program are not left without options. "Our generally available models can continue to be used for tasks such as code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts," the company said.

Data retention and deployment

Joining the program means accepting data retention, so Anthropic can monitor for cybersecurity misuse. A feature called Enterprise Frontier Safeguards, expected later this fall, will let eligible companies keep data in cloud infrastructure they control while misuse safeguards remain in place.

Until then, organizations already approved to use Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP under zero data retention.

The program runs on the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry. On Amazon Bedrock, access is limited to customers eligible for Enterprise Frontier Safeguards.

Existing CVP members will be evaluated automatically for access to Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, and their settings for earlier models stay as they are. New applicants must pass verification and show proof of the security controls their tier requires.

How the tiers change what Claude will do

To show the effect of each tier, Anthropic ran Claude Opus 5.5 through CyScenarioBench, a benchmark that checks whether models can plan and carry out multistage cyber operations under realistic constraints. Safeguards were set up to match the CVP tiers, and the model got five attempts at each of the benchmark's 10 challenges.

Without CVP access, all 50 trials were blocked at the first prompt. With Defense Access, 46 trials hit a block at some point, and four succeeded. With Red Team Access, no trials were blocked, and the model completed 34 of 50.

Glasswing's vulnerability haul

Anthropic also shared numbers from Project Glasswing. Between April and July 2026, partners used Claude Mythos models to find at least 129,000 verified software vulnerabilities in their own systems. Anthropic found another 5,500 through open-source scanning between April and October.

More than 33,000 of these flaws were rated critical or high severity. The company said the real totals are probably higher, since the figures come from only a subset of Glasswing partners.

Our Take

The tiered model reflects a problem the industry has struggled with for a while: the same capability that helps a defender analyze malware can help an attacker build it. Rather than one set of guardrails for everyone, Anthropic is tying capability to identity and authorization. For security teams, this suggests that verification paperwork may become a normal part of getting full value from frontier AI tools.

The benchmark numbers make the trade-off clear. Defense Access still blocked almost every multistage operation, so teams that need offensive testing will likely have to go through the slower Red Team review. Individual researchers are shut out of that tier for now, which may frustrate independent pentesters.

The Glasswing figures also fit a wider pattern of AI speeding up vulnerability discovery, and of debate over whether attackers currently lead defenders in using these tools. Finding flaws at this scale only helps if they get fixed, and maintainers are already strained, as seen when Google paused an open-source bug bounty over AI-generated reports. It is worth watching how quickly Defense Access approvals actually arrive, how the US government's role in Specialized Access reviews plays out, and whether the data retention requirement puts off privacy-sensitive organizations before Enterprise Frontier Safeguards ships.