Anthropic has expanded its Cyber Verification Program (CVP), offering three access tiers for vetted security teams to use its advanced Claude models with reduced cyber safeguards. The program is designed to support defensive work, red teaming, and testing of high-risk systems.
TL;DR
- Anthropic expands CVP to include three access tiers for security teams.
- The program offers reduced cyber safeguards on Claude models for defensive and offensive security work.
- Anthropic aims to provide advanced tools for cyber defenders while maintaining strict authorization and monitoring.
What happened
Anthropic has expanded its Cyber Verification Program to include three access tiers: Defense Access, Red Team Access, and Specialized Access. These tiers cater to different types of cybersecurity work, from defensive security to testing high-risk systems. The expanded program combines two previous initiatives: Project Glasswing and the earlier CVP.
Vetted security organizations can now access Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, as well as future models, with varying levels of cyber restrictions. The company tested the different access levels using CyScenarioBench, an evaluation designed to measure AI models' ability to plan and execute multistage cyber operations.
Anthropic reported that under the Defense Access tier, 46 of 50 trials were blocked, while four succeeded. Under Red Team Access, none of the 50 trials were blocked, and Claude completed 34, equivalent to a 67.6% success rate when no safeguards were applied. The Specialized Access tier has the fewest cyber restrictions and is reserved for a limited set of verified organizations authorized to test critical systems.
Why it matters
This expansion provides cybersecurity teams with more advanced tools to secure their systems and test high-risk environments. It underscores the importance of authorization and scope in AI-driven security testing, as noted by IDC's Sakshi Grover and Deepika Giri.
The tiered approach allows for more granular control over AI capabilities, ensuring that access is continuously reviewed and monitored. Enterprises should implement additional controls outside the AI model when agents receive reduced safeguards or privileged access.
For developers and startups, this highlights the growing need for robust cybersecurity measures and the potential of AI in enhancing security capabilities. Investors should note the strategic importance of AI in cybersecurity and the competitive landscape in this sector.
Key facts
- Anthropic's Cyber Verification Program now offers three access tiers: Defense Access, Red Team Access, and Specialized Access.
- The program provides access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, as well as future models, with varying levels of cyber restrictions.
- Anthropic tested the access levels using CyScenarioBench, with 46 of 50 trials blocked under Defense Access and 34 completed under Red Team Access.
- Project Glasswing partners identified 129,000 verified software vulnerabilities between April and July 2026, with another 5,500 identified by Anthropic's open-source scanning efforts.
- More than 33,000 of the identified vulnerabilities have been rated critical or high severity, with the true impact likely being at least five times higher.
- Organizations enrolled in CVP will be subject to data retention for monitoring cyber misuse, with a forthcoming Enterprise Frontier Safeguards service offering zero-data-retention capabilities.
Context
Anthropic's expansion of its Cyber Verification Program reflects the growing importance of AI in cybersecurity. As cyber threats become more sophisticated, the need for advanced tools and capabilities to defend against these threats is paramount.
The tiered approach to access ensures that AI capabilities are used responsibly and within authorized scopes, addressing concerns about the potential misuse of AI in cyber operations. This aligns with broader industry efforts to balance the benefits of AI with the need for security and accountability.
For the AI industry, this development underscores the strategic importance of cybersecurity and the role of AI in enhancing security measures. It also highlights the competitive landscape in AI-driven cybersecurity solutions and the need for continuous innovation and adaptation.
