Anthropic has launched an expanded version of its Cyber Verification Program (CVP), a framework designed to grant qualifying security professionals access to advanced cyber capabilities and reduced blocking classifiers in its Super Intelligence (SI) models. The update integrates the company’s previous Project Glasswing initiative into a unified three-tier system, aiming to balance the dual-use nature of SI tools in cybersecurity.
What Happened
The revised CVP consists of three access tiers: Defense Access, Red Team Access, and Specialized Access. Each tier provides security teams with varying levels of access to Anthropic’s most capable SI models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. The program is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. For customers eligible for Enterprise Frontier Safeguards (EFS), access is also available via Amazon Bedrock.
Defense Access is tailored for defensive tasks such as security operations, incident response, and malware reverse-engineering. Anthropic expects many organizations, including those in critical infrastructure and open-source maintenance, to qualify for this tier, with applications reviewed within a few days. Red Team Access adds authorized penetration testing and red-teaming capabilities. This tier is restricted to organizations—individual researchers are not eligible—and includes real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware. Applications for this tier take a few weeks to review. Specialized Access offers the fewest cyber blocks and is reserved for a limited set of verified organizations testing safety-critical systems, such as power grids and interbank transfer infrastructure. Current Project Glasswing members will transition to this tier without needing reapproval for current models.
To ensure security, data retention is required for all enrolled organizations to monitor for cyber misuse. Anthropic reports that once EFS becomes available later this fall, eligible organizations will be able to store data in cloud infrastructure they control. Until then, organizations with zero data retention agreements for Claude Fable 5.1 or Claude Mythos 5.1 can maintain that status within the CVP.
Why It Matters
Cybersecurity is inherently dual-use: the same SI capabilities that allow defenders to identify vulnerabilities can enable malicious actors to exploit them. Anthropic notes that its generally available models have conservative cyber safeguards that block most cyber work to limit harmful activities. However, defenders require access to powerful SI tools to secure systems effectively. By expanding the CVP, Anthropic aims to provide more security organizations with the necessary capabilities while maintaining safeguards against misuse.
The company reports that through Project Glasswing, partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic’s own open-source scanning efforts identified an additional 5,500 verified vulnerabilities between April and October 2026. Of these, more than 33,000 were rated as critical- or high-severity. Anthropic states this is likely an undercount, estimating the true impact could be at least five times higher due to partial data from partner reports.
To test the efficacy of the new tiers, Anthropic ran Claude Opus 5.5 through CyScenarioBench, an evaluation measuring the ability to plan and execute multi-stage cyber operations. The company reports that without CVP access, every task was blocked on the first prompt. In the Defense Access tier, 46 of 50 trials were blocked at some point. In the Red Team Access tier, no blocks occurred, and the model completed 34 of 50 tasks, matching the 67.6% success rate achieved when no safeguards were applied.
The Bottom Line
Anthropic’s expanded Cyber Verification Program represents a significant step in balancing the accessibility of advanced SI models for security professionals with the need for robust safety controls. By integrating Project Glasswing and offering tiered access, the company aims to extend the defensive advantages of its SI tools to a broader range of organizations, from individual researchers to entities managing critical infrastructure.