The AI company said its expanded Cyber Verification Program, announced on October 6, combines its previous verification scheme with Project Glasswing, a controlled-access initiative created for organisations protecting critical software. The new structure divides access into Defense, Red Team and Specialized tiers, with verification and security requirements increasing as potentially sensitive capabilities are unlocked.
All three tiers provide access to Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, as well as future models covered by the programme. Anthropic said its generally available models retain conservative cybersecurity safeguards because capabilities useful for identifying and fixing vulnerabilities can also be used to exploit them.
Defense Access is intended for work including security operations, incident response, malware reverse engineering and vulnerability analysis and validation. Eligible applicants can include corporate, university, nonprofit and government security teams, critical-infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a record of responsibly reporting vulnerabilities.
Red Team Access permits those defensive activities while adding authorised penetration testing and adversarial security assessments. It is available only to organisations, including internal red teams, government teams and penetration-testing firms. Anthropic said testing must be limited to systems the organisation is authorised to assess.
Some protections remain even at that level. The company said real-time controls can still block actions capable of causing physical harm or mass disruption, including ransomware deployment, damage to physical systems and penetration testing of high-risk safety systems.
Specialized Access carries the fewest cybersecurity blocks and is restricted to a smaller group of verified organisations authorised to assess systems where failure could endanger people or disrupt markets. Anthropic cited flight operating systems, electricity grids, telecommunications networks, interbank transfer infrastructure and government administrative networks as examples.
Applicants for Specialized Access undergo an in-depth review conducted by Anthropic in collaboration with the US government. Existing Project Glasswing participants will move to the specialised tier without requiring reapproval for models they already use.
Anthropic said internal testing showed a sharp difference between the restrictions applied across tiers. On CyScenarioBench, an evaluation of multi-stage cyber operations, all 50 trials using Claude Opus 5.5 without CVP access were blocked at the first prompt. Under Defense Access, safeguards blocked 46 of 50 trials at some point.
With Red Team Access, none of the 50 trials was blocked and Opus 5.5 successfully completed 34. Anthropic said that was effectively equivalent to the model’s 67.6 per cent success rate when safeguards were removed, a configuration representative of Specialized Access. The figures are Anthropic’s own evaluation results rather than an independent assessment.
The expansion follows six months of controlled cybersecurity use through the earlier CVP and Project Glasswing. Anthropic said Glasswing partners identified at least 129,000 verified software vulnerabilities between April and July, while its own open-source scanning found another 5,500 between April and October. More than 33,000 of the verified flaws have been rated critical or high severity.
The company cautioned that those totals are incomplete because partner data came from only a subset of participating organisations and approaches to triage differed. It said fewer than half of partners disclosed numbers of patched vulnerabilities, often because remediation was still under way.
The redesigned programme also imposes monitoring and incident-response obligations. Participating customers must designate a security contact, use personal accounts for approved users and report suspected breaches or misuse involving programme access. Anthropic’s published requirements specify reporting within 72 hours for suspected breaches or misuse and within 24 hours for a security incident.
Data retention is generally required so Anthropic can monitor misuse. The company said eligible organisations will later be able to keep data in cloud infrastructure they control through Enterprise Frontier Safeguards, while maintaining additional protections under the revised rules.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.