Anthropic is expanding access to its most capable cybersecurity-focused AI systems through a redesigned Cyber Verification Program (CVP), announced on October 6, 2026. The updated program introduces three access tiers for verified security professionals, with different levels of capability, eligibility checks, and safeguards. It also brings together work previously conducted through the Cyber Verification Program and Project Glasswing, aiming to give more defenders access to advanced models without making the least-restricted capabilities generally available.

The change matters because frontier AI models can help security teams discover software vulnerabilities, investigate suspicious activity, and test defenses—but the same capabilities can also assist people attempting to exploit systems. Anthropic’s approach is to vary access according to the applicant’s role and the risk of the work, rather than treat every cybersecurity task as either automatically safe or automatically prohibited.

The announcement does not mean that all Claude users now receive unrestricted cybersecurity assistance. Access is conditional, some tiers are limited to organizations, and the most permissive tier is reserved for a small group of verified entities. Anthropic also says monitoring and data-retention requirements apply to participating organizations, subject to specific exceptions and its planned Enterprise Frontier Safeguards offering.

This guide explains what changed, how the three tiers differ, which models are included, what Anthropic’s published testing says about the safeguards, and what security teams should consider before applying.

What Anthropic Announced

In its official announcement, “Expanding the Cyber Verification Program,” published October 6, 2026, Anthropic introduced an expanded version of CVP that makes advanced cyber capabilities and reduced-blocking classifiers available to qualifying security professionals.

The program now has three tiers: Defense Access, Red Team Access, and Specialized Access. Each tier is designed for a different scope of work, and each has its own verification requirements and security controls. Anthropic says all three tiers include access to its most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models as they become available through the program.

The revised CVP integrates the earlier CVP offering with Project Glasswing, which provided a selected group of organizations working to secure critical software with access to Claude Mythos. Under the new arrangement, existing Project Glasswing members transition to Specialized Access and do not need to reapply for access to current models, according to Anthropic.

The practical change is a more structured route for organizations and qualified individuals to request capabilities that may be restricted in generally available Claude experiences. Instead of a single trusted-access path, applicants can seek access appropriate to their work, with greater scrutiny as the potential impact of the work increases.

Why Cybersecurity Requires a Different Access Model

Cybersecurity is a dual-use field. The same technical knowledge can help a defender identify a vulnerable service, understand malicious code, or verify a patch—and help an attacker find a way into a system. AI models can lower the time and expertise needed to perform some of these tasks, making both the benefits and risks more consequential.

For defenders, advanced models can assist with code review, vulnerability discovery, reverse engineering, security-alert triage, and incident response. These tasks can be difficult to scale because organizations often have large codebases, limited security staff, and software dependencies that are poorly documented or rarely maintained. An AI assistant that helps prioritize findings or explain a flaw may make it easier for a team to investigate and remediate problems.

The risk is that similar capabilities can be redirected toward unauthorized intrusion, exploitation, or disruption. Anthropic says its generally available models retain conservative cyber safeguards intended to block most cyber work that could be misused, while the company continues to reduce false positives for legitimate secure coding. Verified access is meant to give qualified defenders more room to work while preserving restrictions against particularly dangerous activity.

This is not simply a matter of trusting an applicant’s stated intentions. The tier system ties access to the kind of work an organization is authorized to conduct, and Anthropic says it verifies applicants and requests evidence of the required security controls. The approach attempts to combine identity and organizational checks with model-level safeguards and monitoring.

The Three CVP Access Tiers

1. Defense Access: Security operations and vulnerability remediation

Defense Access is intended for defensive work. Anthropic lists activities such as security operations center tasks, incident response, malware reverse engineering, and analyzing or validating vulnerabilities.

Potentially eligible applicants include security teams at companies, nonprofits, universities, and government organizations that defend systems they own or maintain. Anthropic also names critical-infrastructure operators—including regional hospitals and municipal utilities—smaller security firms, open-source maintainers, and individual researchers with a record of reporting vulnerabilities.

The company expects many organizations conducting defensive cybersecurity work to qualify and says it aims to respond to applications within a few days. That is an expected response time, not a guarantee that every application will be approved within that period.

For teams that spend much of their time triaging alerts, reviewing suspicious code, or validating fixes, this tier is the most directly relevant starting point. It is intended to make useful defensive work possible without opening the door to every high-risk capability.

2. Red Team Access: Authorized penetration testing

Red Team Access adds authorized penetration testing and red-teaming to the defensive activities allowed under Defense Access. It is aimed at organizations whose work requires controlled adversarial testing, such as in-house red teams, government red teams, and security or penetration-testing firms.

This tier is for organizations, not individual researchers. Applicants must satisfy the program’s increased eligibility requirements and security controls. Anthropic expects reviews to take a few weeks; while applications are under review, qualifying organizations are expected to be enrolled in Defense Access.

Authorization remains central. Red-team access is intended for testing systems that the organization has permission to assess, including IT systems in critical industries. It is not blanket permission to test arbitrary public targets or to carry out destructive activity.

Anthropic says real-time blocks will remain in place for actions that could cause physical harm or mass disruption. Examples include deploying ransomware, damaging physical systems, or penetration-testing high-risk safety systems. In other words, Red Team Access expands the scope of permitted security testing but does not remove every safeguard.

Organizations considering this tier should be prepared to demonstrate the legitimacy and scope of their testing, maintain appropriate access controls, and ensure that staff use the models only within authorized engagements.

3. Specialized Access: Highly sensitive and safety-critical testing

Specialized Access is the most restricted tier and has the fewest cyber blocks. It is reserved for a limited set of verified organizations authorized to test safety systems whose failure could affect human lives or disrupt markets.

Anthropic’s examples include flight operating systems, power grids, telecommunications networks, interbank transfer infrastructure, and government administrative networks. Because these environments can have consequences beyond a single company or application, the program applies deeper review.

Anthropic says it currently reviews each organization in depth in collaboration with the US government. Existing Project Glasswing members transition to this tier without needing reapproval for current models.

Specialized Access should not be interpreted as general availability for critical-infrastructure operators. It is a narrowly controlled route for organizations whose authorization, mission, and security controls meet the program’s requirements.

Which Claude Models Are Included?

Anthropic says the updated program includes its most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward. Exact access still depends on the tier, model availability, and the organization’s approved setup.

The distinction between a model and its access configuration is important. A model name alone does not tell users which safeguards are active or which tasks are permitted. The CVP changes the access and safeguards available to approved participants; it does not imply that every model is unrestricted for every user.

Anthropic also says the program is available through the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. Availability on Amazon Bedrock is limited to customers eligible for Enterprise Frontier Safeguards. Teams should check the latest program documentation and their own platform’s availability before planning a deployment.

For teams already using Claude for software development, the normal generally available experience remains distinct from CVP access. Anthropic says general-purpose models can still be used for tasks such as code review, patching known issues, finding vulnerabilities in source code the user owns, and triaging security alerts. Organizations should not assume they need CVP for every routine secure-coding workflow.

What Anthropic’s Safeguard Evaluation Shows

Anthropic included results from CyScenarioBench, its evaluation of cyber-related tasks, to illustrate how access tiers can change model behavior. The company reports that safeguards blocked 46 of 50 tasks when Claude Opus 5.5 was used under Defense Access. Under Red Team Access, Claude Opus 5.5 did not block any of those tasks and completed 34 of 50—the same completion rate reported when no safeguards were applied.

These results demonstrate the intended distinction between the tiers: a stricter configuration blocks more tasks, while a more permissive configuration can complete more of the evaluated work. They do not establish that every blocked task was malicious, that every completed task was safe, or that the same rates will hold for all real-world activity.

The figures are also Anthropic’s own reported evaluation results. A benchmark offers useful evidence about behavior under defined conditions, but it cannot capture every network, organization, attacker, or defensive engagement. Independent testing and operational experience will be important for judging how well the controls work beyond the benchmark.

Anthropic says it will continue refining its tier-based classifiers. This is a meaningful caveat: the program is not presented as a finished system whose safeguards will never need adjustment. Its effectiveness depends on the quality of verification, the boundaries of approved work, monitoring, and continued evaluation as model capabilities change.

Project Glasswing and the Scale of Vulnerability Discovery

The expanded CVP builds on Project Glasswing, Anthropic’s effort to use advanced AI to help secure critical software. In the October 6 announcement, Anthropic reported that its Glasswing partners had identified at least 129,000 verified software vulnerabilities between April and July 2026. The company’s own open-source scanning efforts found another 5,500 verified vulnerabilities between April and October 2026.

Anthropic said more than 33,000 of those verified vulnerabilities had so far been rated critical or high severity. It also cautioned that the figures are likely an undercount: they rely on survey data from only a subset of Glasswing partners, and the company expects the true impact to be at least five times higher.

Those numbers are substantial, but their scope needs to be understood carefully. They are figures reported by Anthropic, not a complete independent census of all vulnerabilities discovered across the software industry. The company also notes that partner approaches to triage differed and that fewer than half of partners disclosed how many vulnerabilities had been patched, often because remediation was still in progress. As a result, the reported patch rate is significantly undercounted.

Finding a vulnerability is only one stage of improving security. A finding must be validated, prioritized, disclosed responsibly when appropriate, and fixed without breaking the system. In critical infrastructure, installing a patch can require careful testing or a maintenance window because the equipment may need to remain operational. A large volume of discoveries is valuable only if organizations can turn those findings into safer software and systems.

Anthropic’s rationale for broadening CVP is that the benefits of advanced cyber models should reach more of the people responsible for defense, not only the initial group of Glasswing partners. The tiered program is its proposed way to extend access while maintaining controls appropriate to the risk.

Data Retention, Monitoring, and Privacy

Participation in CVP comes with a monitoring trade-off. Anthropic says organizations enrolled in the program are required to retain data so it can monitor for cyber misuse. This is part of the program’s accountability model, but it is also a consideration for security teams handling confidential code, incident records, or sensitive infrastructure details.

Anthropic says it is developing Enterprise Frontier Safeguards (EFS), a solution intended to combine zero data retention with robust safeguards. It expects eligible organizations to be able to store data in cloud infrastructure they control once EFS becomes available later in fall 2026. The announcement also notes that some organizations with zero-data-retention access to Claude Fable 5.1 or Claude Mythos 5.1 can use CVP with zero data retention.

These exceptions are conditional and should not be assumed to apply to every applicant or platform. Before enrolling, an organization should review the current program terms, data-handling requirements, available retention options, and any internal obligations governing customer information or regulated data.

The important distinction is that access to a more permissive model is not merely a model-selection setting. It comes with eligibility and operational requirements that organizations need to understand and meet.

How Security Teams Should Decide Whether to Apply

The right tier depends on the work the team actually performs and the authority it has to perform that work.

  • Start with Defense Access if the main work involves incident response, alert triage, malware analysis, secure coding, or investigating vulnerabilities in systems the organization owns or maintains.
  • Consider Red Team Access if the organization conducts formal penetration tests or red-team engagements and can document authorization, scope, and the controls used to keep testing within those boundaries.
  • Treat Specialized Access as exceptional if the work involves safety-critical systems such as power, transport, telecommunications, or financial infrastructure. The program’s deeper review reflects the potential consequences of mistakes or misuse.

Applicants should also consider whether their cloud platform supports the program, whether their data-retention obligations are compatible with their policies, and how model outputs will be reviewed before being acted upon. AI-generated vulnerability reports can be incomplete or incorrect, and automated recommendations should not be deployed to production systems without appropriate validation.

For any tier, access controls should be applied at the workspace or organizational level, with permissions limited to the people who need them. Teams should document authorized targets, keep testing environments isolated where appropriate, and use human review for decisions that could disrupt systems or expose sensitive data. These are sound operational practices regardless of which model or access program is used.

What the Announcement Does—and Does Not—Mean

The expanded CVP creates a more explicit path for vetted defenders to request stronger cybersecurity capabilities. It does not make the most permissive Claude configurations generally available, eliminate real-time blocks on high-risk actions, or replace authorization for penetration testing.

Nor do the reported vulnerability counts prove that AI alone secured those systems. The results reflect a program involving models, security professionals, partner organizations, triage processes, and remediation work. The most meaningful outcome is not simply how many issues an AI system can identify, but whether organizations can verify and fix them responsibly.

Finally, the benchmark results should not be read as a guarantee that the tier controls will block every harmful request or permit every legitimate one. Anthropic says it will continue refining the classifiers, and the real-world balance between useful security work and misuse prevention will remain an ongoing challenge.

The Bottom Line

Anthropic’s October 6, 2026 update expands the Cyber Verification Program into three tiers—Defense Access, Red Team Access, and Specialized Access—so verified security professionals can request capabilities matched to their work. The program includes access to advanced Claude models, preserves restrictions on particularly dangerous activity, and uses stronger verification for more sensitive testing.

The update also integrates Project Glasswing into the broader access model and extends Anthropic’s stated effort to help defenders identify and remediate vulnerabilities. Its reported findings suggest that advanced models can contribute to security work at scale, but discovery is not the same as remediation, and benchmark performance is not a guarantee of real-world safety.

For security teams, the practical next step is to match the tier to their authorized work, verify the current eligibility and data-handling requirements, and treat model output as evidence to investigate—not as an instruction to execute blindly. The program’s long-term value will depend on whether it expands defenders’ capabilities while maintaining controls that are effective, transparent, and appropriate to the systems at stake.

Official Sources

  1. Anthropic: Expanding the Cyber Verification Program — Published October 6, 2026. Primary source for access tiers, model availability, safeguards, and reported evaluation results.
  2. Anthropic: Project Glasswing — Background on the initiative to secure critical software and the transition to the expanded CVP.
  3. Anthropic: Introducing the Anthropic Cyber Mission — Published October 8, 2026. Context on Anthropic’s wider efforts around critical infrastructure defense and open-source security.