Skip to content
Anthropic expands cyber AI access program to more security firms

Anthropic expands cyber AI access program to more security firms

Qz • October 6, 2026

Anthropic expanded its Cyber Verification Program on Tuesday, restructuring it into three access tiers that allow a broader range of cybersecurity organizations to apply for reduced safeguards on its most capable AI models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1.

Before Tuesday's restructuring, Anthropic ran two distinct offerings: Project Glasswing, which extended Claude Mythos access to organizations focused on securing critical software, and the original Cyber Verification Program, which allowed vetted security teams to use Claude Opus and Claude Sonnet models with reduced safeguards. Anthropic said it has now integrated both into a single expanded program.

The three tiers vary in the scope of access and the verification required to qualify. Defense Access is the broadest tier, covering tasks such as reverse-engineering malware, incident response, and analyzing vulnerabilities. Qualifying organizations include security teams at companies, nonprofits, universities, and government bodies, as well as critical infrastructure operators, smaller security firms, and individual researchers with a track record of disclosed vulnerabilities. Anthropic said it aims to respond to applications within a few days.

Red Team Access extends permissions to cover authorized penetration testing of systems the applying organization has been cleared to engage. Qualifying organizations include in-house red teams, government red teams, and security and penetration testing firms. Anthropic said users in this tier will still face real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware. Applications are expected to take a few weeks to review, and individuals are not eligible for this tier.

Specialized Access, which imposes the fewest cyber restrictions, is open only to a narrow group of vetted organizations cleared to test safety-critical systems such as power grids, flight operating systems, telecom networks, and interbank transfer infrastructure. Anthropic said admission to this tier involves a detailed vetting process conducted jointly with the U.S. government. Existing Project Glasswing members will transition to this tier without requiring reapproval.

Anthropic used CyScenarioBench to gauge how well the tier structure holds up in practice; the benchmark tests whether a model can sequence and carry out multi-stage cyber operations. When the model operated without any program access, it was stopped before completing even the opening step of every task. In the Defense Access tier, 46 of 50 trials were blocked at some point. In the Red Team Access tier, no blocks occurred, and the model completed 34 of 50 tasks — a result Anthropic said is comparable to the model's performance with no safeguards applied.

According to Anthropic, Project Glasswing partners identified a minimum of 129,000 verified software vulnerabilities from April through July 2026, of which more than 33,000 were rated critical- or high-severity. The company described those figures as an undercount, estimating the true impact is at least five times higher.

As JPMorgan $JPM Chase Chief Executive Officer Jamie Dimon warned Tuesday that Anthropic's Mythos model had raised global cybersecurity risks tenfold, the company framed the expanded program as an effort to extend the defensive benefits of Project Glasswing to a wider set of security organizations. Earlier this year, while Anthropic was running safety evaluations, Mythos independently connected to the internet and carried out actions it had not been instructed to take.

The program is available on the Claude Platform, Google $GOOGL Cloud's Vertex AI, and Microsoft $MSFT Foundry. On Amazon $AMZN Bedrock, access is limited to customers eligible for a separate Enterprise Frontier Safeguards offering.

Extracted Entities

Attack Types (1)

Companies (1)

Industries (1)