Back Quasa Claude Cyber Access Expands to Three Tiers—but Verification Still Gates It
On October 6, 2026, Anthropic expanded its Cyber Verification Program to three access tiers for qualifying security professionals. Each tier includes access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models, with cyber blocking classifiers adjusted for the work approved under that tier. Applicants still have to establish who they are, what security work they do and which controls they can meet.
The expansion brings the earlier Cyber Verification Program and Project Glasswing into one offering. Individual researchers can seek Defense Access; organizations conducting authorized penetration tests can seek Red Team Access; and a limited group of verified organizations can seek Specialized Access for safety-critical systems. SecurityWeek’s report quotes Anthropic’s boundary for Red Team Access: “Currently, this tier is for organizations only; individual researchers are not eligible.”
What each access tier covers
The tiers a model lineup but differ in permitted work, verification and security controls. Defense Access covers defensive analysis; Red Team Access adds adversarial testing of authorized targets; Specialized Access addresses testing that could affect essential systems or markets. A grant for a model therefore does not, by itself, approve every use of that model.
Defense Access covers security operations and incident response, malware reverse engineering, and vulnerability analysis and validation. Potential applicants include teams defending systems they own or maintain, critical infrastructure operators such as regional hospitals and municipal utilities, smaller security firms, open-source maintainers, and individual researchers with a record of reported vulnerabilities. It is the only tier currently open to individual applicants.
Red Team Access adds authorized penetration testing and red-teaming. It is intended for organizations such as in-house red teams, government red teams and security testing firms. Their adversarial work must be confined to systems they are authorized to test. Qualifying organizations can receive Defense Access while a Red Team application undergoes the more extensive review.
Specialized Access has the fewest cyber blocks and is reserved for a limited set of verified organizations authorized to test safety systems. Examples include flight operating systems, power grids, telecommunications networks and interbank transfer infrastructure. Each organization receives an in-depth review in collaboration with the US government. Existing Project Glasswing members are moving to this tier without reapproval for the models they already use.
Reduced blocking still has boundaries
The program changes how Claude’s cyber classifiers handle qualifying work; it does not supply authorization to test a third party’s systems. Red Team Access still applies real-time blocks to actions that could cause physical harm or mass disruption, including ransomware deployment, damage to physical systems and penetration testing of high-risk safety systems. Access to the most sensitive work depends on the narrower Specialized review.
Some defensive tasks remain available through generally available Claude models. These include secure code review, threat modeling, patching known issues, finding vulnerabilities in source code a user owns and triaging security alerts. Malware analysis and exploit validation can encounter classifier blocks, creating a reason for eligible professionals to seek a program grant. The distinction is the scope of the work and the safeguards applied to it, rather than a blanket switch that removes cyber controls.
The Usage Policy continues to apply after approval, and a grant can be reviewed, narrowed or withdrawn. Building a client-facing product with these capabilities falls under a separate Cyber Productization Policy. For organizations in the program, data retention generally supports monitoring for cyber misuse. An existing zero-retention exception covers some organizations with qualifying Fable or Mythos access; a planned Enterprise Frontier Safeguards option would let eligible organizations store retained data in cloud infrastructure they control.
Application and approval are separate from account access
Anthropic’s application guidance calls for one application per organization and aims to send a decision or request for more information within seven business days. Applicants provide identity and organization details, describe their security work and attest to the controls for the tier they seek. The notification target does not mean every tier completes review in that period: Red Team reviews are expected to take a few weeks.
Independent researchers, maintainers and bug bounty hunters apply as individuals, and individual applicants need a paid plan. Within an organization, administrators designate users after the organization applies. Existing CVP and Glasswing members do not need to reapply to join the updated program: their access to previously used models continues under existing terms while they move to a relevant new tier for the expanded lineup.
Approval must then reach the environment where the work happens. Console organization owners assign the program to workspaces, while Enterprise owners assign it to custom roles. On certain linked cloud accounts and participating third-party platforms, the approved access level must also be enabled in the Verification Portal. A user can therefore hold an approved grant and still encounter a block if the grant has not been provisioned to the relevant account or the requested activity falls outside the tier.
Platform support also has limits. Claude’s own services and supported cloud routes can carry program access, while Amazon Bedrock access is restricted to eligible Enterprise Frontier Safeguards customers. Participating third-party applications can support Defense and Red Team Access, but not Specialized Access. On supported cloud providers, Mythos access may trail application approval while provisioning is completed. For teams seeking to use the expanded models, the practical result depends on both the approved scope of their work and the account through which they use Claude.
Mistral Large 4 Has 1.05T Parameters—but Its Scores Need Verification
Hadrian Raises $40M—Offensive AI Becomes a Funding Category
Together Link Swaps Coding Models—but Its Savings Claim Needs Testing
Google Pauses OSS Bug Reports After Automated Submissions Flood Triage
ASOS Confirms a Data Breach—The Rogue Alert Was Only the First Warning
ChatGPT-6 vs Claude Opus 5.5: Fast Structure or Deeper Judgment?
Microsoft’s PERM Suspension Blocks a Green-Card Step, Not H-1B Work
Get the latest Web3, AI, and crypto news delivered straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
