
News
Anthropic opens three cyber-access tiers for vetted teams
Anthropic’s expanded Cyber Verification Program gives vetted teams three tiers of access to Opus 5.5, Sonnet 5.5, and Mythos 5.1.
Searcher → Analyst → Writer → Editor · subagentic-20261007-0800
Anthropic on October 6, 2026 expanded its Cyber Verification Program into three access tiers for qualifying security professionals: Defense, Red Team, and Specialized. The new offering folds in Project Glasswing and is meant to give more defenders reduced blocking classifiers on the company’s most capable models, while generally available Claude still blocks most cyber work.
Each tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models. Anthropic says public models, including Opus 5.5, Sonnet 5.5, and Fable 5.1, keep conservative cyber safeguards so malicious use stays limited, even as the company tries to cut false positives on secure coding. Code review, patching known issues, vulnerability finding in source code an organization owns, and triage of security alerts remain available without CVP.
For the prior six months Anthropic had run two separate programs. Glasswing gave organizations securing the most critical software access to Claude Mythos. The original CVP gave vetted security teams reduced safeguards on Opus and Sonnet. Reuters, reporting the same day, noted that the April unveiling of Claude Mythos Preview had raised fears that AI could hack software before it had been secured. The expanded CVP is the combined program.
Who can apply, and for what
Defense Access is for defensive work: security operations and incident response, reverse-engineering malware, and analyzing and validating vulnerabilities. Anthropic expects many organizations doing that work to qualify, and says it aims to answer applications within a few days. Eligible applicants include security teams at companies, nonprofits, universities, and government bodies defending systems they own or maintain; critical-infrastructure operators of any size, such as regional hospitals or municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a track record of reported vulnerabilities.
Red Team Access adds authorized penetration testing and red-teaming. In-house red teams, government red teams, and security and penetration-testing firms can apply, and only against systems they are authorized to test, including IT systems in critical industries. Real-time blocks still apply to actions that could cause physical harm or mass disruption, including deploying ransomware, damaging physical systems, and penetration testing of high-risk safety systems. Reviews are expected to take a few weeks. Qualifying organizations are enrolled in Defense Access while a Red Team application is pending. This tier is for organizations only; individual researchers are not eligible.
Specialized Access has the fewest cyber blocks. It is limited to verified organizations authorized to test safety systems that could affect lives or disrupt markets, including flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks. Anthropic reviews each organization in depth with the US government. Existing Glasswing members move into this tier and do not need reapproval for current models.
Retention, and where the program runs
Organizations enrolled in CVP must retain data so Anthropic can monitor for cyber misuse. Later this fall, Enterprise Frontier Safeguards is supposed to pair the privacy of zero data retention with safeguards, and let eligible organizations store data in cloud infrastructure they control. Until that ships, organizations that already have zero-data-retention access to Claude Fable 5.1 or Claude Mythos 5.1 can use CVP with zero data retention as well.
CVP is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. On Amazon Bedrock it is limited to customers eligible for Enterprise Frontier Safeguards.
Anthropic verifies applicants and asks for proof of the security controls required for the relevant tier. Existing CVP members keep their current settings on previous models and are automatically evaluated for Opus 5.5, Sonnet 5.5, and Mythos 5.1. Admins still have to assign access to specific workspaces. Teams blocked on work they believe their tier should allow can report that to Anthropic; tier details are also in the company’s Help Center.
What Glasswing partners reported
Anthropic says Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, and that its own open-source scanning found another 5,500 verified vulnerabilities between April and October 2026. More than 33,000 of those verified findings have been rated critical or high severity. Reuters reported the same counts. Anthropic calls the total a likely undercount, based on survey data from only a subset of partners, and says it expects the true impact to be at least five times higher. The announcement’s own caption treats the figures as a lower bound from partial data in 33 partner reports plus Anthropic’s open-source partnerships. Partners triaged differently, and fewer than half disclosed how many issues they had patched, often because fixes were still in progress, so the patch rate is undercounted. Several partners told Anthropic the models had raised their rate of vulnerability finding by months or years. Anthropic pointed readers to accounts from Booz Allen and Comcast.
The company said it will share more in the coming weeks on open-source software and critical infrastructure.
If your team’s work is owned-code review, known-issue patching, or alert triage, the general models are still the path Anthropic describes. If you need a reduced-classifier tier, apply through Anthropic’s CVP portal, gather proof of the controls for the tier you want, and check whether your cloud—especially Bedrock—requires Enterprise Frontier Safeguards eligibility before access is real.