> Anthropic widens access to AI cyber capabilities for vetted security teams
[DATE: 07/10/2026 12:58]
[LANGUAGE: EN]
Anthropic is expanding its Cyber Verification Program to give more security teams access to advanced cyber capabilities with reduced safeguards on its most advanced AI models.
The expanded program has three access tiers based on the type of cybersecurity work an organization is authorized to perform. The tiers cover defensive security work, authorized red teaming, and testing of systems that could affect public safety or financial markets.
“Defenders also need access to the best tools and most powerful capabilities to secure their systems,” Anthropic said in its announcement.
The company said its generally available models use conservative cyber safeguards that block most cyber attacks. Anthropic said the safeguards are intended to limit harmful activity while it works to reduce false positives affecting secure coding.
The expanded program gives verified security organizations access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, as well as future models, with different levels of cyber restrictions.
From Glasswing to CVP
Anthropic’s new program combines two initiatives it has operated over the past six months: Project Glasswing and the earlier Cyber Verification Program.
Project Glasswing gave selected organizations working to secure critical software access to Claude Mythos. The existing CVP gave vetted security teams access to Claude Opus and Claude Sonnet models with reduced safeguards.
“The changes we’re making to our Cyber Verification Program today are intended to extend the impact of Project Glasswing to a much larger number of cyber defenders,” the statement added.
Under the expanded program, existing Glasswing members will move to the Specialized Access tier and will not need to seek approval again for their current models, the statement added.
Defense Access tier is aimed at defensive work such as security operations, incident response, malware reverse engineering, and vulnerability analysis and validation.
Red Team Access adds authorized penetration testing and red-team operations. Users can test only systems they are authorized to assess, Anthropic said.
Specialized Access has the fewest cyber restrictions and is reserved for a limited set of verified organizations authorized to test systems such as flight operating systems, power grids, telecommunications networks, interbank transfer infrastructure, and government administrative networks.
Anthropic said it reviews organizations seeking Specialized Access in collaboration with the US government.
Testing the tiers
Anthropic tested the different access levels using CyScenarioBench, an evaluation designed to measure whether AI models can plan and execute multistage cyber operations.
The company ran Claude Opus 5.5 through 10 challenges, with five attempts at each challenge for every access tier.
Without CVP access, all 50 trials were blocked at the first prompt, Anthropic said. Under Defense Access, 46 of the 50 trials were blocked at some point, while four succeeded.
Under Red Team Access, Anthropic said none of the 50 trials was blocked, and Claude completed 34. The company said that was equivalent to its 67.6% success rate when no safeguards were applied.
Sakshi Grover, research director at IDC, said the evaluation should be viewed in context because it was “a vendor-run test, not an independent one.”
Grover said the results show why authorization and scope matter when AI is used for security testing.
“Because the steps can resemble an attacker’s, legitimacy depends on authorization, target scope and execution conditions, not on the technique itself,” she said.
Deepika Giri, vice president, Asia/Pacific artificial intelligence platforms and advisory at IDC, said the tiered approach can work if access is continuously reviewed.
“It only works if the vetting is real and access keeps being checked after it is granted, because an agent’s behavior can change over time,” Giri said.
Controls beyond safeguards
Grover said enterprises should use controls outside the AI model when agents receive reduced safeguards or privileged access.
“When model-level refusals are reduced, controls must sit outside the model,” she said.
Grover recommended giving each agent a distinct identity, using short-lived privileges for specific tasks, independently checking targets and actions, and testing containment and recovery mechanisms.
Giri said enterprises should treat an AI agent like a privileged employee.
“Give it an identity and grant short-lived access only for the task at hand, complete observability and control over its actions,” she said. Giri also recommended human oversight for high-impact actions.
Cybersecurity researcher and red teamer Vibhum Dubey said organizations also need to establish accountability for actions taken by autonomous systems.
“Organizations also need to define who is accountable for the actions taken by the AI,” Dubey said.
Anthropic said Project Glasswing partners identified at least 129,000 verified software vulnerabilities between April and July 2026. Its own open-source scanning efforts identified another 5,500 between April and October, the company said.
According to Anthropic, more than 33,000 of those vulnerabilities have so far been rated critical or high severity. “This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher,” Anthropic said in the announcement.
Organizations enrolled in CVP will be subject to data retention so that Anthropic can monitor for cyber misuse. The company said its forthcoming Enterprise Frontier Safeguards service will allow eligible organizations to combine zero-data-retention capabilities with additional safeguards and store data in cloud infrastructure they control.